A practical way to combine an organisation-wide AI management system with Singapore’s AI governance guidance and testing tools.
How do ISO/IEC 42001 and AI Verify fit together?
ISO/IEC 42001 defines an AI management system: the organisational responsibilities, policies, risk decisions, lifecycle controls, review, and improvement needed to manage AI. AI Verify is a Singapore-developed governance testing framework and toolkit. The AI Verify Foundation has published a crosswalk mapping ISO/IEC 42001 controls to AI Verify process checks.
Use the crosswalk as an evidence-design aid. A test result can inform a system-level decision within the management system, while the AIMS explains who selected the test, how its limits were considered, and what happened after the result. Running a toolkit is not the same as establishing an AIMS, and a test result is not an ISO/IEC 42001 certificate.
Scope the use case before choosing a test
Describe the system’s intended purpose, users, affected groups, inputs, outputs, supplier dependencies, and level of human involvement. Singapore’s Model AI Governance Framework points to internal governance, human involvement, operations management, and stakeholder communication. Those themes help determine what should be assessed for a particular deployment.
Select evaluation methods according to the system and risk. AI Verify and IMDA’s Project Moonshot provide testing approaches relevant to different AI systems, including generative applications. Record the test configuration, data, results, known limitations, and acceptance decision. A model-level score alone may not represent how the full application behaves with prompts, retrieval, users, and downstream workflows.
Build an evidence chain for procurement and release
For each significant AI use, connect four records: the business purpose and owner; the risk and impact assessment; the selected evaluation and results; and the decision to deploy, restrict, or reject the use. Preserve supplier claims separately from what your own organisation tested. If a vendor changes a model or feature, review whether the original evaluation still supports the approved use.
The management system should also specify how issues are reported, who can suspend a deployment, and how corrective actions reach leadership. These arrangements are especially useful when a Singapore-based provider must answer customer questions across several markets with different assurance expectations.
How should the outcome be described to buyers?
State the actual scope: which organisation and systems are within the AIMS, which application was tested, which method was used, and when the evidence was produced. Link the test result to the relevant governance decision. Avoid a broad claim that every AI output is safe or that a crosswalk automatically satisfies all ISO/IEC 42001 requirements.
If independent certification is pursued, a certification body determines conformity to the standard within its assessed scope. Singapore’s governance guidance and AI Verify results can support the organisation’s work, while legal duties and sector-specific obligations still require their own analysis.
Put it into practice
- Identify the AI systems and activities included in the proposed AIMS scope.
- Choose system-specific tests based on intended use and risk.
- Retain test settings, results, limitations, and the deployment decision together.
- Use the AI Verify–ISO/IEC 42001 crosswalk to identify relevant process evidence.
- Reassess a system after material changes to its model, data, supplier, or use.
Primary sources
- ISO: ISO/IEC 42001 AI management systems
- AI Verify Foundation: ISO/IEC 42001 crosswalk and resource library
- IMDA: artificial intelligence governance and testing initiatives
- PDPC: Singapore’s approach to AI governance
Normstone resources are general information, not legal advice or an independent assessment.