Checkpoint · ISO 42001
ISO 42001 software for AI governance
Checkpoint runs an ISO/IEC 42001 AI management system alongside your ISO 27001 one: an AI systems register, impact assessments and the Annex A controls, with the same risk register, audits and management reviews.
The demo is the real console with sample data. No sign-up.

What Checkpoint holds for ISO 42001
- The ISO/IEC 42001:2023 Annex A control set: policies, resourcing, impact assessment, life cycle, data, disclosure, use and third-party relationships.
- Clauses 4–10 as requirement checklists, on the same clause register as ISO 27001.
- An AI systems register and an AI impact assessment procedure.
- AI-specific policies, kept separate from your information security documents.
Measured from your Microsoft 365
The scan flags high-privilege app grants in Microsoft Entra that nobody has reviewed, a common route for unapproved AI tools to reach your data.
Checkpoint signs in with Microsoft Entra and reads your settings through Microsoft Graph with read-only, delegated permissions. Your records are SharePoint lists in your own tenant, so if you stop using Checkpoint they are still yours. How Checkpoint works.
Questions
- Do we need ISO 27001 first?
- No, but most organisations pair them. Checkpoint runs both on one clause register and one risk register, so shared work is done once.
- Is ISO 42001 certifiable?
- Yes. ISO/IEC 42001 is a certifiable management system standard, audited by an accredited certification body.
- Does it cover the EU AI Act?
- Checkpoint does not run the EU AI Act as a framework. ISO 42001 is commonly used as the management system behind AI Act obligations; the free EU AI Act classifier on our ISO 42001 page helps you check where a system may fall.