Orient — before you anchor

ISO 42001 is the spine of AI governance — not the whole body

"AI governance" is so broad it paralyses teams. This map fixes your location: what the certifiable core (ISO 42001) covers, where the law sets the actual bar, and which adjacent standards handle everything else. Honest scope, no over-claiming.

Core · ISO 42001 covers this well

Governance operating model

Policy, roles, objectives, management review — the AIMS itself.

Risk management (process)

A repeatable process to identify, score and treat AI risk.

Impact assessment

Structured assessment of impacts on people and society (A.5).

Documentation & evidence

Statement of Applicability, controls, records — the audit trail.

Third parties

Supplier and value-chain governance obligations.

Operationalised · 42001 is the machine, the law is the bar

EU AI Act legal compliance

42001 ≠ AI Act compliance. High-risk conformity assessment, Art. 50, Annex IV, EU database registration are mapped separately — the management system produces the evidence, the Act sets what must be true.

Transparency (Art. 50)

Chatbot disclosure, synthetic-content marking, deepfake labelling — in force, with a hard 2 Dec 2026 deadline.

Human oversight (Art. 14)

Oversight measures for high-risk systems — the standard operationalises what the Act requires.

Data governance (Art. 10)

Data quality and bias controls, where the Act sets the threshold.

Adjacent · 42001 coordinates, it doesn't replace

Privacy

ISO 27701 / GDPR — personal-data obligations sit beside the AIMS.

AI security & robustness

NIST AI RMF, ISO 27001, ISO 42005/23894 for technical thresholds.

AI strategy / ROI (AX)

Business strategy — outside any standard; that's yours to own.

The honest conclusion

Complete AI governance = ISO 42001 (the spine) + legal mapping + technical/ethical standards + strategy/AX + industry & privacy rules. ISO 42001 coordinates the rest; it doesn't substitute for it. What makes it the anchor is that it's the one part you can actually get certified — turning an open-ended "governance" problem into a concrete, provable result.