Three groups now ask how you govern AI: regulators, who require named accountability and traceable records; auditors, who require a management system with evidence that controls operate; and customer security reviews, whose questionnaires now carry an AI section. All three require records of what your AI systems did, which a policy document does not provide.
Three distinct groups now ask how AI is governed, and each requires something different.
| Asker | What they are assessing | What satisfies them |
|---|---|---|
| Regulator | Accountability and harm | A named owner, documented decisions, records that allow an outcome to be traced and remediated |
| Auditor | Whether governance operates | A management system: scope, assessed risks, controls, and evidence the controls run |
| Customer security review | Their data inside your AI | Direct answers about models, data flows, output review and failure handling, with evidence behind them |
The regulator’s question is accountability. Where an AI-assisted decision produces harm, they require an accountable person, a record of what the system did, and evidence the organisation could detect and correct the outcome. Records answer that; statements of principle do not.
The auditor’s question is operation. An auditor assesses whether governance of the AI runs: AI systems in scope, risks assessed, controls chosen, and evidence the controls operated over the audit period rather than on the date the policy was approved. It is the discipline ISO 27001 applies to information security, applied to AI.
The customer’s question arrives first for most companies and is the most direct: what the AI does with their data. Security review questionnaires now carry an AI section covering which models are used, what data reaches them, who checks the outputs, and how a failure would be identified. An unevidenced answer generates follow-up questions and holds the deal open while they are addressed.
ISO 42001 is the AI management system standard, built on the same machinery as ISO 27001 — scope, risk assessment, controls, audit, continual improvement — applied to AI systems. It exists because the three groups above require management systems rather than policy documents.
For most organisations it is not the starting point. An existing ISO 27001 ISMS can bring AI systems into scope now: add them to the asset inventory, put AI-specific risks through the existing risk assessment, and apply the same evidence discipline. ISO 42001 becomes worth pursuing where AI is the product, or where customers name it in reviews. ISO 27001 for AI companies covers that sequencing.
Under either standard the requirement is records. Every asker reaches the same test: what a given AI system did. Without a trail of inputs, actions, outputs and approvals, no certificate answers it.
That sets the build order. The audit trail comes first, because it is the evidence every asker shares and it cannot be reconstructed retrospectively. Ownership follows: one named person accountable for AI use, with decisions recorded. The policy comes last and describes what is already running. In that order, a certificate later documents a working system.
An AI policy is the least demanding artefact: a page of principles about responsible use, approved and filed. Every asker on this page requires records of what the AI systems did — which model saw which data, what it produced, and who approved the action that followed.
The available test is to select one AI-assisted decision from last month and reconstruct it end to end. Where the answer sits in someone’s recollection rather than a log, the organisation holds a statement of intent, and a questionnaire or audit will identify the gap.
We run AI agents inside our own security operations, so we solved AI governance for ourselves before offering it. Every agent session is logged — inputs, actions, verdicts — into the same platform that handles our customers’ security evidence, and our AI security capability applies that discipline to the AI in your environment. Secure60 holds ISO 27001:2022 certification, with AI systems inside that scope. When a review asks how your AI is governed, the answer is a record you can produce.
Do we need ISO 42001 certification?
Usually not yet. ISO 42001 is the AI management system standard, and most current requirements are satisfied by ISO 27001 with AI-specific risks and controls added. ISO 27001 for AI companies covers when 42001 becomes worth pursuing.
What does the AI section of a security questionnaire ask?
What AI systems and models you use, what customer data reaches them, who reviews their outputs, how access is controlled, and how an AI system behaving incorrectly would be detected and handled. Answers need evidence behind them, because follow-up questions request it.
Is AI governance a legal requirement?
It depends on jurisdiction and sector, and obligations are tightening. The consistent element is the shape of the requirement: a named owner, documented decisions, and records that allow an AI system’s actions to be reconstructed.
Can our existing ISO 27001 ISMS cover AI?
Largely, yes. AI systems are information systems: put them in scope, add AI-specific risks to your risk assessment, and apply the same control and evidence discipline. What most ISMSs lack is the audit trail of AI activity itself — that gap has its own guide.
How do we prove what an AI system did?
With an audit trail captured at the time: inputs, actions, outputs and approvals, logged and retained like any other security record. How do you prove what an AI system did? covers what that trail contains.