Book an Appointment

AI Compliance & Governance

How to build an AI governance program in a structured way – from the AI inventory through risk classification and AI literacy to lifecycle controls along the AI Act, ISO/IEC 42001, the NIST AI RMF and BSI AIC4.

Hardly any organization introduces just a single AI system these days – the typical picture is a growing portfolio of AI features in standard software, use cases built on generative models and a handful of in-house developments. Regulation (EU) 2024/1689 (the AI Act) sets a staggered framework for this: the AI literacy obligation and the bans on certain practices have applied since 2 February 2025, the obligations for providers of general-purpose AI models since 2 August 2025, and the transparency obligations of Art. 50 apply from 2 August 2026; following the "Digital Omnibus" Regulation (EU) 2026/1744, the high-risk obligations follow in stages from 2 December 2027. AI governance is the answer to this mix: a program that systematically records AI use, classifies each use case by risk and steers it across the entire lifecycle. This overview page puts the building blocks into context – for details on ISO/IEC 42001, the transparency obligations under Art. 50 and the NIST AI frameworks, see the respective deep dives in this knowledge base.

The Essentials at a Glance

01

AI inventory and risk classification per use case

The starting point of any governance program is a complete inventory: which AI systems and features are in use – developed in-house, procured as a service or embedded as a feature in standard software – and which business units use them for what? Each use case is then classified along the risk categories of the AI Act: prohibited practices (Art. 5, applicable since 2 February 2025), high-risk systems (Art. 6 in conjunction with Annex III), systems subject to transparency obligations (Art. 50) and minimal-risk systems. Relevant for planning: Regulation (EU) 2026/1744 (the "Digital Omnibus", in force since 27 July 2026) has postponed the application of the high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (systems embedded in products under Annex I). The classification determines the depth of controls, the scope of documentation and the approval paths – and must be repeated whenever a use case changes substantially.

02

AI literacy under Art. 4 AI Act

Since 2 February 2025, Art. 4 has required providers and deployers of AI systems to take measures to ensure the AI literacy of their staff and of third parties acting on their behalf – tailored to role, prior knowledge and context of use. No specific training format, certification or formally appointed AI officer is prescribed; what matters is traceable documentation of the measures taken. With Regulation (EU) 2026/1744, Art. 4 was softened into an obligation to promote AI literacy, and it was clarified that no specific level of knowledge has to be guaranteed for individual persons – risk-based training approaches therefore remain permissible. In practice, a proven pattern is basic training for all employees plus deeper, role-specific modules for development, procurement, business units with riskier use cases and management.

03

Roles and responsibilities

The AI Act ties obligations to roles – above all providers and deployers – and the same organization can take on different roles depending on the use case; anyone who substantially modifies a third-party system or offers it under their own name can move into the provider role. Internally, a governance program needs clear responsibilities: a board or function that approves use cases and owns the inventory, named owners for each AI system, and the involvement of the CISO, the data protection officer, legal and the business units. ISO/IEC 42001 anchors this structure in the management system: top-management commitment, a documented AI policy and defined roles with authorities. There is no legally mandated "AI officer" – yet responsibility still has to be assigned unambiguously and lived in practice.

04

Lifecycle controls: from idea to decommissioning

Controls only work if they cover the entire lifecycle: impact and risk assessment before development or procurement, data quality and bias checks, testing and validation before go-live, human oversight and logging in operation, monitoring for drift and misbehavior, and managed change and decommissioning processes. The NIST AI RMF structures these tasks through its four functions Govern, Map, Measure and Manage; ISO/IEC 42005:2025 adds guidance on AI impact assessments as a building block of the management system. For procured AI cloud services, the BSI criteria catalogue AIC4 defines auditable criteria across the lifecycle – from security and robustness through performance, reliability, data quality and data management to explainability and bias. Substantial changes to a model or its purpose should automatically trigger a reassessment of the risk class.

05

Standards map: AI Act, ISO/IEC 42001, NIST AI RMF, BSI AIC4

The building blocks complement rather than compete with each other. As law, the AI Act sets the binding framework; ISO/IEC 42001:2023, the first certifiable standard for AI management systems (AIMS), describes the organizational implementation – following the same management-system logic as ISO/IEC 27001; the NIST AI RMF (AI RMF 1.0, 2023) is a voluntary framework for managing the risks of individual AI systems, complemented by the generative AI profile NIST AI 600-1 (2024); BSI AIC4 (2021), an extension of the C5 catalogue, addresses the auditability of AI cloud services. A governance program typically combines all of these levels: the law as obligation, ISO/IEC 42001 as the management system, NIST as the methodology, AIC4 as an assurance instrument for suppliers. The deep dives "ISO 42001 in Practice", "AI Act Transparency Obligations" and "NIST AI Frameworks" in this knowledge base provide further detail.

06

Interlocking with data protection and DPIAs

If an AI system processes personal data, the GDPR applies in full alongside the AI Act; for many AI use cases, a data protection impact assessment under Art. 35 GDPR is required. Certain deployers of high-risk systems – in particular public bodies and private providers of public services – must additionally carry out a fundamental rights impact assessment under Art. 27 AI Act; under Art. 27(4), this complements a DPIA that has already been carried out rather than replacing it. Practical guidance comes from the papers of the German Datenschutzkonferenz (DSK): the guidance "Künstliche Intelligenz und Datenschutz" (version 1.0, May 2024) on legal bases, purpose limitation and data subject rights, and the guidance on technical and organizational measures for the development and operation of AI systems (June 2025). Organizationally, it makes sense to set up a joint intake process in which AI classification and data protection review assess the same use case once instead of twice.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Amtsblatt der EU / EUR-Lex · 2024

Verordnung (EU) 2024/1689 (KI-Verordnung / AI Act)

Risk-based legal framework with staggered application; relevant here: Art. 4 (AI literacy), Art. 5 (prohibitions), Art. 6/Annex III (high risk), Art. 27 (fundamental rights impact assessment), Art. 50 (transparency).

Amtsblatt der EU / EUR-Lex · 2026

Verordnung (EU) 2026/1744 („Digital Omnibus on AI“)

In force since 27 July 2026; postpones the high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I) and softens the AI literacy obligation of Art. 4 into an obligation to promote AI literacy.

ISO/IEC · 2023

ISO/IEC 42001:2023 – Information technology – Artificial intelligence – Management system

First certifiable standard for AI management systems (AIMS); complemented by ISO/IEC 42005:2025 as guidance for AI impact assessments.

NIST · 2023

Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1

Voluntary framework built around the four functions Govern, Map, Measure, Manage; complemented for generative AI by the profile NIST AI 600-1 (2024).

BSI · 2021

AI Cloud Service Compliance Criteria Catalogue (AIC4)

Auditable criteria for AI cloud services across the entire lifecycle (including robustness, data quality, explainability, bias) as an extension of the C5 catalogue.

Datenschutzkonferenz (DSK) · 2024

Orientierungshilfe „Künstliche Intelligenz und Datenschutz“ (Version 1.0)

Data protection requirements for AI applications including DPIAs; complemented by the DSK guidance on technical and organizational measures for the development and operation of AI systems (June 2025).

Where does your AI governance program stand?

In a no-obligation initial consultation, we jointly assess which building blocks – from the AI inventory to ISO/IEC 42001 readiness – should take priority in your organization.