White paper · 2026
An AI system is audit-ready when you can name it, place it in a risk tier, show who is accountable for it, evidence the human oversight applied to it, and produce the documentation behind its behaviour. The EU AI Act sets obligations by role and risk. ISO/IEC 42001 gives you a certifiable management system to run them through. This paper sets out what each demands, where they overlap, and the order of work that gets a regulated firm from a shadow-AI estate to a defensible one.
Audience: CISOs, heads of technology risk, data protection officers and internal audit in financial services and healthcare.
In short. Start with the inventory, because nothing else can be assessed without it. Determine your role for each system — provider, deployer, or both. Classify by risk, not by enthusiasm. Assign a named accountable owner. Then decide whether you need a certifiable management system or a lighter governance layer: the deciding question is whether customers, regulators or auditors will ask you to prove it.
In the firms we assess, an AI policy is usually already written and an inventory usually is not. Assistants arrive through SaaS features nobody procured as AI, through team credit cards, and through engineering pilots that quietly reached production. Governance written against an unknown estate is documentation, not control.
A usable inventory entry answers eight questions: what the system does, which data it touches, which model and provider sit behind it, who owns it, which tools or actions it can invoke, whether it acts autonomously, which jurisdictions it operates in, and what its risk classification is. Anything less cannot be assessed, monitored or defended.
Discovery sources that actually find things: SaaS admin consoles and OAuth grants; egress logs to known model API endpoints; expense and procurement records; code repository dependency scans for model SDKs; and a short amnesty survey to teams. Run all five — each finds systems the others miss.
Under the EU AI Act, your duties follow your role for each system rather than your industry. Most regulated firms are deployers of third-party systems, occasionally providers of their own, and sometimes both for the same system when they substantially modify it or put their own name on it. Getting this wrong is expensive in both directions: over-scoping produces provider-grade documentation you did not owe, and under-scoping leaves obligations unowned.
| ROLE | TYPICAL SITUATION | WHERE THE WORK LANDS |
|---|---|---|
| Deployer | You use a vendor's AI system under your own authority — a copilot, a triage assistant, a screening tool. | Human oversight, input data quality within your control, monitoring, record-keeping, staff competence, informing affected people where required. |
| Provider | You develop a system, or place one on the market under your own name or trademark. | Risk management system, data governance, technical documentation, logging capability, accuracy and robustness, conformity assessment, post-market monitoring. |
| Both | You substantially modify a third-party system, change its intended purpose, or rebrand it. | Provider duties attach for the modified system. Decide this deliberately and document the reasoning; it is a design decision, not a formality. |
The EU AI Act is law: obligations attached to roles and risk tiers, enforced by authorities. ISO/IEC 42001 is a management-system standard: certifiable, voluntary, and structured like ISO/IEC 27001 — context, leadership, planning, support, operation, evaluation, improvement. NIST AI RMF sits alongside both as a risk framework rather than a certification target. Firms that already run a 27001 ISMS get most of 42001's machinery for free; what is new is the AI-specific impact assessment, the system lifecycle controls and the competence requirements.
| CAPABILITY | EU AI ACT | ISO/IEC 42001 | NIST AI RMF |
|---|---|---|---|
| AI system inventory | Implied by role and risk duties | Required as part of scope and lifecycle | Map function |
| Risk classification | Prohibited, high-risk, limited, minimal tiers | Organisation-defined criteria | Measure function |
| Human oversight | Explicit duty for high-risk systems | Operational control and competence | Govern and Manage |
| Impact assessment | Required for certain deployers | AI system impact assessment process | Map and Measure |
| Independent assurance | Conformity assessment routes | Certification by an accredited body | None — voluntary framework |
Regulatory timelines and interpretations continue to move. Confirm the current position and the dates applicable to your systems with your counsel and the relevant authority before committing to a programme plan.
Oversight is not a person nominally in the loop. It is a named role with the competence, the information and the authority to intervene, including the authority to stop the system, plus evidence that interventions actually happen. Three artefacts make it real:
ARTEFACT 01
Where in the workflow a human must review, approve or reject, written into the process rather than left to judgement.
ARTEFACT 02
A record of accepted, amended and rejected outputs. An empty override log is a finding, not a clean bill of health.
ARTEFACT 03
Evidence that whoever holds oversight understands the system's limits, failure modes and escalation path.
When a system can act rather than only answer, identity becomes the control. Every agent needs a registered non-human identity, scoped credentials, a human sponsor, an approval gate for consequential actions, and a revocation path that someone has tested. Excessive agency is the characteristic failure: an agent holding broader entitlements than the human it acts for, with no record of what it did.
This is why AI governance collapses into identity governance faster than most programmes expect. If your joiner-mover-leaver process cannot describe an agent, your AI controls have no enforcement point.
| FLOW POINT | CONTROL | OWASP LLM CATEGORY |
|---|---|---|
| User and content input | Input validation, allow-listed content sources | Prompt injection · LLM01 |
| Retrieval and context | Classification-aware retrieval, per-user filtering | Sensitive information disclosure · LLM02; embedding weaknesses · LLM08 |
| Model | System prompt isolation, provenance of models and data | System prompt leakage · LLM07; data and model poisoning · LLM04 |
| Tools and agents | Scoped credentials, human approval for consequential actions, quotas | Excessive agency · LLM06; unbounded consumption · LLM10 |
| Output and downstream | Output filtering, egress control, downstream encoding | Improper output handling · LLM05; misinformation · LLM09 |
| WINDOW | WORK | EVIDENCE PRODUCED |
|---|---|---|
| Weeks 1–3 | Discovery across all five sources; inventory built; owners named. | AI system register with owners and data classes |
| Weeks 3–6 | Role determination and risk classification per system; prohibited-use screen. | Classification memos with reasoning and sign-off |
| Weeks 5–9 | Threat modeling and red teaming for systems nearest production; oversight design. | Threat models, red-team report with retest, oversight runbooks |
| Weeks 8–12 | Agent identity registration, logging and monitoring build, committee reporting line. | Agent register, log specification, first risk report |
| Week 12 | Decide: certifiable ISO/IEC 42001 management system, or governance layer aligned to NIST AI RMF. | Board-ready recommendation with cost and timeline |
As a scoped engagement under a statement of work: discovery and inventory, role and risk classification, threat modeling and red teaming, oversight and logging design, then either management-system build or a lighter governance layer. Senior-led, onshore leadership with offshore engineering, delivered across the USA, EU and Middle East.
Talk to a practice lead: info@aceitsolutions.ai · +1 (650) 606-5553
© 2026 ACE IT Solutions. ACE IT Solutions — an Autharva company. This paper is general information, not legal advice. Framework and standard names are the property of their respective owners. ACE IT Solutions provides advisory and implementation services designed to support compliance; certification is granted solely by accredited certification bodies.