Pillar guide

AI governance for companies that ship AI features

ISO 42001, the EU AI Act and NIST AI RMF, explained in one place: what each one asks for, which applies to you, and how to build the inventory, risk register and controls without starting a second compliance program.
The short version. ISO 42001 is the certifiable management-system standard for AI. The EU AI Act is a regulation with obligations by risk tier, phasing in from 2025 to 2027. NIST AI RMF is a voluntary US framework of practices. If you build or deploy AI, ISO 42001 gives you a certificate customers recognise, and its structure covers most of what the EU AI Act and NIST AI RMF ask for. All three sit on top of a security management system such as ISO 27001.

Three frameworks, one register

FrameworkWhat it isApplies whenOutput
ISO/IEC 42001Certifiable AI management system standard (2023)You develop, provide or use AI systems and want independent proof of governanceCertificate from an accredited body
EU AI ActRegulation with obligations by risk tier: prohibited, high-risk, limited, minimalYou place AI on the EU market or its output is used in the EULegal compliance; conformity assessment for high-risk systems
NIST AI RMFVoluntary framework: Govern, Map, Measure, ManageUS customers or public-sector buyers ask for itDocumented practices, no certificate

What an AI management system contains

ISO 42001 follows the same structure as ISO 27001: context, leadership, planning, support, operation, evaluation and improvement. What changes is the subject. Instead of information assets you inventory AI systems; instead of security risks you assess AI-specific ones such as bias, robustness, transparency and misuse; instead of Annex A security controls you apply Annex A AI controls covering data, models, lifecycle and accountability.

Start here

AI system inventory

Every model, agent and third-party AI service you build or use, with purpose, data, owner and risk tier. The inventory is the foundation of every other requirement.

Clause 6 / Annex A

AI impact assessment

For each system: who is affected, what could go wrong, how likely, how severe, and what you do about it. High-risk EU AI Act systems need a formal one.

Annex A

Lifecycle controls

Data provenance, model documentation, testing before release, monitoring in production, human oversight and incident handling for AI failures.

Clauses 5 and 7

Accountability

Named owners, an AI policy leadership signs, training for people who build and use AI, and records that show decisions were made and reviewed.

Reusing your ISO 27001 work

Roughly two thirds of an ISO 42001 management system already exists if you hold ISO 27001: the governance clauses, risk methodology, document control, internal audit and management review. Certifyi keeps AI risk in the same register as security risk and maps the shared controls once, so the AI standard is an overlay rather than a second program. Customers who start from ISO 27001 typically add ISO 42001 in four to six weeks.

EU AI Act timing

Prohibited practices applied from February 2025, general-purpose AI obligations from August 2025, and most high-risk obligations from August 2026 with some product-safety categories following in 2027. If your product could be classed high-risk (employment, credit, education, critical infrastructure, biometrics, essential services), the inventory and impact assessment are the first two documents a regulator or enterprise buyer will ask to see.

AI governance questions we hear most

If AI features are part of your product or your operations, yes, the standard applies to users of AI as well as developers. Your controls focus on selection, data handling, monitoring and human oversight rather than model training.

Yes. Many certification bodies run integrated audits, and Certifyi schedules them on one calendar so shared controls are examined once.

If your AI system is placed on the EU market or its output is used in the EU, the Act applies regardless of where you are based, in the same way GDPR does.

From an existing ISO 27001 base, four to six weeks to audit-ready. From zero, 8 to 12 weeks alongside ISO 27001, since both share the management-system work.

Shipping AI features?

Bring your product and your customer list. A compliance lead will tell you which framework your buyers will ask for first and what the inventory needs to contain.
Scroll to Top