Framework Reference
The frameworks, in plain language.
What each standard actually requires, whether it's mandatory or voluntary, whether you can get certified against it, and how they overlap. No sales pitch — just the reference.
STANDARD 01
ISO 9001 — Quality management systems
- 01What it is
- The international standard for quality management systems — a framework that helps organizations deliver consistent products and services, improve efficiency, and meet customer and regulatory expectations. It covers context of the organization, planning, support, operation, performance evaluation, and improvement.
- 02Mandatory or voluntary
- Voluntary, though customers or contracts in some sectors may require it.
- 03Certifiable
- Yes, via independent accredited certification bodies.
- 04Who it applies to
- Used across nearly every sector — manufacturing, services, healthcare, education, construction, technology, and public administration.
- 05Current status
- ISO 9001:2015 is the current edition. A revised edition, ISO 9001:2026, is expected to publish around September 2026 following a 2023 international consensus that a revision would add value. [Publication date and transition timeline to be confirmed once ISO formally releases it.]
STANDARD 02
ISO/IEC 27001 — Information security management systems
- 01What it is
- The international standard specifying requirements for an information security management system (ISMS) — a model for establishing, implementing, operating, monitoring, reviewing, maintaining, and improving how an organization protects information.
- 02Mandatory or voluntary
- Voluntary, though frequently required by customers, partners, or regulators as a trust signal.
- 03Certifiable
- Yes. The current edition is ISO/IEC 27001:2022; organizations certified to the prior edition had until 31 October 2025 to complete their transition.
- 04Who it applies to
- Organizations of every type — private, public, and non-profit, across all sectors — though IT remains the sector with the largest share of certificates.
- 05Overlap note
- It can be combined with an ISO 9001 certification either as a fully integrated management system or as separate systems that share some structure. The same combinability applies to ISO/IEC 42001.
STANDARD 03
ISO/IEC 42001 — AI management systems
- 01What it is
- The international standard specifying requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS), for organizations that provide or use AI-based products or services.
- 02Mandatory or voluntary
- Voluntary — ISO does not certify organizations itself; independent, nationally accredited certification bodies do.
- 03Certifiable
- Yes. It follows the same Annex SL management-system structure as ISO 27001, making integration with an existing ISMS straightforward. Typical certification timelines run 6–18 months depending on organizational maturity.
- 04Who it applies to
- Any organization that develops, provides, or uses AI-based products or services, regardless of size, sector, or AI technique — including generative AI and autonomous agents.
- 05Relationship to regulation
- Often discussed alongside the EU AI Act because it maps well onto the Act's expectations for risk management, data governance, technical documentation, human oversight, and post-market monitoring — though certification to it does not by itself confer legal conformity with the Act.
STANDARD 04
NIST AI Risk Management Framework (AI RMF 1.0)
- 01What it is
- Voluntary U.S. guidance, published in January 2023, organized around four core functions — Govern, Map, Measure, and Manage — to help organizations design, develop, deploy, and use AI systems that are valid, reliable, safe, secure, accountable, transparent, and fair.
- 02Mandatory or voluntary
- Voluntary — created after Congress directed NIST to develop a voluntary framework balancing innovation with accountability.
- 03Certifiable
- No formal certification path exists; it's a reference framework, not an auditable standard like ISO/IEC 42001.
- 04Who it applies to
- Sector-agnostic — any organization building, buying, or operating AI systems.
- 05Current status
- Companion materials (playbooks, profiles, evaluation methodologies) have continued to expand through 2025–2026. No finalized “AI RMF 2.0” exists as of this writing.
- 06Related development
- NIST's separately launched AI Agent Standards Initiative addresses agent-specific identity and authorization gaps that AI RMF 1.0 does not cover in depth; finalized guidance from that initiative isn't expected before 2027.
STANDARD 05
EU AI Act
- 01What it is
- A binding EU regulation establishing risk-tiered obligations for AI systems — unacceptable-risk practices are prohibited outright, high-risk systems carry the heaviest compliance burden, limited-risk systems carry transparency duties, and minimal-risk systems carry none.
