Article
AI governance before the AI strategy
Most organisations deploying AI cannot list the systems they already use. ISO 42001 starts there, which is why it is more useful than it sounds.
Prem Kumar Dvivedi · 12. September 2026
The first exercise in an ISO/IEC 42001 project is an inventory of the AI systems the organisation uses. It sounds administrative. It is almost always the moment the project earns its cost, because the list is longer than anybody expected and nobody owns half of it.
What the inventory turns up
A model embedded in a recruitment tool that screens applications. A vendor's fraud scoring that nobody inside can explain. A support chatbot trained on tickets that contain personal data. Three teams independently paying for the same assistant, one of them with customer data flowing through it. A spreadsheet macro nobody thinks of as AI making a decision that affects a person.
Each of those has a purpose, an owner, a data source and a consequence for somebody. Most have none of those recorded.
Why the inventory is the governance
Every obligation that follows — impact assessment, human oversight, transparency, data provenance, monitoring after deployment, the criteria for withdrawing a system — attaches to a specific system. Without the list, the policy is an aspiration. With it, the work becomes ordinary: for each system, who owns it, what it decides, who is affected, what the fallback is when it is wrong.
The distinction worth being clear about
A management system is not regulatory compliance. Where the EU AI Act applies, obligations attach to roles — provider, deployer, importer — and the first question is which role you occupy for each system. ISO/IEC 42001 gives you an auditable structure to hang those obligations on, and it maps onto risk management, data governance, technical documentation, record-keeping, transparency, human oversight and quality management. It does not discharge a legal duty, and anybody selling it as though it does is selling you something worthless.
Where it sits with what you already have
If you hold ISO/IEC 27001, you already have the risk method, the supplier controls, the incident process and the internal audit programme. ISO 42001 reuses all of it. If you hold ISO/IEC 27701 as well, the personal data questions are already answered. The marginal cost of AI governance for an organisation with a working information security system is modest; for one without, the AI standard is not the place to start.
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 42001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- ISO/IEC 27001:2022: documentation and compliance requirements
Everything ISO/IEC 27001:2022 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checkli
12. September 2026
- ISO/IEC 27701:2025: documentation and compliance requirements
Everything ISO/IEC 27701:2025 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checkli
12. September 2026
- ISO/IEC 42001:2023: documentation and compliance requirements
Everything ISO/IEC 42001:2023 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checkli
12. September 2026
