EN

Internal controls · risk management · ISO/IEC 42001

AI Governance in Internal Controls and Risk Management

AI risks should not run outside the organisation. They belong in existing control objectives, risk maps, responsibilities and review cycles.

No parallel system for AI

Bias, hallucination, model drift, privacy risk, vendor AI and shadow AI are not a separate universe. They must be translated into internal controls and risk management: control objectives, owners, evidence and escalation routes.

ISO/IEC 42001 offers a management-system framework. The EU AI Act adds concrete role, deployer, high-risk, logging and incident obligations. Good governance connects both with the existing processes of the corporation.

Mapping AI risks to control objectives

AI riskControl objective
Incomplete inventoryAll AI systems are captured, classified, assigned to an owner and reviewed regularly.
Bias or discriminationRisk analysis, testing concept, human oversight and complaint/escalation routes are documented.
Model driftPerformance metrics, review cycles and thresholds for reassessment or deactivation are defined.
Vendor AISupplier information, Art. 25 role allocation, contractual records and update processes are traceable.
IncidentsAI Act, GDPR, DORA/NISG and internal escalations are assessed separately and coordinated.

Three-lines model

The first line consists of business units and system owners: use, controls and ongoing monitoring. The second line coordinates compliance, risk, privacy and information security. The third line independently checks whether the model works and evidence is reliable.

Management review

The cycle should report regularly to management and, where relevant, to the supervisory board: inventory status, high-risk systems, open measures, incidents, audit findings and material changes.

Integrate AI risks into existing governance.

We support the design of control objectives, review cycles and evidence for AI governance.

Request gap analysis
Notice: This page is for general information only and does not constitute legal, certification or audit advice. Content reflects the reviewed status of July 2026.