No parallel system for AI
Bias, hallucination, model drift, privacy risk, vendor AI and shadow AI are not a separate universe. They must be translated into internal controls and risk management: control objectives, owners, evidence and escalation routes.
ISO/IEC 42001 offers a management-system framework. The EU AI Act adds concrete role, deployer, high-risk, logging and incident obligations. Good governance connects both with the existing processes of the corporation.
Mapping AI risks to control objectives
| AI risk | Control objective |
|---|---|
| Incomplete inventory | All AI systems are captured, classified, assigned to an owner and reviewed regularly. |
| Bias or discrimination | Risk analysis, testing concept, human oversight and complaint/escalation routes are documented. |
| Model drift | Performance metrics, review cycles and thresholds for reassessment or deactivation are defined. |
| Vendor AI | Supplier information, Art. 25 role allocation, contractual records and update processes are traceable. |
| Incidents | AI Act, GDPR, DORA/NISG and internal escalations are assessed separately and coordinated. |
Three-lines model
The first line consists of business units and system owners: use, controls and ongoing monitoring. The second line coordinates compliance, risk, privacy and information security. The third line independently checks whether the model works and evidence is reliable.
The cycle should report regularly to management and, where relevant, to the supervisory board: inventory status, high-risk systems, open measures, incidents, audit findings and material changes.