STALE MEASUREMENTNewest real-model measurement: 26 days old, measured with v0.32.0; 7 releases have shipped since, past this project’s own 7-day window. Why, and what unblocks it

ProductEvidenceTop 10LeaderboardCompliancePricingDocsStar on GitHub Quickstart

STALE CLOCKThe regulatory entries on this page were last checked against their primary sources on 39 days before this build’s anchor of , past this project’s own 30-day window. Every date here was true when it was read and has not been re-read since. Verify against the primary source before relying on it. The clock, with every source

ISO/IEC 42001:2023

ISO/IEC 42001:2023

ISO/IEC 42001:2023 is the first certifiable management-system standard for artificial intelligence - the AI counterpart to ISO 27001. It asks an organisation to run AI risk as a managed, auditable process, and Provael slots in as an operational control: adversarial red-teaming with a documented, repeatable measurement.

Published December 2023 - the first certifiable AI management-system standard.Evidence, not certification.
What it is

The framework

  • ISO/IEC 42001:2023 specifies requirements for establishing, implementing, maintaining and continually improving an AI management system (AIMS).
  • Its Annex A lists operational controls; red-teaming and adversarial testing sit naturally among them as an evidence-producing control.
  • It is certifiable by accredited bodies, so enterprise buyers increasingly ask suppliers to hold it or work toward it.
  • Related AI standards: ISO/IEC 23894:2023 (AI risk management) and ISO/IEC TR 5469:2024 (AI functional safety); Provael produces evidence that feeds these processes rather than implementing them.
The hook

Where a red-team result fits

Annex A · operational control

Red-teaming as an operational control - a documented, repeatable adversarial test with a measured result and a retained trace is exactly the control evidence an AIMS audit looks for.

What Provael maps to it

Evidence produced

  • A repeatable adversarial-robustness measurement you can register as an operational control in your AIMS.
  • Retained traces and a one-page scorecard that serve as control evidence during a 42001 audit.
  • A CI red-team gate that turns the control from a point-in-time test into a continuously monitored one.
Timing

Dates (verified 26 Jul 2026)

Published
December 2023
How to read this mapping

What it is - and isn’t

  • adversarial-only - Provael measures adversarial robustness - susceptibility to manipulation - not general accuracy, reliability, or functional safety.
  • evidence-not-certification - The output is evidence you file, not a certificate. Provael is not a notified body, a lab, or a certification scheme.
  • behavioural-not-worst-case - Attacks are templated and auditable, not gradient- or search-optimised. Results are a floor on susceptibility - a behavioural lower bound, not a certified worst-case bound.
Evidence, not certification

Running Provael does not make a system compliant or certified - it generates measurements you can put into a conformity or assurance file.

Independent project. Not affiliated with or endorsed by ISO, the EU, NIST, IEC, OWASP, or MITRE. Not legal advice.

Clause references are indicative; a wrong clause citation is worse than a missing one.

Turn this into filed evidence.

Download the redacted sample pack, or book an assessment to get the crosswalk filled in for your policy.