Skip to main content
AI governance · Regulation (EU) 2024/1689 · ISO/IEC 42001

AI governance: what it is and how to run it

AI governance is how an organisation decides which AI it uses, who is accountable for each system, and how that is evidenced. In the EU it is no longer a matter of good intentions: the AI Act makes parts of it binding law, and ISO/IEC 42001 supplies the management structure to carry it.

Last updated: 8 September 2026

At a glance

What binds, and when

EU-wide
Governing law(EU) 2024/1689
AI literacy (Art. 4)since 2 Feb 2025
Transparency (Art. 50)since 2 Aug 2026
High risk · Annex III2 Dec 2027
Management standardISO/IEC 42001
Certifiablestandard only

What is AI governance?

AI governance is the way an organisation directs and controls its use of artificial intelligence: which systems are permitted, who owns each one, how their risks are assessed and treated, and what evidence exists that any of it actually happened. It is an accountability question before it is a technical one.

It is worth separating three things that get used interchangeably. AI ethics is a set of principles — fairness, transparency, human oversight. Model governance is the engineering discipline around a model: versions, datasets, drift, monitoring. AI governance is the layer that decides who is allowed to answer those questions, and keeps the record. Principles without a named owner and a dated record do not survive an audit, and a well-monitored model in an undocumented process does not either.

In practice a working setup has three parts and rarely more: an inventory of the AI systems actually in use, one accountable person per system, and a record that shows what was decided and when. Everything else — policies, risk registers, impact assessments — hangs off those three.

Inside the AI Manager

What governance looks like on screen

Screenshots from the AI Manager, the same screens a live account shows, filled with example data — not a demo account with empty tables.

The AI Manager overview screen showing two AI systems, one high-risk, 36 percent average implementation, eight open high risks, forty-two saved documents, a risk class distribution chart and a list of upcoming deadlines with dates.

Portfolio at a glance

See every AI system, its risk class, open risks and the next deadline the moment you open the tool — no report to assemble first.

The action plan step of the AI Manager wizard with a Gantt chart of nine phases from classification to go-live and monitoring, plus a table of recurring deadlines and reviews with due dates and status.

Plan and deadlines together

A rough timeline to go-live sits next to the recurring reviews it triggers, so a plan and a compliance calendar are the same screen.

The responsibilities screen in kanban view with three columns, planned, open and done, each holding task cards naming the obligation, the AI system, the due date and status.

Tasks, as a board

The same tasks that show up on the calendar, sorted into planned, open and done — for teams who read a board faster than a list.

Which framework: the AI Act, ISO/IEC 42001 or the NIST AI RMF

They are not alternatives to one another. The AI Act is binding law wherever you place AI on the EU market, ISO/IEC 42001 is a voluntary management-system standard you can be certified against, and the NIST AI Risk Management Framework is a voluntary US framework with no certification behind it.

Binding law

EU AI Act

Identifier(EU) 2024/1689
Statusmandatory
ReachEU market
Certifiableno

Tells you which duties apply to a given system, based on its risk class and your role. It does not tell you how to organise yourself to meet them.

Management standard

ISO/IEC 42001

IdentifierISO/IEC 42001
Statusvoluntary
Reachinternational
Certifiableyes

Supplies the frame: scope, policy, roles, risk assessment and treatment, a statement of applicability, monitoring, internal audit, management review. Auditable by an accredited body.

Voluntary framework

NIST AI RMF

IdentifierNIST AI 100-1
Statusvoluntary
Reachmainly US
Certifiableno

A shared vocabulary for describing and treating AI risk. Widely referenced in the United States, and not tied to any EU obligation.

The practical order is the same for most European companies. Start with the AI Act, because it is the only one of the three you can be fined under. Add ISO/IEC 42001 when you need the organisational frame — or when a customer asks for a certificate. Reach for the NIST framework when a US partner or contract asks for it by name.

Why we build on ISO/IEC 42001 and not the NIST AI RMF

The TSMONDO AI Manager implements the EU AI Act and ISO/IEC 42001. It does not implement the NIST AI Risk Management Framework, and there is no mapping to it in the product. If a NIST alignment is what you have been asked to produce, this is not the tool for that job, and we would rather say so here than at the end of a trial.

The reasoning is narrow and it is about fit, not quality. Our customers sell into the EU and are measured against an EU regulation; the standard that an auditor or an insurer here asks to see is ISO/IEC 42001, because it is the one with an accredited certification route behind it. The NIST framework has no certificate, so it cannot close that conversation.

It also has more search demand than most of the terms on this page, which is exactly why the honest answer belongs here rather than a vague section implying coverage we have not built. The overlap in substance is real — identify your systems, assess the risk, treat it, keep the record — so work done for one is rarely wasted for the other. But a mapping is a piece of software, not a sentence, and we have not written it.

