// ISO42001.jsx — Verigo Global: dedicated ISO/IEC 42001 (AIMS) framework + support page const { V: JV, MAXW: JMW, FONT: JFT } = window; /* ── DATA ─────────────────────────────────────────────────── */ const ANNEX_THEMES = [ ['briefcase', 'Policy & Organization', '8', 'AI policy, roles, resourcing, and the governance backbone of the AI management system.'], ['target', 'Impact Assessment', '3', 'Assessing effects of AI systems on individuals, groups, and society before deployment.'], ['layers', 'AI System Life Cycle', '10', 'Requirements, design, verification, deployment, and monitoring across the AI lifecycle.'], ['doc', 'Data & Transparency', '9', 'Data quality and provenance, plus disclosure to interested parties and third parties.'], ['compass', 'Use & Relationships', '8', 'Responsible use objectives, supplier allocation of responsibility, and customer commitments.'], ]; const SUPPORT_STAGES = [ { step: '01', icon: 'search', overline: 'Assess', title: 'ISO 42001 Readiness Assessment', lead: 'Know exactly where you stand against ISO/IEC 42001:2023.', desc: 'We benchmark your current state against Clauses 4–10 and all 38 Annex A controls, score your gaps by risk and effort, and hand you an independent remediation roadmap — the foundation for everything that follows.', deliverables: ['Clause 4–10 gap analysis', 'Annex A control-by-control review', 'Risk-scored remediation roadmap', 'Indicative certification timeline'], link: 'services', linkLabel: 'About readiness assessments', }, { step: '02', icon: 'layers', overline: 'Implement', title: 'AIMS Implementation Toolkit', lead: 'We build the AI Management System with you — not for a shelf.', desc: 'A practitioner-led program that stands up the full AIMS: AI risk assessment methodology, Statement of Applicability, the complete policy set, impact assessments, and the internal audit and management-review machinery that keeps it alive.', deliverables: ['AI risk assessment & treatment methodology', 'Statement of Applicability (SoA)', 'Full AIMS policy & procedure set', 'Internal audit & management review program'], link: 'toolkits', linkLabel: 'Explore the toolkits', }, { step: '03', icon: 'clipboard', overline: 'Prepare', title: 'Stage 1 & Stage 2 Pre-Audit Preparation', lead: 'Walk into the certification audit knowing you will pass.', desc: 'A mock Stage 1 documentation review and a full Stage 2 mock audit run by a lead auditor independent of your implementation team — surfacing nonconformities while there is still time to close them.', deliverables: ['Mock Stage 1 documentation review', 'Full Stage 2 mock audit', 'Nonconformity log & corrective actions', 'Auditor-readiness coaching for your team'], link: 'services', linkLabel: 'About pre-audit preparation', }, { step: '04', icon: 'award', overline: 'Certify & Sustain', title: 'Certification & Surveillance Support', lead: 'Get certified — and stay certified across the three-year cycle.', desc: 'We support you through the certification body’s Stage 1 and Stage 2 audits, manage findings to closure, then keep the AIMS audit-ready through annual surveillance and three-year recertification.', deliverables: ['Certification body coordination', 'Findings management to closure', 'Annual surveillance audit support', 'Year-three recertification'], link: 'contact', linkLabel: 'Talk to a practitioner', }, ]; const JOURNEY = [ ['search', 'Gap analysis', '2–4 wks', 'Readiness assessment against the 2023 standard.'], ['layers', 'Build the AIMS', '3–6 mo', 'Risk method, SoA, policies, impact assessments, evidence.'], ['file', 'Stage 1 audit', '~1 wk', 'Certification body reviews AIMS documentation.'], ['shield', 'Stage 2 audit', '1–2 wks', 'On-site assessment of operating effectiveness.'], ['award', 'Certified', '—', 'Three-year ISO/IEC 42001 certificate issued.'], ['refresh', 'Surveillance', 'Yr 1 & 2', 'Annual checks, then recertify in year three.'], ]; const CROSS = [ ['globe', 'iso27001', 'ISO 27001', 'Reuse ISMS governance, risk, and supplier controls as the backbone of your AI management system.'], ['shield', 'soc2', 'SOC 2', 'Align AI system controls with the Trust Services Criteria your customers already expect.'], ['lock', 'cmmc', 'CMMC 2.0', 'AI-specific access and data controls complement the NIST 800-171 practices behind CMMC Level 2.'], ['building', 'nist', 'NIST', 'AI risk categories map onto the NIST Cybersecurity Framework functions your program already tracks.'], ]; const ISO_FAQ = [ ['What is ISO/IEC 42001?', 'ISO/IEC 42001:2023 is the first certifiable international standard for an Artificial Intelligence Management System (AIMS) — a structured framework for governing, developing, and deploying AI responsibly across its lifecycle, covering fairness, transparency, human oversight, and accountability.'], ['How does it relate to ISO 27001?', 'Both standards share the same management-system clauses (context, leadership, planning, support, operation, evaluation, improvement), so organizations already certified to ISO 27001 typically find ISO 42001 faster to implement. Annex A adds AI-specific controls — bias, explainability, impact assessment — that ISO 27001 was never written to cover.'], ['How long does certification take?', 'For a mid-market organization, expect roughly 4–8 months end to end: a 2–4 week readiness assessment, 3–6 months to build and operate the AIMS, then the certification body’s Stage 1 and Stage 2 audits. We give you a firm timeline in the scoping proposal.'], ['Do we need to implement all 38 Annex A controls?', 'No. You select applicable controls based on your AI risk assessment and document your reasoning — including exclusions — in the Statement of Applicability, the same approach used in ISO 27001.'], ['Can Verigo both build and audit our AIMS?', 'We support you through the full lifecycle, but the certification audit itself must be performed by an independent, accredited certification body — never the firm that implemented your controls. Our pre-audit lead auditor is kept separate from your implementation team to preserve that independence.'], ['Does ISO 42001 help with the EU AI Act and similar regulation?', 'Yes. While ISO 42001 is not itself a legal requirement, its risk-based, documented approach to AI governance gives you much of the evidence and process rigor that emerging AI regulation expects — reducing the incremental work of demonstrating regulatory compliance.'], ]; /* ── BREADCRUMB ───────────────────────────────────────────── */ const Crumb = ({ onNav }) => (
/ / ISO 42001
); const crumbBtn = { background: 'none', border: 'none', cursor: 'pointer', color: '#7A7A8A', fontSize: 13, fontWeight: 600, padding: 0, fontFamily: "'DM Sans', system-ui, sans-serif" }; /* ── HERO ─────────────────────────────────────────────────── */ const Hero = ({ onNav }) => (
AI Management System ISO/IEC 42001:2023

