Start/Blog/ISO 42001 & AI policy template: Your guide through the EU AI Act—pragmatic and efficient
AI Regulation

ISO 42001 & AI policy template: Your guide through the EU AI Act—pragmatic and efficient

The EU AI Act requires companies to establish systematic governance structures for the legally compliant use of artificial intelligence. But where do you start? How can these complex requirements be implemented in practice without bringing business operations to a standstill? ISO 42001 is the first international standard for AI management systems and translates many abstract AI Act requirements into 38 concrete controls—a field-tested blueprint that helps you: In this article, we show you how to use the structure of ISO 42001 to comply with the AI Act pragmatically—and implement it efficiently with our policy template. This integrated approach not only saves time but also significantly reduces your AI compliance costs.

02. Februar 2026 · René Schneider · 4 min read

1. Smart integration: Use what you already have

Many companies have already established management systems for information security (ISO 27001) or data protection.

ISO 42001 can be integrated very effectively into these existing structures and adds AI-specific aspects.

Practical synergies with the GDPR

The GDPR and AI Act overlap in many areas—use the synergies from your data protection management to achieve efficient AI compliance:

Lawfulness & transparency: Both the GDPR and AI Act require transparent processing/use subject to legal permission and evidence of conformity—the GDPR for data processing and the AI Act for AI systems.

Accountability & documentation: Expand your GDPR record of processing activities to include AI systems—the documentation obligations are very similar.

Purpose limitation: Under both regulatory frameworks, every change of purpose or use requires a new risk assessment.

Integrity & confidentiality: The AI Act’s robustness and security requirements call for AI-specific technical and organisational measures that go beyond, but build on, the GDPR requirements.

Data quality & fairness: GDPR requirements concerning accuracy and protection against discrimination correspond with AI Act requirements for relevant, representative, error-free and unbiased data, as well as restrictions on automated decisions.

Risk assessment: Data protection impact assessments (DPIAs) provide the basis for the fundamental rights impact assessment (FRIA) that may be required.

Incident management: A single process should be able to cover both data protection and AI incidents.

2. Take a resource-efficient approach: Extend existing roles instead of creating new ones.

Rather than creating new positions, it is more efficient to selectively expand your established departments, teams and processes.

Executive management responsibility
Executive management bears overall responsibility for the compliant use of AI. It provides resources, defines the risk strategy, makes approval decisions (or delegates them) and regularly reviews the AI strategy as part of management review.

The cross-functional AI compliance “task force”

Relevant specialist departments must integrate AI aspects into their existing tasks, responsibilities, processes and measures:

  • Compliance, legal & risk management: AI classification, risk assessment, legal monitoring and advice
  • IT & IT security: Extend security concepts to cover AI-specific threats:
    • Protection against adversarial attacks, model poisoning and prompt injection
    • Securing API access and authentication
    • Secure data storage (opt-out configurations, encryption)
    • Access controls and permission management for AI systems
    • Monitoring AI logs and detecting anomalies
    • Incident response for AI-specific security incidents
  • Data protection: Support with specific requirements (e.g. DPIAs for AI).
  • Audit / control: Integration of AI systems into internal audit plans and documentation
  • HR: Involvement in AI systems relevant to employees (co-determination, transparency)

Specialist departments (system owners)
A specialist system owner is appointed as the “responsible coordinator” for each AI system: they conduct the initial review of every AI system, coordinate assessments throughout its lifecycle, ensure compliance with internal guidelines/policies and report to stakeholders.

3. Make existing processes “AI-ready”:

Use the 38 ISO 42001 controls as a blueprint to selectively supplement your established systems, such as your data protection management system, with the necessary AI aspects:

1) Governance & strategy—Embed the following principles here:

  • Central AI inventory:
    • Expand your software list with a simple register of AI applications (status, owner, risk class). This prevents shadow IT and provides an overview.
  • Risk management:
    • Expand existing frameworks to include specific AI risks such as hallucinations, discrimination or operational risks such as vendor lock-in.
  • Ethical compass:
    • Define quality principles such as fairness, non-discrimination and transparency as binding guidelines.
  • Training:
    • Add modules on “AI literacy” and “responsible use” to data protection and IT security training.

