AI Governance

    ISO 42001 and AI Regulation: Build One Governance System, Not Two

    ICyberWave Editorial
    Sep 26, 2026
    AI Governance
    Multidisciplinary team mapping AI governance, risk, data and human oversight

    The case for mapping instead of duplicating

    Organisations are being asked to govern AI through several overlapping lenses: regulation, customer assurance, enterprise risk, privacy, cybersecurity and responsible-use commitments. A common reaction is to create a separate programme for every framework. That produces duplicated registers, conflicting owners and evidence that cannot be traced to a decision.

    In an MSECB expert interview, Graeme Parker and Roman Krepki argue for mapping ISO/IEC 42001 to regulatory requirements rather than treating each as an isolated implementation. Their most important caution is equally clear: ISO 42001 certification does not automatically prove compliance with the EU AI Act. The standard can provide the management-system backbone, while legal obligations still require their own applicability assessment.

    What ISO 42001 contributes

    ISO/IEC 42001 establishes a repeatable AI Management System (AIMS). It brings governance into the same Plan-Do-Check-Act discipline used by other management standards:

    • Define the organisational context and AI policy.
    • Assign accountable roles and objectives.
    • Assess AI risks and impacts.
    • Select and operate controls.
    • Monitor performance, audit the system and improve it.

    This is valuable because AI risk is not confined to model accuracy. It includes privacy, security, bias, transparency, human oversight, supplier dependence, misuse and effects on people or society.

    Where regulation still needs separate treatment

    Legal compliance starts with jurisdiction, role and use-case classification. An organisation may be a provider for one system, a deployer for another and a supplier of components for a third. Obligations can change with each role.

    Certification therefore cannot replace legal analysis. The governance system should contain the method for identifying obligations, assigning them and retaining evidence that they were met.

    Governance needAIMS mechanismEvidence example
    AI inventoryControlled register and ownershipSystem purpose, owner, users, data and suppliers
    Risk classificationDefined assessment methodApproved classification with rationale
    Impact assessmentRepeatable evaluation processRights, safety and affected-party analysis
    Human oversightRoles and intervention criteriaEscalation rules, override logs and training
    Data governanceData-quality and provenance controlsDataset records, lineage and validation results
    MonitoringPerformance and incident thresholdsDrift reports, complaints and corrective actions

    One integrated mapping workshop

    Parker and Krepki’s practical recommendation can be turned into a focused working session. Start with the organisation’s AI inventory, not a generic control list.

    For each system:

    1. Identify business purpose, users and affected people.
    2. Record the organisation’s role and applicable jurisdictions.
    3. Classify risk using documented criteria.
    4. Map applicable legal duties to AIMS processes and controls.
    5. Assign one accountable owner and one evidence location.
    6. Record gaps, treatment decisions and acceptance authority.

    The output should be a traceable obligations-and-controls matrix. One row may connect an impact-assessment requirement to the AIMS risk process, product approval gate, privacy assessment and retained decision record.

    Multidisciplinary governance is not optional

    Parker notes that ISO 42001 requires input across privacy, ethics and security. Add legal, product, data science, procurement, HR and internal audit where the use case demands it. A committee without decision rights is not governance; each role needs a defined approval, challenge or escalation responsibility.

    Questions the governance group should answer

    • Who can approve a high-impact AI use case?
    • What evidence is required before deployment?
    • When must a human review or override an output?
    • How are model, data and supplier changes reassessed?
    • Which incidents reach leadership, customers or regulators?
    • How is AI literacy tailored to executives, developers and users?

    Use NIST as an operating cross-check

    NIST’s published crosswalk connects AI RMF outcomes with ISO 42001 clauses and controls. It can help teams test whether their AIMS covers practical outcomes across Govern, Map, Measure and Manage. A crosswalk is not proof of effectiveness, however. Auditors still need to test whether the mapped process operates and whether evidence supports the claimed outcome.

    ICyberWave perspective

    The strongest AI governance programmes use one control architecture with multiple mappings. That reduces duplicate work while preserving the differences between certification, regulation and customer requirements. ICyberWave supports AI inventory, impact assessment, risk and control mapping, internal audit and ISO 42001 readiness. Read our ISO 42001 certification guide, or contact us to scope an integrated programme.

    Hi! I'm your AI Assistant 💬