ISO/IEC 42001

ISO/IEC 42001:2023 is the international standard for AI Management Systems. It’s the AI equivalent of ISO 27001 for information security — it tells organizations how to govern, develop, and operate AI systems responsibly. ai-blackteam maps harm categories to ISO 42001 Annex A controls so you can see which governance areas your model’s weaknesses fall under.

Annex A Controls

How ai-blackteam Maps to ISO 42001

When ai-blackteam finds a bypass, it maps the harm category to the relevant ISO 42001 control. This tells you which area of your AI management system needs attention.

Using ISO 42001 for Compliance

If your organization is pursuing ISO 42001 certification (or aligning to it voluntarily), ai-blackteam results help you document evidence for your management system:
  • A.5 (Impact Assessment): ai-blackteam’s safety scan IS part of your impact assessment. Run ai-blackteam benchmark and export the results as evidence.
  • A.6 (Lifecycle): Regular scanning at each deployment stage. Use ai-blackteam batch in CI/CD as a lifecycle gate.
  • A.7 (Data): Test for PII extraction and data leakage with privacy-violation and information-disclosure attack categories.
  • A.9 (Use): The OWASP scorecard (ai-blackteam scorecard --standard llm) provides a structured compliance artifact.
  • A.10 (Third-Party): If you use third-party models, run ai-blackteam against each provider to assess their risk profile.

Reference