Server data from the Official MCP Registry
AI-powered iso 42001 ai MCP server for agents. Supports audit management system, assess ai r...
AI-powered iso 42001 ai MCP server for agents. Supports audit management system, assess ai r...
This ISO 42001 compliance assessment MCP server has moderate security concerns stemming from insufficient authentication enforcement, overly broad path traversal patterns in code, and incomplete error handling in critical security paths. While the server's stated purpose (compliance assessment) aligns with its permissions, the authentication middleware is optional and authentication failures are silently tolerated rather than enforced, creating a gateway vulnerability. The codebase also exhibits patterns suggesting incomplete implementation that could enable unauthorized access to rate-limited features. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.
4 files analyzed · 14 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
This plugin requests these system permissions. Most are normal for its category.
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-csoai-org-iso-42001-ai-mcp": {
"args": [
"-y",
"iso-42001-ai-mcp"
],
"command": "npx"
}
}
}From the project's GitHub README.
AI Management System (AIMS) assessment, certification readiness, and EU AI Act crosswalk against ISO/IEC 42001:2023.
Install · Tools · Pricing · Attestation API
ISO 42001:2023 is the world's first certification standard specifically for AI management systems. It defines what an organisation must do to develop, deploy, and maintain AI responsibly. Certification bodies (BSI, TUV, SGS, Bureau Veritas) are now issuing ISO 42001 certificates, and enterprises are requesting it in procurement.
The standard has 39 Annex A controls and 9 management system clauses. Mapping these to your AI lifecycle, crosswalking to EU AI Act conformity assessment, and preparing for a Stage 1/Stage 2 audit typically costs 20-50K in consultancy fees. This MCP performs the full AIMS assessment, risk analysis, policy generation, Annex A control checks, EU AI Act crosswalk, and certification timeline planning from a single prompt.
pip install iso-42001-ai-mcp
| Tool | ISO Reference | What it does |
|---|---|---|
audit_management_system | Clauses 4-10 | Full AIMS audit against ISO 42001:2023 management clauses |
assess_ai_risk | Clause 6.1 | AI-specific risk assessment with impact and likelihood scoring |
generate_policy_template | Clause 5.2, Annex A | Generate AI policy aligned to management commitment requirements |
check_annex_controls | Annex A (39 controls) | Control-by-control assessment of all Annex A objectives |
crosswalk_to_eu_ai_act | Annex A + EU AI Act | Map ISO 42001 controls to EU AI Act conformity requirements |
create_certification_checklist | Stage 1 / Stage 2 | Certification readiness checklist with timeline |
predict_risk_neural | ML-assisted | Neural network risk prediction for AI systems |
quick_scan | All clauses | Rapid AI system compliance overview |
certification_timeline | Full lifecycle | Stage 1/Stage 2 audit timeline and milestones |
Prompt: "Assess our computer vision system for ISO 42001 certification
readiness. It processes facial images for building access control,
was trained on a proprietary dataset, and has no explainability layer."
Result: AIMS assessment with findings across Annex A controls: biometric
processing triggers A.6.2.4 (impact assessment), missing explainability
fails A.6.2.6 (transparency), proprietary dataset needs A.7.3 (data
management). EU AI Act crosswalk flags Annex III high-risk classification.
Certification timeline generated with 14-week remediation path.
| Tier | Price | What you get |
|---|---|---|
| Free | £0 | 10 calls/day — AIMS audit + quick scan |
| Pro | £199/mo | Unlimited + HMAC-signed attestations + verify URLs |
| Enterprise | £1,499/mo | Multi-tenant + co-branded reports + webhooks |
Every Pro/Enterprise audit produces a cryptographically signed certificate:
POST https://meok-attestation-api.vercel.app/sign
GET https://meok-attestation-api.vercel.app/verify/{cert_id}
Zero-dep verifier: pip install meok-attestation-verify
MIT
Be the first to review this server!
by Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
by Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
by mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.