AI governance
ISO 42001, the EU AI Act and responsible AI reviews
What it is
AI governance is how you show AI features are built and run responsibly: an AI policy, a risk assessment for each feature, a record of which models are used and how, human oversight where it matters, and a process for incidents. ISO/IEC 42001 certifies an AI management system, the EU AI Act places obligations on certain uses, and the NIST AI Risk Management Framework is a common reference in the US.
Large buyers now run AI-specific vendor reviews alongside security reviews. Regulated customers especially need evidence they can show their own auditors.
What it takes
About 6–12 engineer-weeks to build in-house, or 3–6 using Credo AI, Holistic AI, Vanta.
Plan for four to nine months to ISO 42001 certification if you already run a security programme.
Answer these first
- Legal: Could any of our AI features count as high-risk under the EU AI Act?
- Product: Where does a person review or approve what the AI does?
- Engineering: Do we keep a record of which models and versions each feature uses?
- Security: How would we detect and respond to an AI incident?
- Sales: Are buyers asking for ISO 42001, or only for answers to AI questions?
- Finance: Who owns AI governance, and can it sit inside existing compliance work?
This page works best with JavaScript on. Every answer also has its own address, like /what/scim.