ISO Compliance Suite (Imtithal) — ISO management system software — 42001, 27001, 9001

Imtithal turns ISO compliance from binders into a living system: each standard (ISO 42001, 27001, 9001 and 20 more) ships as structured data over one engine — requirements, controls, evidence collection, internal audits, nonconformities and corrective actions — with cross-standard mapping so shared controls count once.

Book a live demo

What you get

  • 23 ISO standards, including the AI-governance family (42001, 23894, 42005)
  • Clause-by-clause requirements with owner assignment and status
  • Evidence vault linked to controls, with review cycles
  • Internal audit planning, findings and corrective-action loops
  • Cross-standard control mapping — one control satisfies many standards
  • Bilingual Arabic/English, built RTL-first

What each role gets

  • Compliance officer — Compliance officers own the full conformity loop for every ISO standard the company runs — assigning clause and requirement owners, tracking control status, and driving nonconformities through corrective action to closure. Because controls map across standards, one access-control policy can satisfy both ISO 27001 and ISO 42001 at once instead of being evidenced twice, which matters the moment a company certifies against more than one standard. The whole program, including the AI-governance family (42001, 23894, 42005), runs from a single system instead of a separate binder per standard.
  • Auditor — Auditors plan and run internal audits against any of the 23 supported standards, log findings directly against the clauses and controls they touch, and track each corrective action through to closure inside the same system the rest of the compliance program uses. Cross-standard control mapping means a finding on a shared control is visible everywhere that control is used, not buried in just the standard being audited. The whole audit trail is bilingual Arabic/English and built RTL-first, so nothing gets lost in translation when findings get reviewed.
  • Control owner — Control owners get a focused queue of exactly the controls assigned to them, with an evidence vault built around review cycles — upload proof, track when it's due for renewal, and respond to audit findings without wading through the rest of the compliance program. Because controls map across standards, evidence logged against one control can satisfy more than one certification at once, so nothing has to be collected twice. It's a lightweight, day-to-day surface built for the people who hold the evidence, not for running the audit program itself.
  • Tenant admin — Tenant admins decide which of the 23 ISO standards — including the AI-governance family (ISO 42001, 23894, 42005) — are active for the company, assign roles across the compliance team, and pull reporting across the entire program from one place. Cross-standard control mapping means activating a second or third standard doesn't mean rebuilding the control set from scratch — shared controls carry over automatically. The whole platform runs bilingual and RTL-first, so Arabic-speaking teams work in a fully native interface rather than a translated afterthought.

Frequently asked questions

Is ISO 42001 (AI management) supported?

Yes — ISO/IEC 42001 is the flagship standard, alongside its AI-governance companions, with the same clause/control/evidence workflow as every other standard.

Can one control serve several standards?

Yes. Controls map across standards, so an access-control policy satisfies ISO 27001 and 42001 simultaneously instead of being duplicated per binder.

Part of one platform

ISO Compliance Suite (Imtithal) is one of 30+ modules sharing the same login, the same people, the same customers and the same AI copilot — see all modules or how Tarleaks ERP compares to Odoo, ERPNext and Zoho.