The Problem: Two Incorrect Approaches
The two most common approaches to implementing ISO 42001 and ISO 37301 are both incorrect:
Fragmented Approach
Implementing ISO 42001 as a separate "AI program" disconnected from the general compliance program (ISO 37301).
Superficial Approach
Treating ISO 42001 as a "technical requirement" disconnected from real regulatory obligations.
The Two Standards: What Each One Is
AI Management System (AIMS)
Published December 2023. First certifiable international standard for AI governance. Comprehensive framework that treats AI as a business process: governance, risk, compliance, and operations.
Compliance Management System
Published 2021. General compliance standard covering all regulatory obligations. Focuses on compliance culture, not specific technology. Integrable with ISO 9001, ISO 14001, ISO 37001.
How They Complement Each Other: The Integration Model
In practice:
- ISO 37301 establishes the "what" and "why": The organization decides it needs AI governance because regulations require it
- ISO 42001 specifies the "how": How to register systems, conduct fundamental rights assessments, train staff
- Integration happens in operations: When a team deploys Copilot, ISO 37301 ensures they know the policies; ISO 42001 ensures it's registered, assessed, and monitored
Explicit Mapping Between Standards
Each ISO 42001 clause must link to a compliance obligation:
| ISO 42001 Clause | Compliance Obligation | Type |
|---|---|---|
| §4-5 Context | Inventory of AI systems in operation | Governance |
| §6 Planning — Risks | Fundamental rights impact assessment | Risk Assessment |
| §7-8 Operation | Records and operational traceability | Documentation |
| §9 Monitoring | Continuous compliance monitoring | Monitoring |
| §10 Improvement | Incident management and corrective actions | Continuous Improvement |
The 3 Critical Implementation Mistakes
Parallel Systems That Don't Talk
AI policy (ISO 42001) exists but isn't linked to regulatory obligations in the compliance program (ISO 37301). AI training isn't integrated in the general program. Incidents are reported through different channels.
ISO 42001 Without Regulatory Mapping
Organizations seek ISO 42001 certification without mapping how their AI systems relate to actual regulatory obligations. Certification is granted, but when the regulator asks to "demonstrate AI Act compliance," documentation is fragmented.
Two Parallel Training Programs
HR delivers compliance training (ISO 37301): "Follow laws and regulations." AI team delivers technical training (ISO 42001): "How to govern AI systems." Staff don't see the connection.
3 Principles of Correct Integration
Principle 1: Alignment from Definition
ISO 37301 must explicitly include "AI governance" as a compliance domain. This ensures ISO 42001 is not a "separate program" but rather the specific implementation of an ISO 37301 obligation.
Principle 2: Explicit Mapping
Each ISO 42001 clause must link to a compliance obligation. It's not enough to "have both certifications" — documentation must show how each ISO 42001 control addresses a specific regulatory requirement.
Principle 3: Integrated Governance, Not Parallel
In ISO 42001: Specifies how systems are registered, how risk is assessed, what controls are implemented, how to document for audit.
The bridge: The system registry in ISO 42001 feeds the compliance indicators in ISO 37301.
Roadmap: How to Implement the Integration
Definition
ISO 37301: Document "AI governance" as a domain, link to regulatory obligations, designate owner. ISO 42001: Inventory AI systems, classify by risk, assign owners.
Mapping
Create matrix of each system → applicable obligations. Document which ISO 42001 clause addresses each obligation. Define proportional controls. Communicate to executives and teams.
Implementation
DPIA/fundamental rights assessment for high risk. Process documentation. Integrated training (not parallel). Monitoring configured with alerts and metrics.
Continuous Improvement
Incident management. Internal audit. Policy evolution as regulations change. Certification preparation if applicable.
The Result: Integrated Governance
When you correctly integrate ISO 42001 + ISO 37301, you get:
- Clear regulatory alignment: Each AI system linked to its obligation. Audit = verification, not document hunting
- Unified communication: Executives see AI governance in the context of general compliance. Teams understand why each control exists
- Structured escalation: An AI incident is not a "technical problem" — it's a compliance incident with clear escalation
- Integrated auditability: Auditor verifies both simultaneously. Regulator sees comprehensive compliance, not fragmentation
SoberanIA: Your Partner in Integrating Both Frameworks
Implementing ISO 42001 + ISO 37301 in an integrated way is not a software project. It is a governance project that requires consultants who know both frameworks in depth and accompany the implementation side-by-side with your team.
What we do differently
- Specialist consultants in both frameworks: Our team knows ISO 42001 and ISO 37301 in detail — not just the theory, but how they are operationalized in real regulated companies
- Boutique accompaniment: We work side-by-side with your compliance team, not deliver a document and disappear. We implement together
- Local regulation as expertise: We know the EU AI Act, CONPES 4144, SFC regulations, SIC, and the sector-specific norms of your market — we map your real obligations
- Platform + implementation: We don't just give you tools. We help you define policies, map systems, configure controls, and prepare for audit
- From definition to certification: We accompany from the initial inventory through to ISO 42001 certification audit preparation
Frequently Asked Questions
Implement ISO 42001 + ISO 37301 with real accompaniment
Specialist consultants in both frameworks who work side-by-side with your team — from definition to certification.
See how we work