2) The approval process for AI systems (before introduction)

Add the following AI checkpoints to your software procurement process:

  • The “red flag” check: First determine whether the system is a prohibited practice under Article 5 of the AI Act (e.g. emotion recognition in the workplace or social scoring). This immediately stops impermissible projects and saves review effort.
  • Risk classification: Categorise the system according to the AI Act risk classes (minimal, limited, high, unacceptable).
  • Data check: Review data quality and origin (data lineage).
  • Transparency: Ensure that documentation obligations are met before commissioning.
  • Operational controls (during ongoing operation)

3) Continuous monitoring

The “go-live” of an AI system is only the beginning of compliance measures across the entire AI lifecycle. Adapt your IT and workplace policies to everyday AI use:

  • Usage control & oversight:
    • Human oversight, labelling and purpose limitation—AI systems only for approved purposes and subject to human review.
  • Access management:
    • Permission models and opt-out configurations to prevent unwanted use of data.
  • Quality assurance:
    • Monitoring performance, model drift and system changes/updates.
  • Data protection & compliance:
    • Protection of trade secrets and personal data.
  • Incident management:
    • Processes for security incidents, data breaches and quality defects (e.g. hallucinations).
  • Lifecycle management and business continuity:
    • Fallback processes for critical systems and orderly offboarding with data deletion and API access revocation.
  • Archiving:
    • AI logs in accordance with retention policies (e.g. 3 years for high-risk systems).
  • External transparency:
    • Labelling of AI-generated content.

4. Your next steps for an efficient immediate solution

Establish an internal AI policy. It minimises risks, meets legal requirements and provides clarity for all users.

Use our AI policy template

We have developed a template that covers the key requirements of ISO 42001 and the EU AI Act—pragmatic, legally sound and ready for immediate use:

  • Scope & definitions incl. 7 AI Act criteria for AI
  • Ethical compass: Fairness, non-discrimination and transparency.
  • Roles & responsibilities for all stakeholders
  • Approval & risk assessment: Checklists for procurement and risk classification
  • Operational obligations: Human oversight, labelling, quality control
  • Security & data protection: Protection of trade secrets and personal data
  • Specific use cases: Source code, marketing, meeting recordings
  • Incident management: Security incidents, data breaches, “AI hallucinations”

ISO 42001 is part of our holistic AI compliance approach. We support you in implementing it—pragmatically, purposefully and tailored to your specific needs.

Weiterlesen

Verwandte Artikel

01
AI Regulation · 01. August 2026 · 7 min read

How to label AI content correctly: A practical guide for websites and social media

Since 2 August 2026, the transparency obligations under Article 50 of the EU AI Act have applied. Anyone using chatbots, AI images, AI voices or AI-generated text has since been asking: Do I now have to label all of it? The short answer is no. The AI Act does not require companies to label every piece of AI-generated content—the obligations apply to clearly defined situations, not every use of an AI tool. This is precisely where the practical problem arises: some companies label everything out of uncertainty and therefore appear unprofessional. Others label too little and risk a violation. This article explains the four cases governed by Article 50, the applicable exceptions and exactly how to label content on websites and social media.

02
NIS2 · 06. März 2024 · 7 min read

NIS2 from 2026: These obligations are coming for SMEs.

The NIS2 Directive (EU 2022/2555) is the European Union's most far-reaching cybersecurity regulation to date - and it affects significantly more companies than its predecessor. Many SMEs still assume that ‘cybersecurity obligations’ apply only to large corporations or critical infrastructure. That misconception can be costly. As transposition into national law is taking effect gradually in several Member States, 2026 will be the year of practical application for many companies. Those who do not start now will come under time pressure. This article summarises who is affected, which obligations apply and where management bears personal responsibility.

03
Whistleblowing · 24. Februar 2022 · 7 min read

The new Whistleblower Directive – what companies should do now

With the new EU Whistleblower Directive, Brussels aims to regulate and harmonize whistleblowing across the EU for the first time. Its stated objective is better protection for whistleblowers. Anyone who reports breaches of Union law or unethical conduct in or by a company should not have to fear sanctions. To achieve this, companies must create appropriate structures and preserve whistleblowers’ anonymity. We explain what this means for companies and how they can overcome the challenges.