AI governance

ISO 42001: building an AI management system that holds up

An AI inventory, impact assessments, human oversight and monitoring — the four things customers and regulators both ask about.

24 June 2026 · 9 min read

Start with an honest inventory

Almost every organisation is using more AI than its inventory shows. Vendor features arrive switched on, teams adopt assistants directly, and models get embedded in products without a governance step. The first deliverable of an AI management system is a list: what systems exist, what they decide or produce, whose data they touch, and who owns each one.

Impact assessment, proportionate to use

A drafting assistant and an automated credit decision do not deserve the same scrutiny. Tier your AI uses by consequence, then apply assessment depth accordingly: purpose and scope, data sources and lawful basis, foreseeable harms, affected groups, mitigations and residual acceptance. Record the reasoning, because the question you will be asked is not whether you assessed it but how you concluded it was acceptable.

  • Purpose, users and affected parties.
  • Data sources, retention and lawful basis.
  • Failure modes, including bias and hallucination.
  • Human oversight and escalation design.
  • Residual risk decision and approver.

Human oversight is a control, not a sentence in a policy

Oversight only counts if it is designed: who reviews what, at what point, with what information, and with a real ability to override. Where a human approval step exists, the system should log it. Where no human is in the loop, that should be a documented and approved decision rather than an accident of implementation.

Monitoring and change control

Models drift, providers update versions, and prompts get edited. Treat AI systems like any other change-controlled asset: version records, performance and quality monitoring, incident capture for wrong or harmful outputs, and periodic reassessment tied to the risk tier.

Reuse your existing control set

Much of ISO 42001 overlaps with what an ISO 27001 or SOC 2 programme already runs: risk assessment, supplier management, change control, incident response, competence and awareness. Mapping the new requirements onto an existing common control framework is usually a few months of focused work rather than a new programme from zero.

Run this in a platform, not a spreadsheet.

See how compliance, risk, policy, third-party oversight and ESG reporting work on one control library.