M ManySignal

Compliance — ISO 42001 AI Management

ISO 42001 AI Management System — monitoring evidence for AI operations

ISO 42001:2023 requires organisations to monitor AI systems in operation — detecting access anomalies, behavioural deviations, and AI-specific security incidents. ManySignal monitors AI infrastructure, model access patterns, and training data pipelines — with audit trail evidence for EU AI Act Article 13-14 requirements.

Control mapping — ISO 42001 to ManySignal

Control ReferenceControl NameManySignal Capability
ISO 42001 6.1 Actions to Address Risks and Opportunities AI system threat monitoring — anomalous model access, training data modification attempts, and inference system abuse
ISO 42001 8.2 AI Risk Assessment Runtime risk indicators — model behaviour anomalies, data drift detection integration, and access pattern deviations
ISO 42001 8.4 AI System Operation and Monitoring Continuous monitoring of AI inference infrastructure — access logging, API anomaly detection, and output integrity monitoring
ISO 42001 A.5 AI Risk Identification and Treatment (Annex A) AI-specific threat intelligence — prompt injection attack patterns, model exfiltration techniques, and adversarial input detection
ISO 42001 A.6 AI System Impact Assessment Incident management for AI-related incidents — classification, evidence collection, and impact documentation
ISO 42001 A.9 Human Oversight of AI Systems Audit trail for AI model decisions affecting users — access log evidence supporting human oversight requirements
ISO 42001 A.10 Responsible Use of AI Data access monitoring for AI training pipelines — detecting misuse of personal data in model training

Certification status

ManySignal's ISO 42001:2023 certification is in progress. AI management system documentation and current status available at trust@manysignal.com. SOC 2 Type II (which covers the security controls underpinning our AI operations) available under NDA.

ISO 42001 AI management — common questions

What is ISO 42001 and who needs it?

ISO 42001:2023 is the international standard for AI Management Systems — the AI equivalent of ISO 27001 for information security. It provides a framework for responsibly developing, deploying, and using AI systems. Organisations developing or deploying AI — AI labs, AI-native SaaS companies, and enterprises using AI in high-risk contexts — increasingly face requirements from customers, regulators (EU AI Act), and supply chain partners to demonstrate ISO 42001 alignment or certification.

How does ManySignal address ISO 42001 Section 8.4 (AI System Operation and Monitoring)?

Section 8.4 requires organisations to monitor their AI systems in operation — detecting deviations from expected behaviour, access anomalies, and operational incidents. ManySignal monitors the infrastructure hosting AI systems: API gateway access logs (who calls the model, with what inputs, at what volume), cloud infrastructure anomalies (GPU workload irregularities, storage access outside normal ML pipelines), and identity events (engineer access to model weights and training data).

Does ManySignal itself hold ISO 42001 certification?

ManySignal's ISO 42001:2023 certification is in progress — reflecting our commitment to AI governance given that ManySignal itself is an AI-powered platform. The current certification status and our AI management practices documentation are available at trust@manysignal.com.

How does ISO 42001 relate to the EU AI Act?

The EU AI Act (Regulation 2024/1689) imposes technical and governance requirements on high-risk AI systems. ISO 42001 is expected to become a conformance route for demonstrating compliance with EU AI Act obligations — similar to how ISO 27001 serves as a conformance route for GDPR's Article 32 technical measures. ManySignal monitors AI system infrastructure and provides the audit trail evidence required by EU AI Act Article 13 (transparency) and Article 14 (human oversight).

Can ManySignal detect prompt injection attacks against LLM systems?

ManySignal monitors the API gateway and application logs for LLM systems — detecting prompt injection attack patterns via anomalous input length, unusual character sequences, and output patterns that suggest successful injection. For enterprise LLM deployments (Copilot, OpenAI API, Anthropic API), ManySignal's API access monitoring baselines normal usage patterns and flags anomalies that could indicate injection attempts or data exfiltration via model outputs.

Monitor your AI systems for ISO 42001

Connect your AI API gateways, cloud infrastructure, and model storage. We'll demonstrate ISO 42001 Section 8.4 monitoring evidence generation in one session.