AI Governance Readiness: EU AI Act & ISO/IEC 42001 | ACE IT Solutions
ACE IT Solutions.ai White paper · AI governance readiness · EU AI Act and ISO/IEC 42001
General information, not legal advice. Obligations depend on your role, systems and regions. aceitsolutions.ai

White paper · 2026

Is your AI audit-ready? Building governance that survives the EU AI Act and ISO/IEC 42001

An AI system is audit-ready when you can name it, place it in a risk tier, show who is accountable for it, evidence the human oversight applied to it, and produce the documentation behind its behaviour. The EU AI Act sets obligations by role and risk. ISO/IEC 42001 gives you a certifiable management system to run them through. This paper sets out what each demands, where they overlap, and the order of work that gets a regulated firm from a shadow-AI estate to a defensible one.

Audience: CISOs, heads of technology risk, data protection officers and internal audit in financial services and healthcare.

In short. Start with the inventory, because nothing else can be assessed without it. Determine your role for each system — provider, deployer, or both. Classify by risk, not by enthusiasm. Assign a named accountable owner. Then decide whether you need a certifiable management system or a lighter governance layer: the deciding question is whether customers, regulators or auditors will ask you to prove it.

1 · The problem is discovery, not policy

In the firms we assess, an AI policy is usually already written and an inventory usually is not. Assistants arrive through SaaS features nobody procured as AI, through team credit cards, and through engineering pilots that quietly reached production. Governance written against an unknown estate is documentation, not control.

A usable inventory entry answers eight questions: what the system does, which data it touches, which model and provider sit behind it, who owns it, which tools or actions it can invoke, whether it acts autonomously, which jurisdictions it operates in, and what its risk classification is. Anything less cannot be assessed, monitored or defended.

Discovery sources that actually find things: SaaS admin consoles and OAuth grants; egress logs to known model API endpoints; expense and procurement records; code repository dependency scans for model SDKs; and a short amnesty survey to teams. Run all five — each finds systems the others miss.

2 · Role determines obligation

Under the EU AI Act, your duties follow your role for each system rather than your industry. Most regulated firms are deployers of third-party systems, occasionally providers of their own, and sometimes both for the same system when they substantially modify it or put their own name on it. Getting this wrong is expensive in both directions: over-scoping produces provider-grade documentation you did not owe, and under-scoping leaves obligations unowned.

ROLETYPICAL SITUATIONWHERE THE WORK LANDS
DeployerYou use a vendor's AI system under your own authority — a copilot, a triage assistant, a screening tool.Human oversight, input data quality within your control, monitoring, record-keeping, staff competence, informing affected people where required.
ProviderYou develop a system, or place one on the market under your own name or trademark.Risk management system, data governance, technical documentation, logging capability, accuracy and robustness, conformity assessment, post-market monitoring.
BothYou substantially modify a third-party system, change its intended purpose, or rebrand it.Provider duties attach for the modified system. Decide this deliberately and document the reasoning; it is a design decision, not a formality.

3 · The two frameworks do different jobs

The EU AI Act is law: obligations attached to roles and risk tiers, enforced by authorities. ISO/IEC 42001 is a management-system standard: certifiable, voluntary, and structured like ISO/IEC 27001 — context, leadership, planning, support, operation, evaluation, improvement. NIST AI RMF sits alongside both as a risk framework rather than a certification target. Firms that already run a 27001 ISMS get most of 42001's machinery for free; what is new is the AI-specific impact assessment, the system lifecycle controls and the competence requirements.

CAPABILITYEU AI ACTISO/IEC 42001NIST AI RMF
AI system inventoryImplied by role and risk dutiesRequired as part of scope and lifecycleMap function
Risk classificationProhibited, high-risk, limited, minimal tiersOrganisation-defined criteriaMeasure function
Human oversightExplicit duty for high-risk systemsOperational control and competenceGovern and Manage
Impact assessmentRequired for certain deployersAI system impact assessment processMap and Measure
Independent assuranceConformity assessment routesCertification by an accredited bodyNone — voluntary framework

Regulatory timelines and interpretations continue to move. Confirm the current position and the dates applicable to your systems with your counsel and the relevant authority before committing to a programme plan.

4 · Human oversight, stated properly

Oversight is not a person nominally in the loop. It is a named role with the competence, the information and the authority to intervene, including the authority to stop the system, plus evidence that interventions actually happen. Three artefacts make it real:

ARTEFACT 01

Decision point

Where in the workflow a human must review, approve or reject, written into the process rather than left to judgement.

ARTEFACT 02

Override log

A record of accepted, amended and rejected outputs. An empty override log is a finding, not a clean bill of health.

ARTEFACT 03

Competence record

Evidence that whoever holds oversight understands the system's limits, failure modes and escalation path.

5 · Where agentic AI changes the assessment

When a system can act rather than only answer, identity becomes the control. Every agent needs a registered non-human identity, scoped credentials, a human sponsor, an approval gate for consequential actions, and a revocation path that someone has tested. Excessive agency is the characteristic failure: an agent holding broader entitlements than the human it acts for, with no record of what it did.

This is why AI governance collapses into identity governance faster than most programmes expect. If your joiner-mover-leaver process cannot describe an agent, your AI controls have no enforcement point.

FLOW POINTCONTROLOWASP LLM CATEGORY
User and content inputInput validation, allow-listed content sourcesPrompt injection · LLM01
Retrieval and contextClassification-aware retrieval, per-user filteringSensitive information disclosure · LLM02; embedding weaknesses · LLM08
ModelSystem prompt isolation, provenance of models and dataSystem prompt leakage · LLM07; data and model poisoning · LLM04
Tools and agentsScoped credentials, human approval for consequential actions, quotasExcessive agency · LLM06; unbounded consumption · LLM10
Output and downstreamOutput filtering, egress control, downstream encodingImproper output handling · LLM05; misinformation · LLM09

6 · A ninety-day sequence

WINDOWWORKEVIDENCE PRODUCED
Weeks 1–3Discovery across all five sources; inventory built; owners named.AI system register with owners and data classes
Weeks 3–6Role determination and risk classification per system; prohibited-use screen.Classification memos with reasoning and sign-off
Weeks 5–9Threat modeling and red teaming for systems nearest production; oversight design.Threat models, red-team report with retest, oversight runbooks
Weeks 8–12Agent identity registration, logging and monitoring build, committee reporting line.Agent register, log specification, first risk report
Week 12Decide: certifiable ISO/IEC 42001 management system, or governance layer aligned to NIST AI RMF.Board-ready recommendation with cost and timeline

How ACE IT Solutions delivers this

As a scoped engagement under a statement of work: discovery and inventory, role and risk classification, threat modeling and red teaming, oversight and logging design, then either management-system build or a lighter governance layer. Senior-led, onshore leadership with offshore engineering, delivered across the USA, EU and Middle East.

Talk to a practice lead: info@aceitsolutions.ai · +1 (650) 606-5553

© 2026 ACE IT Solutions. ACE IT Solutions — an Autharva company. This paper is general information, not legal advice. Framework and standard names are the property of their respective owners. ACE IT Solutions provides advisory and implementation services designed to support compliance; certification is granted solely by accredited certification bodies.