ISO 42001, delivered end to end.

The first certifiable standard for responsible AI governance. Verigo takes you from first gap analysis to a certified AI Management System — and keeps you certified across the full three-year cycle, with senior practitioners on every engagement.

onNav('contact')}>Start a Conversation document.getElementById('support')?.scrollIntoView({ behavior: 'smooth', block: 'start' })}>See how we help
At a glance
{[ ['cpu', 'Scope', 'Any AI system you build, buy, or operate'], ['layers', 'Standard', '38 Annex A controls, 9 objectives'], ['refresh', 'Cycle', '3-year certificate + surveillance'], ['gauge', 'Typical timeline', '4–8 months to certified'], ].map(([ic, k, val], i) => (
{k}
{val}
))}
); /* ── STATS STRIP ──────────────────────────────────────────── */ const Stats = () => (
{[ ['2023', 'Standard first published'], ['38', 'Annex A controls'], ['9', 'Control objectives (A.2–A.10)'], ['3-yr', 'Certification cycle'], ].map(([v, l], i) => (
{v} {l}
))}
); /* ── WHAT IT IS / ANNEX A ─────────────────────────────────── */ const Overview = () => (
What ISO 42001 certifies

A living system, not a model card.

ISO/IEC 42001 certifies a complete AI Management System — a risk-based, continuously improving framework that governs how AI systems are designed, developed, deployed, and monitored across your whole organization.

The standard pairs management-system requirements (Clauses 4–10) with a catalog of 38 Annex A controls. Verigo’s Compliance by Design approach embeds those controls into how you already build and operate AI — so evidence is generated by the process, not assembled in a panic before each audit.

{[ 'Risk-based — controls follow your actual AI use cases, not a checklist', 'The first certifiable standard purpose-built for responsible AI', 'A natural extension for organizations already certified to ISO 27001', ].map((t, i) => (
{t}
))}
Annex A — 2023 structure

38 controls, nine objectives.

{ANNEX_THEMES.map(([ic, name, count, desc], i) => (
{count}

{name}

{desc}

))}
); /* ── THE SUPPORT MODEL (CORE) ─────────────────────────────── */ const Support = ({ onNav }) => (
Four service lines, mapped
to the ISO 42001 lifecycle.} sub="Engage any single stage or move through the whole journey with one accountable, senior-led team — and a peer-review quality gate on every deliverable." maxSub={640} />
{SUPPORT_STAGES.map((s) => (
{s.step}
{s.overline}

{s.title}

{s.lead}

{s.desc}

What you receive
{s.deliverables.map((d, j) => (
{d}
))}
))}
); /* ── CERTIFICATION JOURNEY ────────────────────────────────── */ const Journey = () => (
{JOURNEY.map(([ic, t, dur, d], i) => (
{dur}
{t}
{d}
))}
); /* ── WHY VERIGO + CROSS-FRAMEWORK ─────────────────────────── */ const WhyAndCross = ({ onNav }) => (
Why certify with Verigo

Implementation and audit, under one roof.

{[ ['users', 'Senior-led, always', 'Every engagement is run by practitioners with deep AI governance and ISO Lead Auditor credentials — never junior consultants with templates.'], ['gauge', 'Audit-ready by design', 'Controls are embedded into how you build and operate AI, so evidence accumulates continuously instead of being reconstructed before each audit.'], ['scale', 'Independence preserved', 'Our pre-audit lead auditor is kept separate from your implementation team, protecting the integrity of the certification.'], ].map(([ic, t, d], i) => (

{t}

{d}

))}
One certification, many doors

ISO 42001 builds on what you already have.

Our cross-framework control mapping lets your existing certifications accelerate ISO 42001 — and lets ISO 42001 evidence support the frameworks you already hold. Build it once, reuse it across:

{CROSS.map(([ic, id, name, desc]) => ( ))}
); /* ── FAQ ──────────────────────────────────────────────────── */ const FAQ = ({ onNav }) => { const [open, setOpen] = React.useState(0); return (
ISO 42001 questions

Good to know before we start.

Questions on scope, timeline, or how this relates to ISO 27001? A senior practitioner will walk you through it.

onNav('contact')}>Start a Conversation
{ISO_FAQ.map(([q, a], i) => { const isOpen = open === i; return (
{isOpen && (

{a}

)}
); })}
); }; /* ── PAGE ─────────────────────────────────────────────────── */ const ISO42001Page = ({ onNav }) => (
); Object.assign(window, { ISO42001Page });