Generative AI usually enters an organisation faster than governance can follow. By the time anyone asks who approved a model, it is embedded in three workflows and a customer-facing product. ISO/IEC 42001 gives you a recognisable structure to catch up with — scope, context, leadership, planning, support, operation, evaluation, improvement — and it maps cleanly onto the management systems most organisations already operate.
Start with the inventory
Everything downstream depends on knowing what exists. An AI inventory is not a list of vendors; it is a list of systems, with enough detail to make a risk decision.
- System, owner, and the business decision it influences
- Model type and provenance — built, fine-tuned, or consumed as an API
- Training and inference data, and whether either contains personal data
- Where a human sits in the loop, and what they are able to override
Model classification and risk tiering
Not every model warrants the same scrutiny. Tiering is what makes governance affordable: a spam classifier and a system that influences admissions decisions should not consume the same review budget.
- Tier on consequence to the individual, not on model sophistication.
- Set the tier at intake, and re-tier when the use case changes — the same model in a new context is a new decision.
- Attach the control set to the tier, so classification does real work rather than producing a label.
Human oversight that means something
"Human in the loop" is only a control if the human can realistically intervene. Specify what the reviewer sees, how long they have, what they can change, and what happens when they disagree with the system. An oversight requirement that a reviewer cannot satisfy under production load is documentation, not governance.
Reusing the data privacy program
Most organisations do not need a second governance function for AI. They need the existing one extended:
- The DPIA process becomes the AI impact assessment, with additional sections on training data, bias, explainability and oversight.
- The ROPA already records processing purposes; AI use is another purpose to record against the same systems.
- Vendor management already screens processors; model providers are processors with an extra set of questions.
- The incident procedure already handles breaches; model failure and harmful output need routes into the same procedure.
Evidence
Certification and regulatory defence both come down to the same thing: for each system, a documented risk decision, made by someone with the authority to make it, at a point in time you can show. Build the evidence trail as you go — reconstructing it later is far more expensive than producing it in the first place.