ISO 42001 and EU AI Act — Who Owns What
ISO/IEC 42001:2023 is the first global, certifiable framework for an AI management system (AIMS) — policies, risk, roles, and continual improvement. The EU AI Act adds hard technical duties for high-risk AI, especially automatic logging under Article 12. Most teams need both a governance programme and runtime proof. They are not the same product category.
Two layers, one audit story
| Layer | What it answers | Typical tools | Sigigo? |
|---|---|---|---|
| Governance programme | Do we have policies, risks, roles, and improvement loops? | Vanta, ISMS platforms, GRC suites, Evidary Dossier | No — customer-owned AIMS |
| Runtime evidence | Can we prove what the AI did — automatically, tamper-evidently, independently? | Sigigo SDK + evidence packs | Yes — core product |
GRC automation can collect cloud configuration, access controls, and policy documents. It does not witness model inference, agent tool calls, or human overrides at the decision boundary. That is what market surveillance expects under Article 12.
Who owns what
| Artifact / activity | Owner | Sigigo role |
|---|---|---|
| AI policy, scope, Statement of Applicability | AIMS / GRC programme | None |
| Risk register & impact assessments | Legal + risk team | Optional hash reference in export |
| Annex IV technical documentation | Provider conformity file | Reference only — not generated |
| Automatic inference logging (Art. 12) | Engineering | SDK — ai_act.* at boundary |
| Human oversight (Art. 14) | Operations | ai_act.human_review_completed, human_override |
| Deployer retention ≥ 6 months (Art. 26) | Deployer | Tenant policy + export slice |
| Transparency disclosure (Art. 50) | Product + engineering | ai_act.transparency_disclosure |
| Evidence pack for surveillance | Audit response | Self-contained export + offline verify |
ISO 42001 operational themes → runtime evidence
ISO 42001 Annex A describes organisational and operational controls. Where those controls touch live AI systems, auditors increasingly ask for reconstructable session chains — not policy PDFs alone.
| ISO 42001 theme | EU AI Act link | Sigigo instrumentation |
|---|---|---|
| Lifecycle traceability (A.4.2, A.4.3) | Art. 12 session chain | session_id from inference_started → completed |
| Accountability (A.4.6) | Art. 12 operator, Art. 14 oversight | actor, overseer_id on review events |
| Model & data lineage (A.4.2) | Art. 12 metadata | gpai_model_id, gpai_model_version, input_hash |
| Monitoring (A.8) | Art. 72 post-market | ai_act.operation_monitored |
| Record authenticity (C.2.7, C.2.10) | Art. 12 tamper-evidence | Signed events, Merkle proofs |
| Regulatory response (A.8.2, A.8.3) | Surveillance export | Evidence pack with VERIFY instructions |
Full field map: Article 12 hub. Technical gaps: readiness quiz.
Running ISO 42001 with Sigigo (practical)
- Stand up or extend your AIMS in your GRC platform — policies, risks, control tests, auditor workflow.
- Instrument every production high-risk inference path with Sigigo at the API or agent boundary.
- Link human review and transparency events to the same
session_idas model output. - Practice exporting an evidence pack for a sample retention window before surveillance asks.
- Store dossier snapshots and model cards in your QMS; reference their hashes from Sigigo exports when useful.
What Sigigo does not do
- ISO 42001 certification, accredited audit, or Statement of Applicability authoring
- Annex IV technical documentation or legal conformity assessment
- Policy templates, control libraries, or hourly cloud configuration tests
- Replace your AI management system — we supply the runtime cryptographic evidence slice
FAQ
- Can Sigigo get us ISO 42001 certified?
- No. Certification requires a complete AIMS — policies, risk treatment, internal audit, management review — assessed by an accredited auditor. Sigigo helps operationalise Article 12–14 technical logging and exportable proof that ISO 42001 programmes must support for high-risk AI.
- We use Vanta (or similar) for ISO 42001 — do we still need Sigigo?
- Often yes, if you operate high-risk AI in production. GRC tools excel at organisational evidence and integrations; Article 12 requires automatic, lifetime, tamper-evident logs at the inference boundary — typically outside what cloud config monitoring captures.
- How does ISO 42001 relate to the EU AI Act?
- ISO 42001 is voluntary and certifiable; the EU AI Act is law with enforcement timelines. They align on responsible AI themes — risk, oversight, monitoring, documentation — but only the Act mandates specific technical logging for high-risk systems. Many enterprises pursue both.
- What should we show an ISO 42001 auditor vs market surveillance?
- ISO auditors: AIMS records, risk treatment, control effectiveness. Market surveillance: operational logs and evidence packs proving automatic capture, retention, and integrity. Sigigo targets the latter; your GRC platform targets the former.
Running an ISO 42001 programme? Run the Article 12 readiness quiz or book a workshop to map operational controls to ai_act.* events.
This guide supports qualification and architecture planning — it is not legal advice. Work with your legal and compliance teams on classification, DPAs, and deployment approvals. See also our Regulatory & Compliance page.