SECTION 11
11Alignment with international standards
UCSMM is built to work with three international standards at once. ISO/IEC 27001 protects information and systems; ISO/IEC 42001 manages AI across its lifecycle; ISO 45003:2021 — guidance within ISO 45001:2018 — guides the protection of the psychological health and safety of the people who work with it.
Each standard governs its own domain. UCSMM is the cognitive layer that connects them: it measures the maturity of all three as one capability, in four dimensions, and tells the organisation which one to raise next.

Text in this figure
ISO/IEC 27001 · Information security · Protects data, systems and identities through an audited management system. · ISO/IEC 42001 · AI management system · Governs AI policy, impact assessment, data and the system lifecycle. · ISO 45003 · Psychological health & safety · Guides the protection of people from psychosocial risk: workload, role clarity, exposure to harmful events. · UCSMM — measures all three as one capability
| UCSMM | ISO/IEC 27001 | ISO/IEC 42001 | ISO 45003 |
|---|---|---|---|
| Cl. 5 Leadership · A.5.1 Policies · A.5.2 Roles Leadership, policy and named roles | A.2 AI policy · A.3 Internal organisation · A.5 Impact assessment AI policy, accountability and impact assessment | ||
| A.5.24–5.28 Incidents · A.5.29–5.30 Continuity Incident response and continuity | A.6 Lifecycle · A.10 Third parties Deployment, operation, rollback and suppliers | Harmful events Support after major incidents | |
| D3 Intelligent detection | A.5.7 Threat intelligence · A.8.16 Monitoring Threat intelligence and monitoring | A.7 Data for AI · A.6 Lifecycle monitoring Data quality, provenance and model monitoring | Workload Alert load per analyst as an indicator |
| D4 Adaptive management | Cl. 9 Evaluation · Cl. 10 Improvement · A.6.3 Awareness Measurement, improvement and training | Cl. 9–10 · A.4 Resources Review, improvement and competence | Participation Worker participation and training on manipulation |
Each standard answers “is it in place?” — UCSMM answers “how mature is it, and what comes next?”
Clause and control references follow ISO/IEC 27001:2022, ISO/IEC 42001:2023 and ISO 45003:2021.
UCSMM in one line
Four dimensions to build, five levels to climb, twenty questions to locate the organisation, three waves to move it — and one rule: it is only as strong as its weakest dimension.
Tip: use ← → to move between sections.
