Subnet345

Compliance · ISO/IEC 42001:2023 · Agentic AI

ISO 42001 certifies how you govern AI. For agents, you still have to prove what they did.

ISO/IEC 42001:2023, published in 2023, is the first international management-system standard for AI. It certifies that you have a system for governing AI: policies, roles, impact assessments, and a selected set of Annex A controls. Certification tells an auditor the system exists. A surveillance audit still asks whether the controls actually operated, and for agents that act on real systems, that answer lives in a record.

§ 01 The standard

A management system, and the controls it selects.

ISO/IEC 42001 follows the shape of ISO 27001. Clauses 4 through 10 define the management system itself: the organization's context, leadership, planning, support, operation, performance evaluation, and continual improvement. Annex A adds a reference set of 38 controls across 9 objectives, from AI policy and impact assessment to the AI system life cycle, data, and third-party relationships. An organization documents which controls apply in a Statement of Applicability and implements them proportionate to the risks its impact assessments surface.

The controls are principle-based, not prescriptive technical checklists. That is a strength for governance and a gap at audit time: a control that says the life cycle must be managed and logged does not, by itself, produce the log. When the systems under management are agents acting on real applications, the evidence the operation and performance-evaluation clauses assume has to come from somewhere.

You can certify the management system in a document. You cannot certify an agent's action without the record of it.

§ 02 The evidence

What a surveillance audit asks an agent program to show.

The substrate makes operational evidence a property of the action. Agent actions are attributed to the agent that performed them and hash-chained into a tamper-evident audit trail kept inside your boundary. Refusals and policy violations are recorded with the exact rule and version that fired. That is the operating record an ISO 42001 program is assumed to have kept, produced as the work happens rather than reconstructed for the audit.

That operational controls on your AI systems were actually applied, not merely documented
Asserted in the Statement of Applicability, evidenced by sampling
The action, the policy version, and the outcome, on the record
Which agent acted, on which data, under whose authority
Reconstructed from scattered application logs
Attributed at the moment of action
How AI-system incidents and refusals were captured and handled
Captured unevenly, if at all
Every refusal recorded with the exact rule and version that fired
Where the operating record lives when a surveillance audit asks for it
Vendor-managed, with caveats
Inside your boundary, on your retention schedule

This material is informational, not legal, regulatory, or certification advice. Subnet345 does not hold ISO 42001 certification and does not certify your organization. The substrate produces the record; it does not by itself make a program compliant or certifiable. Regulatory mapping reviewed: August 2026.

§ 03 Questions

ISO 42001 and agentic AI, answered.

What is ISO/IEC 42001:2023?

ISO/IEC 42001:2023 is the first international management-system standard for artificial intelligence, published in 2023. Like ISO 27001, it pairs management-system requirements (clauses 4 through 10: context, leadership, planning, support, operation, performance evaluation, improvement) with a reference set of controls in Annex A (38 controls across 9 control objectives) and implementation guidance in Annex B. An organization selects the applicable controls in a Statement of Applicability and implements them proportionate to the risks found in its AI system impact assessments. It is certifiable by accredited third-party bodies.

Is Subnet345 ISO 42001 certified?

No. Subnet345 does not hold ISO 42001 certification, and we do not certify your organization; certification is issued by accredited certification bodies, not by a vendor. What the substrate does is produce the operational evidence your AI management system relies on: the attributed, tamper-evident record of what your AI agents actually did. It supports your program's evidence, it is not a certificate and it is not a substitute for one.

What does the substrate produce for an ISO 42001 program?

When the AI systems in scope are agents that act on real systems, the operation clause (8) and the performance-evaluation clause (9), together with the Annex A controls covering the AI system life cycle and record-keeping, assume an operating record exists. The substrate produces it: agent actions attributed to the agent that performed them and hash-chained into a tamper-evident audit trail, with refusals, escalations, and approvals recorded as durable events, each tagged with the exact rule and version that fired, kept inside your boundary.

Does producing this record make our program compliant?

No. This material is informational, not legal, regulatory, or certification advice. The substrate produces the record; it does not by itself align a program to ISO 42001, select your controls, or make you certifiable. Assess your specific posture with qualified counsel, your internal AI governance function, and an accredited certification body.

Related

Adjacent frameworks, and the substrate itself.

Can you evidence the controls operated, action by action?