Article 2.2 · ISO 42001 and the AI Governance Imperative
- Will Whawell

- 3 days ago
- 6 min read
T3PS Legal Dynamics · Series 2: AI Readiness — It’s Not a Technology Question ·
Written by Will Whawell. Human intelligence throughout; AI assisted with the drafting.
There is a pattern in how organisations respond to transformative technology. First, adoption outpaces governance. Then something goes wrong — a regulatory sanction, a headline, a client complaint, a fabricated citation in a court document — and the scramble for governance infrastructure begins. The difference with AI is that we can see this pattern clearly, in real time, and still choose to get ahead of it. The governance frameworks already exist. The question is whether firms have the appetite to use them.
ISO/IEC 42001:2023 is the world's first international standard for Artificial Intelligence Management Systems — AIMS in the standard's terminology. Published in December 2023, it provides a structured, auditable framework for organisations that develop, deploy, or use AI systems. It covers governance, risk assessment, impact assessment, data protection, transparency, and continuous improvement. It follows the familiar Plan-Do-Check-Act methodology that underpins the broader ISO management system family, and it is deliberately designed to integrate with existing frameworks rather than replace them.
For firms already operating under ISO 9001 or ISO 27001, the architecture will feel immediately recognisable. The clauses, the structure, the emphasis on documented processes and evidence-based decision-making — these are not foreign concepts. They are extensions of work already done.
What ISO 42001 Actually Requires
The standard does not prescribe specific AI technologies or algorithmic approaches. What it requires is that organisations establish a systematic, governed approach to managing AI throughout its lifecycle — from procurement and deployment through ongoing monitoring and eventual decommissioning.
Core requirements include:
AI risk and impact assessments. Organisations must identify and assess the risks their AI systems pose — to users, to third parties, and to society more broadly. This is not a checkbox exercise. It involves structured analysis of potential failure modes, bias risks, data quality issues, and the consequences of AI-generated errors.
Governance and accountability structures. There must be defined roles and responsibilities for AI oversight. Who owns the AI strategy? Who is accountable when a system produces poor outputs? Who has the authority to suspend or decommission an AI tool if it is not performing as expected?
Policies and controls. The organisation must establish and maintain documented policies governing AI use — acceptable use, data inputs, output review requirements, human oversight obligations.
Supplier and third-party management. Most law firms will be using third-party AI products rather than building their own. The standard requires that the governance obligations extend to supplier relationships: what data are you sharing with AI vendors, under what terms, and what oversight do you exercise over how those systems operate?
Monitoring, measurement, and continual improvement. AI systems must be monitored for performance and for emerging risks. Governance arrangements must be reviewed and updated as both the technology and the regulatory environment evolve.
The UK Governance Landscape
The UK's approach to AI regulation has been characterised, at least to date, by deliberate restraint. Rather than introducing a single comprehensive AI statute to mirror the EU's approach, the government has favoured a principles-based, sector-specific model. The AI Regulation White Paper (2023) set out five cross-sector principles — safety, transparency, fairness, accountability, and contestability — but stopped short of binding legislation.
This means that, for the legal sector, the relevant regulatory framework currently remains the SRA's Standards and Regulations. The SRA has confirmed that no AI-specific regulations exist — but it has been equally clear that existing obligations, including duties around competence, confidentiality, supervision, and client outcomes, apply fully to AI-assisted work. The SRA regulates solicitors and firms, not the technology itself. That distinction is practically important: the firm remains responsible for outputs regardless of how they were generated.
The Compliance Officer for Legal Practice — the COLP — sits at the centre of this. As one analysis of SRA expectations notes: "The COLP is expected to take responsibility for regulatory compliance when new technologies are introduced." This is not a matter of best practice. It is a regulatory expectation. And it is worth being direct about what it means: if your firm adopts an AI tool that produces errors, breaches client confidentiality, or compromises professional standards, the COLP will be expected to demonstrate what governance was in place, what monitoring was conducted, and what actions were taken.
The [AI (Regulation) Bill [HL] 2025](https://www.parliament.uk/business/news/2025/ai-regulation-bill/) proposes the establishment of an AI Authority and a risk-based regulatory framework, but is not yet enacted. In the interim, the practical governance gap — between the pace of AI adoption and the maturity of governance arrangements — is being filled, or ought to be filled, by frameworks like ISO 42001.
