Govern Your AI To The EU AI Act
And ISO 42001

AI moved from pilot to production faster than the oversight around it. IrisInfosec gives you that oversight: an inventory of where AI is used, a clear risk classification under the EU AI Act, and an AI management system to ISO 42001 and the NIST AI RMF. The result is responsible AI you can evidence to a board and a regulator.

4

EU AI Act risk tiers your systems are classified into.

ISO 42001

A certifiable AI management system.

Inventory

Every AI use found, including vendor and GenAI tools.

Oversight

Human-in-the-loop and accountability by design.

What this covers

Oversight That Keeps Pace With Adoption

Most organisations are already using more AI than they have governed, often through vendor features and generative tools no one formally approved. The work is to find it, classify it, and put proportionate oversight around it before a regulator or an incident does the finding for you.

This is governance of the AI you build and the AI you buy. It is about overseeing AI responsibly, not badging a product with it, and it sits naturally beside your privacy and security programmes.

In one line

AI governance and responsible AI

is the inventory, risk classification, management system and oversight that let you develop and use AI lawfully and accountably, aligned to the EU AI Act, ISO 42001 and the NIST AI RMF.

What we build

From AI Inventory To Accountable Oversight

The components of a governance programme that an auditor, a board and a regulator
can all follow.

AI Inventory

A register of every AI system in use, built and bought, with owner, purpose and data, so nothing governs in the dark.

EU AI Act Risk Classification

Classify each system into the right tier and define the obligations that follow, from transparency to conformity assessment.

AI Management System (ISO 42001)

A certifiable management system that governs how AI is developed, procured and operated across the organisation.

Model & Data Governance

Controls over training data, model changes, evaluation and documentation, so decisions can be explained later.

Transparency & Human Oversight

Disclosure where the Act requires it, and human-in-the-loop controls proportionate to each system’s risk.

NIST AI RMF Alignment

Map your programme to the NIST AI Risk Management Framework for a common language across EU and US stakeholders.

Where governance starts

The EU AI Act Risk Tiers

Obligations follow risk. Knowing which tier each system sits in is the first decision, and
the one everything else depends on.

Tier What It Means What It Requires
Unacceptable A short list of prohibited uses Not permitted on the EU market
High-risk Sensitive uses such as employment or credit Risk management, data governance, oversight, conformity assessment
Limited risk Systems that interact with people Transparency, so users know they are dealing with AI
Minimal risk The majority of everyday AI Voluntary codes of practice

How we work

From Discovery To Ongoing Oversight

A measured approach that fits how your teams actually adopt AI.

01

Inventory

Find every AI system in use, built and bought, and record purpose, owner and data.

02

Classify

Place each system in its EU AI Act tier and confirm the obligations that apply.

03

Govern

Stand up the management system, policies and controls proportionate to each tier.

04

Document

Produce the technical documentation, assessments and disclosures the Act expects.

05

Monitor

Ongoing oversight of models, vendors and new use cases as your adoption grows.

What you receive

Governance You Can Evidence

The register, the management system and the documentation a board, an auditor and a
regulator can all follow.

AI Inventory & Risk Register

A maintained register of AI systems with their tier, owner and the obligations attached to each.

AI Management System

The ISO 42001 policies, roles and processes to govern AI across its lifecycle, ready for certification.

Documentation & Assessments

Technical documentation, impact assessments and disclosures for your high-risk and customer-facing systems.

Know your AI before a regulator asks

Start With An Inventory And A Risk Read

Tell us where AI shows up in your products and operations. We will inventory it, classify
it under the EU AI Act, and send a prioritised plan.

Questions, answered

AI Governance FAQ

The EU AI Act classifies AI systems by risk and sets obligations accordingly. A small set of uses are prohibited. High-risk systems carry duties such as risk management, data governance, documentation, human oversight and conformity assessment. Limited-risk systems mainly require transparency. Obligations apply in stages through 2025 and 2026, so the first step is to know which tier your systems fall into.

Broadly, AI used in areas the Act lists as sensitive, such as employment, credit, education, essential services, biometrics and critical infrastructure, or AI that is a safety component of a regulated product. High-risk status brings the heaviest obligations, so accurate classification is where governance starts.

ISO 42001 is the international standard for an AI management system. It gives you a certifiable framework to govern how AI is developed, procured and used, much as ISO 27001 does for information security. It pairs well with the EU AI Act and reuses an existing management system where you have one.

Yes. Deploying AI, including third-party and generative tools, still carries obligations under the EU AI Act and creates privacy and security risk. You need an inventory of where AI is used, an assessment of each use, and oversight of the vendors providing it, even if you build nothing yourselves.

Most AI processes personal data, so AI governance and data protection overlap heavily. A DPIA is often required for high-risk AI, and lawful basis, transparency and data minimisation all apply. We run the two together so your AI oversight and your privacy programme reinforce each other.

Related services

Responsible AI You Can Put In Front Of A Regulator

Book a call with an advisor who works from the EU AI Act itself. We
inventory and classify your AI and send a prioritised plan, no obligation.