ISO/IEC 42001

The Foundation's position, in short. ISO/IEC 42001 certifies that an organization has a management system for AI. The Slop Audit measures the artifact that system produced. The two are complements, not competitors. The Foundation does not assess conformity to ISO/IEC 42001 and does not offer certification against it.

ISO/IEC 42001:2023 is the first international management-system standard for artificial intelligence. Organizations meet it through procurement, customer questionnaires, and their own risk committees. The question that follows is a fair one. Where does the Slop Audit sit in relation to it?

This page answers that directly. Some of the answer is that the two instruments do different work and should not be blurred together.

The answer rests on the discipline described on the Epistemology page. Every measuring instrument reveals the structure it was built to reveal. It is silent on structure outside that reach. Naming the reach of an instrument is not a criticism of it. It is the precondition for using it well, and it applies to the Foundation's own instruments first.

What ISO/IEC 42001 certifies

ISO/IEC 42001 specifies requirements for an AI management system. It sits in the same family as ISO/IEC 27001 for information security and ISO 9001 for quality. Its numbered clauses run from 4 to 10 and cover seven areas: the organization's AI context; leadership and AI policy; planning, including AI risk and impact assessment; support, such as competence and documented information; operation across the AI system life cycle; performance evaluation; and continual improvement.

Alongside those clauses, Annex A offers 38 reference controls arranged in nine groups:

Annex A is informative rather than normative. An organization selects the controls that apply to it through a Statement of Applicability driven by its own scope statement and its own risk and impact assessments, and it may exclude controls where it can justify the exclusion against that risk assessment. This is a sensible design for a management-system standard, and it is also the first thing a reader of a certificate needs to understand about what the certificate covers.

A valid ISO/IEC 42001 certificate is meaningful evidence. It says an independent, accredited assessor examined the organization's governance of AI against a published international standard and found it conformant within a declared scope. That is a genuine finding about a real property, and organizations that hold one have done real work to get it.

What the certificate does not tell you

A management-system standard governs process. It asks whether an organization has policies, assigned roles, risk assessments, documented procedures, and a review cycle, and whether it follows them. The object under assessment is the organization's system for doing the work. It does not guarantee the quality of what the system produces.

Code produced with AI assistance is what the Slop Audit assesses: an impartial, deterministic, automated evaluation of the quality measurement. This is needed because an organization can run a sound management system and still ship structurally fragile code.

The Foundation's commitment is to measure rather than assert based on expert opinion. So far the Foundation has tested the key Layer 1 indicator across 200 public open-source codebases. Approximately 99 per cent of non-React enterprise codebases proved structurally incapable of exhaustive behavioural verification. That property is invisible to a management-system audit. No clause of ISO/IEC 42001 asks for it, and no assessor is expected to compute it.

Two further boundaries of the certificate follow from how the standard is designed, and both are properties of every management-system standard rather than defects of this one:

None of this argues against certification. It argues that a certificate and an artifact measurement answer different questions, and that an organization cannot rely upon the first for assurance about the second.

Why the Slop Audit does not claim a mapping to ISO/IEC 42001

The Slop Audit scores codebases against the published thresholds of named compliance frameworks: SOC 2 Trust Services Criteria, NIST SP 800-53, OSFI B-13, OWASP ASVS, ISO/IEC 25010, WCAG 2.2, Section 508, EN 301 549, AODA, and Quebec Law 25. Every one of those is either a catalogue of technical controls or a product quality model. Each contains clauses that a measured property of code can be pointed at, which is what makes the mapping checkable by anyone who wants to check it.

ISO/IEC 42001 is a different kind of document. Pointing a mutable-state ratio at a clause about organizational roles would be a category error. Publishing one would undermine the Foundation's claim to authority.

A narrower statement is defensible, three of the Annex A control groups do reach the artifact and the evidence about it: the AI system life cycle (A.6), data for AI systems (A.7), and information for interested parties (A.8). Where the Slop Audit produces evidence relevant to specific controls in those groups, that is worth stating control by control. It is a smaller claim than a mapping to the standard, and it will be published as the smaller claim, with the scope named.

What the Slop Audit offers an organization certifying under ISO/IEC 42001

Evidence. Clause 9 requires an organization to evaluate how its AI management system performs, and the life-cycle controls reach verification and validation. An assessor asks what the organization did and what it found. Many arrive at that question holding policy documents and no artifact-level measurement to put beside them.

The Slop Audit produces exactly that artifact-level measurement, mechanically (automated) and reproducibly, and its Phase 0 audit already extracts a compliance-evidence package as a byproduct. An organization can run it against its own codebases and put the results in front of an assessor as evidence of what its verification activity actually established.

Two things this is not. Running a Slop Audit does not make an organization conformant to ISO/IEC 42001, and no result it produces should be represented that way. Nor does a Slop Audit result substitute for any part of a certification audit. The audit produces evidence; a conformity assessment decides what that evidence is worth.

What the Foundation does not do

The relationship in one sentence

ISO/IEC 42001 tells you an organization governs its AI work under an audited system. The Slop Audit tells you what the code that system produced is made of. An organization that wants both answers needs both instruments. Saying so plainly serves everyone better than a mapping table that does not hold up.

Sources and limits of this page

ISO/IEC 42001:2023 is a copyrighted standard published by the International Organization for Standardization and is not reproduced here. The structural description above is drawn from published secondary summaries: the clause range, the count and grouping of Annex A controls, the informative status of Annex A, and the role of the Statement of Applicability. It is stated only at the level of detail those summaries support. The standard itself is the authority. Any reader relying on this page for a compliance decision should consult it and their own assessor. The Foundation will correct anything here that is shown to be wrong, on the same terms it applies to its research.

This page states a position, not a finding. It is not a research output, carries no pre-registration, and should not be cited as one. The empirical claim it rests on, the 200-repository structural measurement, is published separately with its replication package under the research program.