ISO/IEC 42001:2023 AI management alignment
Frameworks · ISO/IEC 42001:2023 · v2026.06 · Alignment matrix between ISO/IEC 42001:2023 (AI Management System) and Foundry’s AI governance program. Last refreshed June 2026.
Status Implemented
Main-body clauses (4–10)
| Clause | Topic | Foundry posture | Policy | Status |
|---|---|---|---|---|
| 4 | Context of the organization | Foundry runs agentic workflows over the operations of independent physician practices. Interested parties include member practices, their patients, regulators (HIPAA + state), and AI subprocessors. | AI governance, Program overview | Implemented |
| 5 | Leadership | Security Officer accountable for AI risk; AI governance policy is the top-level statement. Executive sign-off is part of policy management. | AI governance, Roles & training | Implemented |
| 6 | Planning (AI risk & opportunities, AI objectives) | AI risk assessment runs alongside the broader risk register, with attention to PHI exposure, bias, hallucination, and human-oversight failure modes. AI objectives are tracked against engineering OKRs. | Risk management, AI governance | Implemented |
| 7 | Support (resources, AI competence, awareness, communication) | Workforce AI-literacy training covers Atlas, Forge Agents, and the Beacon Layer; communication of AI changes is built into change management. | Roles & training, CCM | Implemented |
| 8 | Operation (AI system lifecycle) | Spec-led cycles in foundry-master-agent capture AI changes; threat modeling, eval gates, and shadow-mode rollouts precede production. Sandboxed (Tier-4) workers run untrusted execution. | AI governance, SDLC | Implemented |
| 9 | Performance evaluation (monitoring, measurement, internal audit, management review) | Eval suites run against agent changes; audit codes capture every PHI read and write; management review of AI performance happens with the broader security program review. | System audits, AI governance | Implemented |
| 10 | Improvement | Post-incident reviews specific to AI failures (e.g., redaction misses, agent overreach) feed corrective action; AI changes that fail eval gates do not ship. | IR, AI governance | Implemented |
Annex A controls: AI-specific
ISO/IEC 42001:2023 Annex A organizes AIMS controls under nine objectives (A.2–A.10). This page maps each objective to the corresponding Foundry policy and posture.
A.2 Policies related to AI
| Control area | Foundry posture | Policy | Status |
|---|---|---|---|
| A.2.2 AI policy · A.2.3 Alignment with other organizational policies · A.2.4 Review of AI policy | The AI governance policy is the top-level AI statement; it cross-references data protection, access, SDLC, and incident response. Policies are reviewed annually or on material change. | AI governance, Policy mgmt | Implemented |
A.3 Internal organization
| Control area | Foundry posture | Policy | Status |
|---|---|---|---|
| A.3.2 AI roles & responsibilities · A.3.3 Reporting of concerns | Security Officer is accountable for AI governance. Workforce can raise concerns through security@bioscopefoundry.com or the non-retaliation channel. | Roles & training, AI governance | Implemented |
A.4 Resources for AI systems
| Control area | Foundry posture | Policy | Status |
|---|---|---|---|
| A.4.2–A.4.6 AI resources (data, tooling, system & computing, human, supplier) | Data, model, tooling, and compute resources for AI systems are inventoried as part of asset management; HIPAA-eligible vendors only for PHI-touching AI; workforce competence requirements are documented. | Asset mgmt, Vendor | Implemented |
A.5 Assessing impacts of AI systems
| Control area | Foundry posture | Policy | Status |
|---|---|---|---|
| A.5.2 AI system impact assessment · A.5.3 Documentation · A.5.4 Impact on individuals · A.5.5 Impact on society | AI system impact assessment is required for any new agentic capability that touches PHI, makes a recommendation a clinician will act on, or affects a physician’s livelihood (e.g., compliance determinations). Beacon Layer is documented as the redaction boundary. | AI governance, Privacy | Implemented |
A.6 AI system lifecycle
| Control area | Foundry posture | Policy | Status |
|---|---|---|---|
| A.6.1 Management guidance for AI development · A.6.2 AI system requirements, design, development & operation | Spec-led cycles in foundry-master-agent capture requirements, design, and audit-code definitions before code lands. Eval suites and shadow-mode rollouts precede production. Audit codes (machine-readable, never PHI text) cover every agent action. | AI governance, SDLC | Implemented |
| A.6.2.4 Verification & validation · A.6.2.5 Deployment · A.6.2.6 Operation & monitoring · A.6.2.7 Documentation | Eval gates block merge when a regression crosses thresholds; deployments are versioned through change management; production agents emit audit codes consumed by monitoring; system docs are byte-deterministic and regenerated on schema change. | CCM, System audits | Implemented |
A.7 Data for AI systems
| Control area | Foundry posture | Policy | Status |
|---|---|---|---|
| A.7.2 Data for AI · A.7.3 Acquisition · A.7.4 Quality · A.7.5 Provenance · A.7.6 Preparation | PHI used by agents is FHIR-resident and accessed live (no training-set copies on disk). Beacon Layer redaction governs which fields flow into sanitized physician-facing surfaces. Provenance is recorded via audit codes. Data quality is monitored as part of FHIR validation. | Data mgmt, Data protection, AI governance | Implemented |
A.8 Information for interested parties
| Control area | Foundry posture | Policy | Status |
|---|---|---|---|
| A.8.2 System documentation · A.8.3 External reporting · A.8.4 Communication of incidents · A.8.5 Information for interested parties | This Trust Center, the Privacy Policy, the HIPAA Notice, and incident notifications under BAA terms together discharge the external-information obligations. | AI governance, Privacy Policy | Implemented |
A.9 Use of AI systems
| Control area | Foundry posture | Policy | Status |
|---|---|---|---|
| A.9.2 Processes for responsible use · A.9.3 Objectives · A.9.4 Intended use | AI outputs augment, not replace, human judgment: material decisions (membership, compliance determinations, clinical workflows) are reviewed by a person. Acceptable-use guidance is published to the workforce and embedded in agent runbooks. | AI governance, HR & personnel | Implemented |
A.10 Third-party & customer relationships
| Control area | Foundry posture | Policy | Status |
|---|---|---|---|
| A.10.2 Allocation of responsibilities · A.10.3 Suppliers · A.10.4 Customers | BAA + MSA define responsibilities between Foundry and member practices for AI-assisted workflows. AI subprocessors that touch PHI are bound by BAA; non-PHI AI tooling is bound by DPAs and security requirements. | Vendor, BAA, Subprocessors | Implemented |
ISO 42001 applicability to Foundry
Foundry is unusual: an MSO whose value proposition is an AI-enabled operating layer over PHI. The same platform runs both PHI-eligible clinic-scoped agents (Tier-3) and sandboxed workers that cannot hold PHI (Tier-4 Moltworkers). ISO/IEC 42001 gives us a standard against which to demonstrate that this tiering is principled, documented, and audited, not an internal implementation detail. The compliance program sequences 42001 alongside 27001 so the AIMS and ISMS land together.