ISO/IEC 42001
Stage-1 documentation ready in weeks.
Skip the months of blank-page drafting. Encor writes the first version of every required artifact — your policy, SoA, per-system risk register, evidence plan — shaped to your AI systems and use cases. Your team reviews, approves, and books the audit.
14-day free trial · Card on file, billed only after the trial ends
Three moves to audit-ready.
129 plain-English questions, scored separately for Stage 1 and Stage 2.
Walk all 38 Annex A controls. Mark applicability. Justify exclusions.
37 required artifacts, populated from your answers, ready to export.
AI does the first pass.
Calibrated for ISO 42001. You review, edit, ship.
Per AI system.
Auditor voice.
Every Annex A control.
3-month evidence plan.
Auditor-credible.
Two stages. We handle the first. We coach the second.
Documentation
- AI policy + scope
- Roles + responsibilities
- Risk + impact procedures
- Statement of Applicability
Operational evidence
- Auto-generated 6-month Operating Effectiveness Report
- Per-system lifecycle stage tracking (A.6.2.2–A.6.2.8)
- AI Incident Response with 6.1.4 reassessment trigger
- Verified-effective NC closure (Clause 10.2.b)
We tell you what to collect — you can't skip the calendar.
Built to make Stage-1 documentation defensible — the kit your auditor reads first.
What we've shipped in the last quarter to take Encor from “demo-ready” to “your auditor's expecting it”.
Every artifact carries a recorded approver, role, version, and content snapshot. Auditors see signed status on every page header.
Rolling 6-month evidence summary. Audits / mgmt reviews / NCs / metric updates / risks reassessed, all per month, mapped to clauses.
Distinct from NCs and concerns. Categorised (bias / hallucination / drift / privacy / etc.) with the 6.1.4 reassessment trigger surfaced on the dashboard.
The Risk Treatment Plan §4 narrates *why* each Annex A control was selected for each risk — the question every Stage-2 auditor asks.
Requirements / Design / V&V / Deployment / Operation / Retirement per AI system. Drives which evidence applies.
Classification + lawful basis + retention captured at onboarding. Renders into the AI Policy and per-system Impact Records.
Blocks the audit-kit ZIP if any artifact ships with empty registers, unresolved placeholders, or under-50%-complete impact assessments.
Postgres Row-Level Security on every table; server-side ensureUserOrg() on every API route; 67 cross-tenant IDOR tests block every commit.
Google + Microsoft OAuth on sign-in. User-controlled TOTP MFA from /settings/security. Procurement-ready.
Ready in 25 minutes.
First pass through onboarding + assessment + SoA. Add your team, invite your auditor, export the kit.
14 days free · Card on file · No charge until trial ends · Cancel anytime