ISO 42001 and the EU AI Act
For firms with European operations or clients, the EU AI Act introduces a more prescriptive regime. The Act classifies AI systems by risk level and imposes corresponding compliance obligations — from transparency requirements for limited-risk systems to rigorous conformity assessments for high-risk applications. Non-compliance with the prohibited AI practices provisions carries fines of up to €35 million or 7% of worldwide annual turnover
The synergy between ISO 42001 and the EU AI Act is substantial. Both are built on risk-based classification. Both emphasise governance, accountability, transparency, and human oversight. Both require documented evidence of ongoing monitoring. As T3 Consultants' analysis notes, "by implementing ISO 42001, companies can proactively address the Act's demands for risk assessment, mitigation, and ongoing monitoring." ISO 42001 certification will not automatically demonstrate EU AI Act compliance — the Act has specific technical and procedural requirements — but it provides a substantial governance foundation and, critically, a documented audit trail.
The ISO Integration Advantage
BSI, the first certification body accredited by UKAS to certify ISO 42001, has positioned the standard alongside BS 9347 for AI governance in the UK, providing specific controls for high-risk AI applications. For firms navigating the UK landscape, this tandem framework offers a practical roadmap.
The integration potential of ISO 42001 with existing frameworks is not theoretical. In November 2025, AvISO became the first UK consultancy to achieve accredited ISO 42001 certification, completing its Stage 2 audit with A-Lign, witnessed by ANAB. AvISO's own assessment was explicit about the integration logic: the certification process built directly on their established ISO 9001, ISO 27001, and ISO 14001 frameworks. The point of departure was not a blank sheet of paper. It was an existing management system, extended and adapted.
This is the key insight for process-mature legal organisations. The investment already made in quality management and information security does not need to be duplicated. It needs to be augmented. An AI steering committee, risk assessment templates, acceptable use policies, training programmes, and output monitoring logs can all be designed to slot into the governance architecture that already exists. The documentation formats, the internal audit cycle, the management review process — these are already in place. You are adding chapters to a governance manual, not writing one from scratch.
A Practical Governance Framework for Legal AI
Drawing on ISO 42001 requirements and SRA expectations, a minimum viable AI governance framework for a law firm should include:
An AI Steering Committee. Cross-functional, with representation from leadership, technology, compliance, and fee earner communities. Responsible for approving AI tools, overseeing risk assessments, and monitoring compliance. Not a one-off project group — a standing body with defined terms of reference.
AI Risk and Impact Assessments. Conducted before deployment of any new AI tool or material change in use. Addressing data protection risks (GDPR compliance, data sharing with vendors), professional conduct risks (supervision, accuracy, client outcomes), and information security risks (access controls, data residency, breach scenarios).
An Acceptable Use Policy. Clear internal guidance on which AI tools are approved, for which purposes, with what oversight requirements. A distinction between tools approved for use and tools that are not yet approved. A process for fee earners to raise concerns or flag unexpected outputs.
Training and Competence. Documented training for all staff using AI tools. Not a vendor onboarding session repurposed as compliance evidence — genuine capability development covering both the operational use of tools and the professional and ethical obligations that attach to AI-assisted work.
Monitoring and Audit. Regular review of AI tool performance, including spot-checks of outputs. Incident reporting for AI-related errors or near-misses. Integration with the firm's existing internal audit programme.
None of this is particularly exotic. Much of it reflects what good governance looks like in any domain. What is new is the need to apply it systematically to AI, and to document that it has been applied in a way that would satisfy an SRA inspection or, increasingly, a client due diligence questionnaire.
The firms that will be best placed as regulatory expectations tighten — and they will tighten — are those that built the governance infrastructure before it was required rather than after. That is not a counsel of excessive caution. It is a straightforward observation about how regulatory cycles work, and about the considerable advantage that comes from acting when there is still time to do it thoughtfully.
Questions worth sitting with:
1. If an AI tool used by your firm today produced a materially incorrect output that affected a client matter, could your COLP produce evidence of the governance arrangements that were in place — and would that evidence satisfy regulatory scrutiny?
2. Your firm may already hold ISO 9001 or ISO 27001 certification. Has anyone in your organisation assessed what proportion of ISO 42001's requirements you could satisfy by extending existing systems, rather than starting from scratch?
3. As AI governance expectations converge internationally — EU AI Act, ISO 42001, sector-specific regulator guidance — at what point does the absence of a documented AI management system become a commercial risk as well as a regulatory one?




Comments