Framework Mapping · ISO/IEC 42001:2023

ISO 42001

Live evidence mapping against ISO/IEC 42001 — the AI Management System standard. Evidence is pulled directly from execution data. No self-assessment.

Transparency note: TrustLayers does not claim ISO 42001 certification. This page maps live execution evidence to each clause so auditors and clients can assess coverage themselves.
1,324
Events in evidence base
2%
SHA-256 sealed
0%
Decision context logged
10
Agents in scope
4 — Context
4.1
Understanding the organisation
Agent registry with category, description and EU AI Act article per agent.
→ 10 agents documented
4.3
AI management system scope
Every agent operates under TrustLayers governance scope from registration.
6 — Planning
6.1.2
AI risk assessment
risk_score and anomaly_score captured per execution event.
→ 1324 events with risk data
6.1.3
AI risk treatment
compliance_status and policy_triggered fields record treatment per event.
→ 0 violations recorded
6.2
AI objectives and planning
Blueprint pre-runtime config defines objectives before execution begins.
8 — Operation
8.1
Operational planning and control
Every action logged asynchronously with zero impact on execution path.
→ 1324 events logged
8.4
AI system lifecycle
created_at timestamps trace full agent lifecycle from first to last event.
8.5
AI system impact assessment
sensitive_data and drift_detected flags assess impact per event.
→ 4 sensitive events
8.6
Data for AI systems
prompt_hash and output_hash seal data integrity cryptographically.
→ 2% sealed
9 — Performance
9.1
Monitoring and measurement
EEI score measures evidence quality across 6 dimensions in real time.
9.1.2
Internal audit evidence
Immutable SHA-256 audit trail — every event cryptographically verifiable.
→ 2% verifiable
9.3
Management review inputs
Public EEI, Replay, Custody and Report pages provide management evidence.
10 — Improvement
10.1
Continual improvement
drift_detected field identifies behavioral change requiring improvement.
→ 0 drift events flagged
10.2
Nonconformity and corrective
Violations and errors logged with error_code for corrective action.
→ 0 nonconformities logged