AI Governance

ISO/IEC 42001 Is Not a Policy Document

Quick Answer

When a board asks for "an AI governance policy," what often gets produced is a document: a few pages describing principles like fairness, transparency, and accountability, circulated for sign-off, then…

When a board asks for “an AI governance policy,” what often gets produced is a document: a few pages describing principles like fairness, transparency, and accountability, circulated for sign-off, then filed away until the next audit. It satisfies the request on paper. It does very little to actually manage the risk of an AI system making a bad decision in production.

ISO/IEC 42001, the international standard for AI management systems, asks for something different. Not a statement of intent, but a system: a defined process for how AI use cases get identified, assessed for risk, approved, monitored, and improved, with evidence that the process is actually being followed.

Use Case Inventory Comes Before Anything Else

You cannot govern what you have not inventoried. A surprising number of organizations, when asked directly, cannot produce a complete list of where AI or machine learning is actually being used across the business. A model embedded in a vendor product counts. An internal tool a team built to triage support tickets counts. A generative AI assistant employees are using informally, without an approved workflow, counts too, and is often the largest source of unmanaged risk.

The starting point under 42001 is a real inventory: every AI use case, who owns it, what data it touches, and what decision it influences. That inventory is what everything else in the standard hangs off of.

Risk Review Has to Be Specific to Each Use Case

A single generic risk statement covering every AI system in the company does not meet the intent of the standard, and it does not actually manage risk either. A model that recommends product bundles carries a very different risk profile than one that influences a hiring decision or a credit decision. 42001 expects the risk assessment to reflect that difference: what happens if this specific model is wrong, who is affected, and what controls exist to catch it before it causes harm.

Monitoring Is the Part Most Programs Skip

A model approved a year ago, on the data available a year ago, is not the same model running today if the underlying data has shifted, or if the vendor has quietly updated the model behind the scenes. Ongoing monitoring, not a one-time approval, is what the standard actually requires: a defined way to catch when a model’s behavior drifts from what was originally assessed and approved, and a process for re-review when it does.

What Certification Readiness Actually Looks Like

Getting ready for a 42001 assessment is less about writing new policy and more about building the evidence trail: the use case inventory, the risk assessments tied to each entry in it, the approval records, and the monitoring logs that show the system is a living process rather than a document that was signed once. That is the gap between organizations that pass and organizations that need another cycle: not effort, but evidence.

If you are trying to figure out how far your current AI governance approach is from what an assessor would actually want to see, that is exactly the kind of independent review our AI Assurance & Responsible AI team runs.