HyperOpsHyperOps

Framework Reference

The frameworks, in plain language.

What each standard actually requires, whether it's mandatory or voluntary, whether you can get certified against it, and how they overlap. No sales pitch — just the reference.

STANDARD 01

ISO 9001 — Quality management systems

01What it is
The international standard for quality management systems — a framework that helps organizations deliver consistent products and services, improve efficiency, and meet customer and regulatory expectations. It covers context of the organization, planning, support, operation, performance evaluation, and improvement.
02Mandatory or voluntary
Voluntary, though customers or contracts in some sectors may require it.
03Certifiable
Yes, via independent accredited certification bodies.
04Who it applies to
Used across nearly every sector — manufacturing, services, healthcare, education, construction, technology, and public administration.
05Current status
ISO 9001:2015 is the current edition. A revised edition, ISO 9001:2026, is expected to publish around September 2026 following a 2023 international consensus that a revision would add value. [Publication date and transition timeline to be confirmed once ISO formally releases it.]

STANDARD 02

ISO/IEC 27001 — Information security management systems

01What it is
The international standard specifying requirements for an information security management system (ISMS) — a model for establishing, implementing, operating, monitoring, reviewing, maintaining, and improving how an organization protects information.
02Mandatory or voluntary
Voluntary, though frequently required by customers, partners, or regulators as a trust signal.
03Certifiable
Yes. The current edition is ISO/IEC 27001:2022; organizations certified to the prior edition had until 31 October 2025 to complete their transition.
04Who it applies to
Organizations of every type — private, public, and non-profit, across all sectors — though IT remains the sector with the largest share of certificates.
05Overlap note
It can be combined with an ISO 9001 certification either as a fully integrated management system or as separate systems that share some structure. The same combinability applies to ISO/IEC 42001.

STANDARD 03

ISO/IEC 42001 — AI management systems

01What it is
The international standard specifying requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS), for organizations that provide or use AI-based products or services.
02Mandatory or voluntary
Voluntary — ISO does not certify organizations itself; independent, nationally accredited certification bodies do.
03Certifiable
Yes. It follows the same Annex SL management-system structure as ISO 27001, making integration with an existing ISMS straightforward. Typical certification timelines run 6–18 months depending on organizational maturity.
04Who it applies to
Any organization that develops, provides, or uses AI-based products or services, regardless of size, sector, or AI technique — including generative AI and autonomous agents.
05Relationship to regulation
Often discussed alongside the EU AI Act because it maps well onto the Act's expectations for risk management, data governance, technical documentation, human oversight, and post-market monitoring — though certification to it does not by itself confer legal conformity with the Act.

STANDARD 04

NIST AI Risk Management Framework (AI RMF 1.0)

01What it is
Voluntary U.S. guidance, published in January 2023, organized around four core functions — Govern, Map, Measure, and Manage — to help organizations design, develop, deploy, and use AI systems that are valid, reliable, safe, secure, accountable, transparent, and fair.
02Mandatory or voluntary
Voluntary — created after Congress directed NIST to develop a voluntary framework balancing innovation with accountability.
03Certifiable
No formal certification path exists; it's a reference framework, not an auditable standard like ISO/IEC 42001.
04Who it applies to
Sector-agnostic — any organization building, buying, or operating AI systems.
05Current status
Companion materials (playbooks, profiles, evaluation methodologies) have continued to expand through 2025–2026. No finalized “AI RMF 2.0” exists as of this writing.
06Related development
NIST's separately launched AI Agent Standards Initiative addresses agent-specific identity and authorization gaps that AI RMF 1.0 does not cover in depth; finalized guidance from that initiative isn't expected before 2027.