- 02Mandatory or voluntary
- Mandatory for organizations placing AI systems on the EU market or affecting people in the EU, regardless of where the organization is headquartered.
- 03Certifiable
- Not certifiable in the ISO sense — compliance is demonstrated through conformity assessment (for high-risk systems) and documentation, not a voluntary third-party certificate.
- 04Current status and timeline
- The Digital Omnibus on AI was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. High-risk obligations for stand-alone Annex III systems are now deferred to 2 December 2027, and for AI embedded in regulated products under Annex I, to 2 August 2028. The Article 50(2) synthetic-content marking duty is deferred to 2 December 2026, and national AI regulatory sandboxes to 2 August 2027. Article 50's core transparency duties took effect on schedule on 2 August 2026, regardless of the high-risk delay, and prohibited-practice rules and GPAI obligations were already in force before this delay and remain unaffected.
- 05Penalties
- Violations of the prohibited-practices regime carry the Act's steepest tier — up to €35 million or 7% of global annual turnover, whichever is higher — compared with up to €15 million or 3% for most other high-risk and GPAI violations.
Where they overlap
Cross-reference table
| Control area | ISO 9001 | ISO/IEC 27001 | ISO/IEC 42001 | NIST AI RMF | EU AI Act |
|---|---|---|---|---|---|
| Risk management | Yes (risk-based thinking, Clause 6) | Yes (information-security risk assessment) | Yes (AI-specific risk & opportunity) | Yes (Map/Measure functions) | Yes (risk-tiering is the Act's core structure) |
| Governance & accountability | Yes (leadership, Clause 5) | Yes (leadership commitment) | Yes (AI policy, roles, responsibilities) | Yes (Govern function) | Yes (obligations on providers/deployers) |
| Lifecycle management | Partial (product/service realization) | Partial (ISMS lifecycle) | Yes (full AI lifecycle: design to decommission) | Yes (across AI lifecycle) | Yes (pre- and post-market obligations) |
| Third-party / supply-chain oversight | Partial (supplier control, Clause 8) | Yes (supplier relationships, Annex A controls) | Yes (AI value-chain, Annex A controls) | Partial (addressed in categories, not a dedicated function) | Yes (obligations flow to providers, deployers, and importers) |
| Transparency & explainability | Not a focus | Not a focus | Yes (explicit requirement) | Yes (a named trustworthiness characteristic) | Yes (Article 50 transparency duties; explainability expected for high-risk systems) |
| Continuous improvement / monitoring | Yes (Clause 10, PDCA) | Yes (PDCA, continual improvement) | Yes (PDCA, continual improvement) | Yes (Manage function, post-deployment monitoring) | Yes (post-market monitoring obligations for high-risk systems) |
Regulatory Scope
We map to these frameworks. We don't issue them.
Independent certification & continuous evidence
HyperOps doesn't certify your organization against ISO 9001, 27001, or 42001, and it can't make you legally compliant with the EU AI Act by itself — those are things only accredited certification bodies and your own legal judgment can confirm. What the platform does is map the controls, decisions, and evidence you generate while running it to the specific clauses and obligations in each of these frameworks, so the evidence an auditor or regulator asks for already exists in the form they recognize.
See your evidence mapped to the frameworks you're on.
Questions
The short answers
No — certification is voluntary, though a growing number of customers and regulators treat it as a trust signal, and it maps well onto EU AI Act expectations without itself conferring legal compliance.
No — it's voluntary reference guidance with no formal certification path, unlike ISO/IEC 42001, which is a certifiable standard.
Yes — high-risk system obligations were deferred (to December 2027 for standalone systems, August 2028 for product-embedded systems), but transparency duties and prohibited-practice rules were not delayed and remain in force on their original or newly-added dates.
Significantly — they share the same management-system structure, which is why many organizations pursuing both build one integrated system rather than two separate ones.
No — HyperOps maps your evidence to these frameworks; certification itself is issued by independent, accredited certification bodies.