The Problem: Two Incorrect Approaches

The two most common approaches to implementing ISO 42001 and ISO 37301 are both incorrect:

Mistake 1

Fragmented Approach

Implementing ISO 42001 as a separate "AI program" disconnected from the general compliance program (ISO 37301).

Result: two systems competing for resources, misaligned policies, complex audits.
Mistake 2

Superficial Approach

Treating ISO 42001 as a "technical requirement" disconnected from real regulatory obligations.

Result: checkbox compliance, governance that doesn't scale, dissatisfied regulators.
The correct approach: see them as two complementary layers of an integrated system. ISO 37301 establishes the "what" and "why"; ISO 42001 specifies the "how."

The Two Standards: What Each One Is

ISO/IEC 42001

AI Management System (AIMS)

Published December 2023. First certifiable international standard for AI governance. Comprehensive framework that treats AI as a business process: governance, risk, compliance, and operations.

Answers: "How do we govern AI specifically?"
ISO 37301

Compliance Management System

Published 2021. General compliance standard covering all regulatory obligations. Focuses on compliance culture, not specific technology. Integrable with ISO 9001, ISO 14001, ISO 37001.

Answers: "How do we integrate AI into our compliance culture?"

How They Complement Each Other: The Integration Model

ISO 37301 (Corporate Compliance) └── AI Policies └── AI Regulatory Obligations └── AI Training └──ISO 42001 (Specific AI Governance) ├── System Registry ├── Risk Assessment ├── Technical/Operational Controls ├── Monitoring └── Audit

In practice:

  • ISO 37301 establishes the "what" and "why": The organization decides it needs AI governance because regulations require it
  • ISO 42001 specifies the "how": How to register systems, conduct fundamental rights assessments, train staff
  • Integration happens in operations: When a team deploys Copilot, ISO 37301 ensures they know the policies; ISO 42001 ensures it's registered, assessed, and monitored

Explicit Mapping Between Standards

Each ISO 42001 clause must link to a compliance obligation:

ISO 42001 ClauseCompliance ObligationType
§4-5 ContextInventory of AI systems in operationGovernance
§6 Planning — RisksFundamental rights impact assessmentRisk Assessment
§7-8 OperationRecords and operational traceabilityDocumentation
§9 MonitoringContinuous compliance monitoringMonitoring
§10 ImprovementIncident management and corrective actionsContinuous Improvement
This mapping is what separates a "checkbox compliance" program from one that works. When a regulator asks "How do you comply with the AI Act?", you have a unified answer — not two separate documents that don't talk to each other.

The 3 Critical Implementation Mistakes

Mistake 1: Fragmentation

Parallel Systems That Don't Talk

AI policy (ISO 42001) exists but isn't linked to regulatory obligations in the compliance program (ISO 37301). AI training isn't integrated in the general program. Incidents are reported through different channels.

Audits expose the cracks. Regulators see immaturity.
Mistake 2: Certification Without Foundation

ISO 42001 Without Regulatory Mapping

Organizations seek ISO 42001 certification without mapping how their AI systems relate to actual regulatory obligations. Certification is granted, but when the regulator asks to "demonstrate AI Act compliance," documentation is fragmented.

Certification is verifiable but not sufficient.
Mistake 3: Disconnected Training

Two Parallel Training Programs

HR delivers compliance training (ISO 37301): "Follow laws and regulations." AI team delivers technical training (ISO 42001): "How to govern AI systems." Staff don't see the connection.

Low adoption, confused staff, weak compliance culture.

3 Principles of Correct Integration

Principle 1: Alignment from Definition

ISO 37301 must explicitly include "AI governance" as a compliance domain. This ensures ISO 42001 is not a "separate program" but rather the specific implementation of an ISO 37301 obligation.

Principle 2: Explicit Mapping

Each ISO 42001 clause must link to a compliance obligation. It's not enough to "have both certifications" — documentation must show how each ISO 42001 control addresses a specific regulatory requirement.

Principle 3: Integrated Governance, Not Parallel

In ISO 37301: Defines that the AI governance policy exists, indicates all systems must be in the ISO 42001 registry, trains staff on why it exists (because regulation requires it).

In ISO 42001: Specifies how systems are registered, how risk is assessed, what controls are implemented, how to document for audit.

The bridge: The system registry in ISO 42001 feeds the compliance indicators in ISO 37301.

Roadmap: How to Implement the Integration

Phase 1 · Month 1-2

Definition

ISO 37301: Document "AI governance" as a domain, link to regulatory obligations, designate owner. ISO 42001: Inventory AI systems, classify by risk, assign owners.

Phase 2 · Month 3-4

Mapping

Create matrix of each system → applicable obligations. Document which ISO 42001 clause addresses each obligation. Define proportional controls. Communicate to executives and teams.

Phase 3 · Month 5-8

Implementation

DPIA/fundamental rights assessment for high risk. Process documentation. Integrated training (not parallel). Monitoring configured with alerts and metrics.

Phase 4 · Month 9+

Continuous Improvement

Incident management. Internal audit. Policy evolution as regulations change. Certification preparation if applicable.

The Result: Integrated Governance

When you correctly integrate ISO 42001 + ISO 37301, you get:

  • Clear regulatory alignment: Each AI system linked to its obligation. Audit = verification, not document hunting
  • Unified communication: Executives see AI governance in the context of general compliance. Teams understand why each control exists
  • Structured escalation: An AI incident is not a "technical problem" — it's a compliance incident with clear escalation
  • Integrated auditability: Auditor verifies both simultaneously. Regulator sees comprehensive compliance, not fragmentation
ISO 42001 is not a standalone standard. It is how you operationalize the AI regulatory compliance that ISO 37301 defines.

SoberanIA: Your Partner in Integrating Both Frameworks

Implementing ISO 42001 + ISO 37301 in an integrated way is not a software project. It is a governance project that requires consultants who know both frameworks in depth and accompany the implementation side-by-side with your team.

What we do differently

  • Specialist consultants in both frameworks: Our team knows ISO 42001 and ISO 37301 in detail — not just the theory, but how they are operationalized in real regulated companies
  • Boutique accompaniment: We work side-by-side with your compliance team, not deliver a document and disappear. We implement together
  • Local regulation as expertise: We know the EU AI Act, CONPES 4144, SFC regulations, SIC, and the sector-specific norms of your market — we map your real obligations
  • Platform + implementation: We don't just give you tools. We help you define policies, map systems, configure controls, and prepare for audit
  • From definition to certification: We accompany from the initial inventory through to ISO 42001 certification audit preparation
You don't need a Big Four to implement AI governance with rigor. You need a specialized team that understands both frameworks and commits to operations — not just the sale.

Frequently Asked Questions

Implement ISO 42001 + ISO 37301 with real accompaniment

Specialist consultants in both frameworks who work side-by-side with your team — from definition to certification.

See how we work