STANDARD 05

EU AI Act

01What it is
A binding EU regulation establishing risk-tiered obligations for AI systems — unacceptable-risk practices are prohibited outright, high-risk systems carry the heaviest compliance burden, limited-risk systems carry transparency duties, and minimal-risk systems carry none.
02Mandatory or voluntary
Mandatory for organizations placing AI systems on the EU market or affecting people in the EU, regardless of where the organization is headquartered.
03Certifiable
Not certifiable in the ISO sense — compliance is demonstrated through conformity assessment (for high-risk systems) and documentation, not a voluntary third-party certificate.
04Current status and timeline
The Digital Omnibus on AI was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. High-risk obligations for stand-alone Annex III systems are now deferred to 2 December 2027, and for AI embedded in regulated products under Annex I, to 2 August 2028. The Article 50(2) synthetic-content marking duty is deferred to 2 December 2026, and national AI regulatory sandboxes to 2 August 2027. Article 50's core transparency duties took effect on schedule on 2 August 2026, regardless of the high-risk delay, and prohibited-practice rules and GPAI obligations were already in force before this delay and remain unaffected.
05Penalties
Violations of the prohibited-practices regime carry the Act's steepest tier — up to €35 million or 7% of global annual turnover, whichever is higher — compared with up to €15 million or 3% for most other high-risk and GPAI violations.

Where they overlap

Cross-reference table

Control areaISO 9001ISO/IEC 27001ISO/IEC 42001NIST AI RMFEU AI Act
Risk managementYes (risk-based thinking, Clause 6)Yes (information-security risk assessment)Yes (AI-specific risk & opportunity)Yes (Map/Measure functions)Yes (risk-tiering is the Act's core structure)
Governance & accountabilityYes (leadership, Clause 5)Yes (leadership commitment)Yes (AI policy, roles, responsibilities)Yes (Govern function)Yes (obligations on providers/deployers)
Lifecycle managementPartial (product/service realization)Partial (ISMS lifecycle)Yes (full AI lifecycle: design to decommission)Yes (across AI lifecycle)Yes (pre- and post-market obligations)
Third-party / supply-chain oversightPartial (supplier control, Clause 8)Yes (supplier relationships, Annex A controls)Yes (AI value-chain, Annex A controls)Partial (addressed in categories, not a dedicated function)Yes (obligations flow to providers, deployers, and importers)
Transparency & explainabilityNot a focusNot a focusYes (explicit requirement)Yes (a named trustworthiness characteristic)Yes (Article 50 transparency duties; explainability expected for high-risk systems)
Continuous improvement / monitoringYes (Clause 10, PDCA)Yes (PDCA, continual improvement)Yes (PDCA, continual improvement)Yes (Manage function, post-deployment monitoring)Yes (post-market monitoring obligations for high-risk systems)

Regulatory Scope

We map to these frameworks. We don't issue them.

EVIDENCE MAPPING VS CERTIFICATION

Independent certification & continuous evidence

HyperOps doesn't certify your organization against ISO 9001, 27001, or 42001, and it can't make you legally compliant with the EU AI Act by itself — those are things only accredited certification bodies and your own legal judgment can confirm. What the platform does is map the controls, decisions, and evidence you generate while running it to the specific clauses and obligations in each of these frameworks, so the evidence an auditor or regulator asks for already exists in the form they recognize.

See your evidence mapped to the frameworks you're on.

Questions

The short answers

No — certification is voluntary, though a growing number of customers and regulators treat it as a trust signal, and it maps well onto EU AI Act expectations without itself conferring legal compliance.

No — it's voluntary reference guidance with no formal certification path, unlike ISO/IEC 42001, which is a certifiable standard.

Yes — high-risk system obligations were deferred (to December 2027 for standalone systems, August 2028 for product-embedded systems), but transparency duties and prohibited-practice rules were not delayed and remain in force on their original or newly-added dates.

Significantly — they share the same management-system structure, which is why many organizations pursuing both build one integrated system rather than two separate ones.

No — HyperOps maps your evidence to these frameworks; certification itself is issued by independent, accredited certification bodies.