Do you need an AI governance platform?

For one or two low-risk systems a spreadsheet and a folder are genuinely enough. A dedicated tool starts to earn its keep at around five systems, or the first time somebody outside the company — an auditor, a customer, an insurer — asks to see the register.

Where you areSpreadsheet and folderDedicated tool
One or two systems, all minimal riskEnoughNot needed yet
Five or more systems across several departmentsStarts to breakPays off
At least one high-risk system under Annex IIINot realisticEffectively necessary
Recurring reviews and refreshers on fixed datesNeeds a calendar beside itBuilt in
An auditor or customer asks for the registerDays of assemblyExport on the spot
You must show who decided what, and whenOnly if you kept versionsRecorded as you go

What separates a useful AI governance tool from a pretty one is unglamorous: does it produce the documents an auditor asks for, does it keep dates, and does it survive the person who set it up leaving. Ours runs locally on your own machine with no cloud account — see what the AI Manager actually does before you decide whether you need anything at all.

AI governance training: the duty that already applies

Article 4 of the AI Act requires providers and deployers to take measures that support a sufficient level of AI literacy among the staff and other people who operate their AI systems on their behalf. As reworded by Regulation (EU) 2026/1744 it no longer asks you to guarantee a particular level of competence per person. It has applied since 2 February 2025, with no size threshold and no exemption for small companies.

What “sufficient” means is deliberately left open: it depends on which systems are in use, what people do with them, and the consequences if they get it wrong. Somebody drafting marketing copy needs less than somebody letting a model pre-sort job applications.

The part that gets forgotten is not the training, it is the record. A short briefing that nobody wrote down is, for supervisory purposes, a briefing that did not happen. Keep the date, the participants and the topics covered; that is the whole obligation for most companies. The deadlines and duties under the AI Act are set out in more detail on the regulation page.

How to start

  • Write down every AI system you actually use — including the ones already embedded in software you licence. Most lists are shorter than feared and longer than expected.
  • Give each system one accountable owner — a named person, not a department. This is the single step that most often does not happen.
  • Classify the use, not the tool — prohibited, high risk, transparency, or none of these. Most business use lands in the last box, and knowing that shrinks the work.
  • Cover the Article 4 literacy duty and keep the record — it already applies and is the cheapest obligation on the list.
  • Set the recurring dates before you need them — review, internal audit, management review. A governance system without a calendar is a folder.

Frequently asked questions

What is AI governance?

AI governance is the way an organisation directs and controls its use of artificial intelligence: which systems are permitted, who is accountable for each one, how their risks are assessed and treated, and what evidence exists that it happened. It is distinct from AI ethics, which is a set of principles, and from model governance, which is the engineering practice around a single model.

Is AI governance a legal requirement in the EU?

Parts of it are. The AI Act, Regulation (EU) 2024/1689, makes specific duties binding: the AI literacy obligation in Article 4 since 2 February 2025, the transparency obligations in Article 50 since 2 August 2026, and the high-risk obligations from 2 December 2027. The wider practice of governance is not itself prescribed, but you cannot demonstrate compliance with those duties without it.

What is the difference between the EU AI Act and ISO/IEC 42001?

The AI Act is binding law and states what must be achieved for a given risk class and role. ISO/IEC 42001 is a voluntary management-system standard that states how to organise yourself to achieve it, and can be certified by an accredited body. A certificate does not create a presumption of conformity with the regulation, but the two overlap enough that building the system once is the proportionate route.

Should we use the NIST AI Risk Management Framework instead?

Only if something specific asks you to. The NIST framework is voluntary, has no certification route, and carries no weight under EU law. For a company selling into the EU, ISO/IEC 42001 is the standard an auditor or insurer expects to see. The TSMONDO AI Manager does not implement the NIST framework and offers no mapping to it.

Do we need an AI governance platform?

Not at one or two low-risk systems — a spreadsheet and a folder will do. A tool becomes worthwhile at around five systems, as soon as one system is high-risk under Annex III, or the first time an auditor, customer or insurer asks to see the register and the dates behind it.

Who should own AI governance in a small company?

One named person with the authority to stop a deployment, supported by the owner of each individual system. In companies below roughly 250 staff this is usually an existing role — the person who already handles data protection or information security — rather than a new hire. What matters is that the name is written down.

What does AI governance training have to cover?

Article 4 does not prescribe content. In practice a sufficient briefing covers which AI systems the organisation uses, what they may and may not be used for, where human oversight is required, and how to report a problem. Depth should match the role. Keep the date, the participants and the topics, because the record is the part that is checked.

From a policy nobody reads to a register you can show

The TSMONDO AI Manager takes you through classification, roles, obligations, deadlines and the documents — locally, on your own machine, with no cloud account.

This page provides general information and does not constitute legal advice. Dates and amounts: confirm against the final legal texts of your member state.