AI

AI governance: know where AI is used, what it touches and who is responsible

Most organizations already use AI — often more than management knows. We help you get an overview, set sensible rules, assess risks and prepare for the EU AI Act and ISO/IEC 42001, building on the governance structures you already have.

The questions many organizations cannot answer yet

AI governance starts with simple questions. The problem is that nobody owns the answers.

  • Which AI systems and tools are employees using?
  • Which AI use cases exist across the organization?
  • What information is being sent to AI services — and where does it go?
  • Who is responsible for approving and monitoring AI use?
  • Which risks exist, and which rules apply?
  • How is AI use documented — and could it be audited?

What we build with you

AI inventory

A structured register of AI systems, tools and use cases — including shadow AI.

AI policy & usage rules

Clear, practical rules for employees: which tools, which data, which approvals.

AI risk assessment

A method to assess AI risks — integrated with your existing risk management.

EU AI Act classification

A structured assessment of your role (provider/deployer) and the risk category of your use cases.

Roles & human oversight

Who approves, who monitors, who intervenes — and how that is documented.

AI lifecycle governance

From idea and approval to operation, monitoring and retirement of AI systems.

AI data governance

Rules for training data, input data and outputs, aligned with information security and data protection.

ISO/IEC 42001 AIMS

An AI management system according to ISO/IEC 42001 — ideally integrated into your ISMS or QMS.

How we proceed

  1. Discover

    Find out where and how AI is used today — through interviews, tool reviews and existing inventories.

  2. Classify

    Assess use cases by risk and by the requirements that apply to them.

  3. Set rules

    Policies, approval processes and responsibilities that people can follow.

  4. Integrate

    Connect AI governance to your existing ISMS, QMS, risk management and documentation.

  5. Enable

    Train employees and decision-makers on responsible and secure AI use.

  6. Monitor

    Keep the inventory, risks and rules current as AI use evolves.

AI governance should not become another silo

Risk management, document control, roles, audits and reviews already exist in your ISMS or QMS. AI governance works best as an extension of these structures — ISO/IEC 42001 is built for exactly that.

Where legal advice is needed

We translate AI requirements into governance structures, processes and controls. Binding legal interpretations of the EU AI Act for your specific case should be confirmed by legal counsel.

No new silo

AI governance builds on what exists

AI governance uses the structures you already have — and only adds what is specific to AI.

  1. ISMS
  2. QMS
  3. Risk management
  4. Governance
  5. Documentation
  6. AI-specific rules

What you get out of it

  • A clear picture of AI use across the organization
  • Rules employees understand and follow
  • Documented, auditable AI decisions with human oversight
  • Readiness for the EU AI Act and ISO/IEC 42001

Frequently asked questions

What is AI governance?

AI governance is the set of rules, responsibilities and processes an organization uses to control how AI is selected, developed, used and monitored — so that AI use is secure, lawful, transparent and aligned with the organization’s goals.

What does the EU AI Act require?

The EU AI Act sorts AI uses by risk. Certain practices are prohibited; providers and deployers must support AI literacy of their staff; transparency obligations apply to certain AI systems; and high-risk AI systems face extensive requirements. Following the 2026 “Digital Omnibus” amendment, most high-risk obligations now apply from December 2027 (stand-alone systems) and August 2028 (AI in regulated products). Which obligations apply to you depends on your role and use cases.

What is ISO/IEC 42001?

ISO/IEC 42001 is the international standard for AI management systems (AIMS). It describes how an organization establishes policies, objectives, risk assessment, roles and controls for the responsible development and use of AI — and can be certified.

How does ISO 42001 relate to ISO 27001?

Both use the same management system structure. ISO/IEC 27001 protects information; ISO/IEC 42001 governs AI systems, including issues like transparency, bias and human oversight. Organizations with an ISMS can reuse much of their management framework and add AI-specific elements.

Is ISO 42001 certification mandatory under the EU AI Act?

No. ISO/IEC 42001 is voluntary. It can, however, provide a structured way to implement and evidence many governance requirements that the EU AI Act and customers expect.

Related services

Related reading

Using AI and not sure what the AI Act means for you?

Let us start with an overview of your AI use. The next steps usually become clear quickly.

contact@feldmanncyber.com · +49 (0)151 6275 6121