Orient — before you anchor
ISO 42001 is the spine of AI governance — not the whole body
"AI governance" is so broad it paralyses teams. This map fixes your location: what the certifiable core (ISO 42001) covers, where the law sets the actual bar, and which adjacent standards handle everything else. Honest scope, no over-claiming.
Governance operating model
Policy, roles, objectives, management review — the AIMS itself.
Risk management (process)
A repeatable process to identify, score and treat AI risk.
Impact assessment
Structured assessment of impacts on people and society (A.5).
Documentation & evidence
Statement of Applicability, controls, records — the audit trail.
Third parties
Supplier and value-chain governance obligations.
EU AI Act legal compliance
42001 ≠ AI Act compliance. High-risk conformity assessment, Art. 50, Annex IV, EU database registration are mapped separately — the management system produces the evidence, the Act sets what must be true.
Transparency (Art. 50)
Chatbot disclosure, synthetic-content marking, deepfake labelling — in force, with a hard 2 Dec 2026 deadline.
Human oversight (Art. 14)
Oversight measures for high-risk systems — the standard operationalises what the Act requires.
Data governance (Art. 10)
Data quality and bias controls, where the Act sets the threshold.
Privacy
ISO 27701 / GDPR — personal-data obligations sit beside the AIMS.
AI security & robustness
NIST AI RMF, ISO 27001, ISO 42005/23894 for technical thresholds.
AI strategy / ROI (AX)
Business strategy — outside any standard; that's yours to own.
The honest conclusion
Complete AI governance = ISO 42001 (the spine) + legal mapping + technical/ethical standards + strategy/AX + industry & privacy rules. ISO 42001 coordinates the rest; it doesn't substitute for it. What makes it the anchor is that it's the one part you can actually get certified — turning an open-ended "governance" problem into a concrete, provable result.