// ISO42001.jsx — Verigo Global: dedicated ISO/IEC 42001 (AIMS) framework + support page const { V: JV, MAXW: JMW, FONT: JFT } = window; /* ── DATA ─────────────────────────────────────────────────── */ const ANNEX_THEMES = [ ['briefcase', 'Policy & Organization', '8', 'AI policy, roles, resourcing, and the governance backbone of the AI management system.'], ['target', 'Impact Assessment', '3', 'Assessing effects of AI systems on individuals, groups, and society before deployment.'], ['layers', 'AI System Life Cycle', '10', 'Requirements, design, verification, deployment, and monitoring across the AI lifecycle.'], ['doc', 'Data & Transparency', '9', 'Data quality and provenance, plus disclosure to interested parties and third parties.'], ['compass', 'Use & Relationships', '8', 'Responsible use objectives, supplier allocation of responsibility, and customer commitments.'], ]; const SUPPORT_STAGES = [ { step: '01', icon: 'search', overline: 'Assess', title: 'ISO 42001 Readiness Assessment', lead: 'Know exactly where you stand against ISO/IEC 42001:2023.', desc: 'We benchmark your current state against Clauses 4–10 and all 38 Annex A controls, score your gaps by risk and effort, and hand you an independent remediation roadmap — the foundation for everything that follows.', deliverables: ['Clause 4–10 gap analysis', 'Annex A control-by-control review', 'Risk-scored remediation roadmap', 'Indicative certification timeline'], link: 'services', linkLabel: 'About readiness assessments', }, { step: '02', icon: 'layers', overline: 'Implement', title: 'AIMS Implementation Toolkit', lead: 'We build the AI Management System with you — not for a shelf.', desc: 'A practitioner-led program that stands up the full AIMS: AI risk assessment methodology, Statement of Applicability, the complete policy set, impact assessments, and the internal audit and management-review machinery that keeps it alive.', deliverables: ['AI risk assessment & treatment methodology', 'Statement of Applicability (SoA)', 'Full AIMS policy & procedure set', 'Internal audit & management review program'], link: 'toolkits', linkLabel: 'Explore the toolkits', }, { step: '03', icon: 'clipboard', overline: 'Prepare', title: 'Stage 1 & Stage 2 Pre-Audit Preparation', lead: 'Walk into the certification audit knowing you will pass.', desc: 'A mock Stage 1 documentation review and a full Stage 2 mock audit run by a lead auditor independent of your implementation team — surfacing nonconformities while there is still time to close them.', deliverables: ['Mock Stage 1 documentation review', 'Full Stage 2 mock audit', 'Nonconformity log & corrective actions', 'Auditor-readiness coaching for your team'], link: 'services', linkLabel: 'About pre-audit preparation', }, { step: '04', icon: 'award', overline: 'Certify & Sustain', title: 'Certification & Surveillance Support', lead: 'Get certified — and stay certified across the three-year cycle.', desc: 'We support you through the certification body’s Stage 1 and Stage 2 audits, manage findings to closure, then keep the AIMS audit-ready through annual surveillance and three-year recertification.', deliverables: ['Certification body coordination', 'Findings management to closure', 'Annual surveillance audit support', 'Year-three recertification'], link: 'contact', linkLabel: 'Talk to a practitioner', }, ]; const JOURNEY = [ ['search', 'Gap analysis', '2–4 wks', 'Readiness assessment against the 2023 standard.'], ['layers', 'Build the AIMS', '3–6 mo', 'Risk method, SoA, policies, impact assessments, evidence.'], ['file', 'Stage 1 audit', '~1 wk', 'Certification body reviews AIMS documentation.'], ['shield', 'Stage 2 audit', '1–2 wks', 'On-site assessment of operating effectiveness.'], ['award', 'Certified', '—', 'Three-year ISO/IEC 42001 certificate issued.'], ['refresh', 'Surveillance', 'Yr 1 & 2', 'Annual checks, then recertify in year three.'], ]; const CROSS = [ ['globe', 'iso27001', 'ISO 27001', 'Reuse ISMS governance, risk, and supplier controls as the backbone of your AI management system.'], ['shield', 'soc2', 'SOC 2', 'Align AI system controls with the Trust Services Criteria your customers already expect.'], ['lock', 'cmmc', 'CMMC 2.0', 'AI-specific access and data controls complement the NIST 800-171 practices behind CMMC Level 2.'], ['building', 'nist', 'NIST', 'AI risk categories map onto the NIST Cybersecurity Framework functions your program already tracks.'], ]; const ISO_FAQ = [ ['What is ISO/IEC 42001?', 'ISO/IEC 42001:2023 is the first certifiable international standard for an Artificial Intelligence Management System (AIMS) — a structured framework for governing, developing, and deploying AI responsibly across its lifecycle, covering fairness, transparency, human oversight, and accountability.'], ['How does it relate to ISO 27001?', 'Both standards share the same management-system clauses (context, leadership, planning, support, operation, evaluation, improvement), so organizations already certified to ISO 27001 typically find ISO 42001 faster to implement. Annex A adds AI-specific controls — bias, explainability, impact assessment — that ISO 27001 was never written to cover.'], ['How long does certification take?', 'For a mid-market organization, expect roughly 4–8 months end to end: a 2–4 week readiness assessment, 3–6 months to build and operate the AIMS, then the certification body’s Stage 1 and Stage 2 audits. We give you a firm timeline in the scoping proposal.'], ['Do we need to implement all 38 Annex A controls?', 'No. You select applicable controls based on your AI risk assessment and document your reasoning — including exclusions — in the Statement of Applicability, the same approach used in ISO 27001.'], ['Can Verigo both build and audit our AIMS?', 'We support you through the full lifecycle, but the certification audit itself must be performed by an independent, accredited certification body — never the firm that implemented your controls. Our pre-audit lead auditor is kept separate from your implementation team to preserve that independence.'], ['Does ISO 42001 help with the EU AI Act and similar regulation?', 'Yes. While ISO 42001 is not itself a legal requirement, its risk-based, documented approach to AI governance gives you much of the evidence and process rigor that emerging AI regulation expects — reducing the incremental work of demonstrating regulatory compliance.'], ]; /* ── BREADCRUMB ───────────────────────────────────────────── */ const Crumb = ({ onNav }) => (
The first certifiable standard for responsible AI governance. Verigo takes you from first gap analysis to a certified AI Management System — and keeps you certified across the full three-year cycle, with senior practitioners on every engagement.
ISO/IEC 42001 certifies a complete AI Management System — a risk-based, continuously improving framework that governs how AI systems are designed, developed, deployed, and monitored across your whole organization.
The standard pairs management-system requirements (Clauses 4–10) with a catalog of 38 Annex A controls. Verigo’s Compliance by Design approach embeds those controls into how you already build and operate AI — so evidence is generated by the process, not assembled in a panic before each audit.
{desc}
{s.lead}
{s.desc}
{d}
Our cross-framework control mapping lets your existing certifications accelerate ISO 42001 — and lets ISO 42001 evidence support the frameworks you already hold. Build it once, reuse it across:
Questions on scope, timeline, or how this relates to ISO 27001? A senior practitioner will walk you through it.
{a}