Skip to content
ISO/IEC 42001:2023

Your ISO 42001 controls,
continuously mapped.

Blackfyre maps infrastructure findings to the ISO/IEC 42001:2023 controls, evidencing the operational and technical safeguards behind the systems your AI runs on — data storage, access, logging, and monitoring. Open source, self-host free.

Coverage · illustrative

22

ISO 42001 controls

9

Frameworks

3 + on-prem

Clouds

Free

Apache-2.0

The standard

What ISO 42001 covers.

AI management-system standard covering AI governance, risk, lifecycle, transparency, fairness, and human oversight.

A.2

AI policies

Policies for the responsible development and use of AI systems.

A.3

Internal organization

Roles, responsibilities, and reporting for the AI management system.

A.4

Resources for AI systems

Data, tooling, compute, and human resources for AI.

A.5

Impact assessment

Assessing impacts of AI systems on individuals, groups, and society.

A.6

AI system life cycle

Responsible design, development, deployment, and operation.

A.7

Data for AI systems

Data quality, provenance, and management across the lifecycle.

A.8

Information for interested parties

Transparency and information provided to users and stakeholders.

A.9

Use of AI systems

Responsible operation and intended-use controls.

A.10

Third-party relationships

Managing suppliers, customers, and third-party AI components.

Blackfyre maps findings to the 22 ISO 42001 controls it tracks · one of 9 frameworks in the platform.

How it works

From scan to audit-ready evidence.

The same pipeline that scores your ISO 42001 posture also produces the artifacts an auditor asks for — no spreadsheet reconciliation. Blackfyre assesses and evidences posture; it never claims a certification on your behalf.

  1. 01 · Scan

    55 auditors enumerate real resources across AWS, Azure, GCP and on-prem — plus Prowler and Checkov / Semgrep / Bandit as containerised scanners.

  2. 02 · Map

    Every finding maps to the 22 ISO 42001 controls it affects. A single misconfiguration can touch several controls at once — the mapping records each one.

  3. 03 · Score

    Weighted per-framework scoring rolls findings into a posture score you track as your team ships fixes — no spreadsheet reconciliation.

  4. 04 · Evidence

    Each result is written to a tamper-evident vault — SHA-256 integrity hash, S3 Object Lock, versioning — ready to hand to an auditor.

Illustrative vault record · shows the shape, not real data

Evidence vaultillustrative
integrity
sha256:d4a1…9c02
control
A.2
storage
S3 Object Lock · versioned
pii
AES-256-GCM · field-encrypted
verify
auditor recomputes the hash

55

Auditors

22

ISO 42001 controls

3 + on-prem

Clouds

SHA-256

Tamper-evident

+3

Scope & honesty

Blackfyre assesses the cloud and on-prem infrastructure that hosts your AI systems and maps posture findings to ISO 42001's technical and operational controls. It is not a model-level red-teaming or evaluation tool — pair it with your own AI-lifecycle and impact-assessment process.

Open source · Apache-2.0

ISO 42001, mapped and evidenced.

Blackfyre is Apache-2.0 — self-host it free forever, or try the hosted option (early access). First findings and mapped ISO 42001 evidence in about fifteen minutes locally. It assesses and evidences your posture; it does not certify compliance.

22

ISO 42001 controls

9

Frameworks

55

Auditors

Free

Apache-2.0