Skip to content
Atlassian Forge app for Jira Service Management

Your AI governance, in the tool your team already opens.

AIMS-in-a-Box keeps your AI system register, works out what the EU AI Act asks of each system, tracks the 65 ISO/IEC 42001 controls, and generates the documents an auditor asks for. It runs entirely inside Jira. Nothing leaves Atlassian.

The Marketplace listing is not published yet, so the button above writes to us instead.

The AI Management System overview page inside Jira, showing 54% ISO/IEC 42001 readiness, tiles for 7 AI systems and 2 high-risk systems, and a readiness bar for each clause.
Illustration The workspace, on the Apps menu of a Jira Service Management site. One readiness figure, the things that need attention, and a breakdown by ISO/IEC 42001 section.

The problem, stated plainly

You sell software to enterprises. Their procurement teams have started asking what AI you use and how you govern it, and the honest answer lives in three spreadsheets, a Confluence page somebody started in March, and one person's head.

The EU AI Act is in force

Obligations are phasing in through 2026 and 2027. Which ones apply depends on what each system does and whether you are its provider or its deployer — a question most teams have never written down system by system.

ISO/IEC 42001 is what buyers ask for

It is becoming the shorthand for "this vendor governs its AI". Certification is a project; knowing where you stand against its 65 controls should not be.

Consultants cost £10k–£25k

And they leave you with a document set that is out of date the week after they go. The work is ongoing; the tooling should be too.

What it does

Six things, numbered in the order you will use them. Each one feeds the next.

AI system register

Every AI system you build or use, with its purpose, its owner, your role — provider, deployer or both — and its lifecycle stage. Everything else reads from this list.

EU AI Act classification

A seven-question wizard resolves each system to prohibited, high, limited or minimal risk, and lists the obligations that follow, with the articles. Where the Act is ambiguous it takes the safer tier and flags the system for review.

ISO 42001 gap tracker

65 controls — 27 across clauses 4–10 and 38 from Annex A. Status, owner, notes, evidence, and an append-only history of who changed what.

Evidence register

What proves each control is in place and where it lives, linked to the controls it covers. The app records the reference; your documents stay where you already keep them.

Readiness self-assessment

18 questions across 6 weighted domains, in about five minutes. Every run is kept, so the movement is visible.

Audit-ready documents

6 documents generated from your own data. Each version is an immutable snapshot — print it, or save it as a PDF.

See each of these in detail →

Zero external systems

This is the part a security reviewer cares about, so it is worth being exact. There is no database of ours, no payment provider, no mail provider, no analytics and no error reporting. The app's manifest declares no external permissions at all, and a test in the codebase asserts their absence.

0
External services
0
Bytes of your data leaving Atlassian
3
Jira scopes requested
0
Files we store on your behalf

Read the security page →

Who does what

There is one AI Management System per Jira site, because an organisation has one AIMS — ISO/IEC 42001 is certified against a scope, not a department.

Jira administrators

Administer the AIMS. No separate owner list to keep in step with reality.

Contributors

Maintain the register, the controls and the evidence, and generate documents. They can also delete systems and evidence records.

Readers

See everything, change nothing. The right level for an auditor or a reviewer.

Access is granted by project administrators

Nobody but a Jira administrator sees any AIMS content until a project administrator grants it, from a project they administer. The grant records which project it came from and who issued it — which is the question an auditor actually asks. The full model →

The ISO/IEC 42001 gap tracker showing controls 4.1 to 9.2 with status lozenges, evidence counts, owners and last-updated dates.
Illustration The gap tracker. Filter to what is not started, set a status, name an owner, and see at a glance which controls have no evidence behind them.

Start here

Four guides, written as end-to-end walkthroughs rather than feature lists.

See it on your own Jira site

The Marketplace listing is not published yet, so there is nothing to link to. Email us and we will tell you the day there is.