Table of contents
Table of contents
- Why AI governance became an IT problem, not just a legal one
- The three governance standards, in plain English
- How the three standards actually relate to each other
- What this means for IT teams, practically: an AI governance checklist
- Evaluating AI vendors against these standards
- The standards will keep shifting. The discipline won't.
AI has been deployed and adopted at breakneck pace, and it’s time now for the tough questions: How do we govern our AI? How do we know how vendors are governing their AI tools?
For IT teams, these questions might arise from a customer’s security questionnaire, a new, stringent regulation, or a board member. And for many IT teams, facing a new type of technology, the answer is “we’re not sure.” With proliferating new standards and acronyms, the question of AI governance has become essential, and confusing.
Three standards in particular are coming up for IT teams: ISO 42001, SOC 2, and the EU AI Act. Though you may hear about them as interchangeable, they each bring different degrees of regulation for different systems. We’ll explore in this piece what IT team members need to know, and what they’re actually on the hook for.
Why AI governance became an IT problem, not just a legal one
Enterprise AI has crossed a threshold: IT teams aren’t simply hosting chatbots, but deploying agentic systems that can alter production environments, remediate security incidents, and approve infrastructure access. This kind of autonomy, using AI agents, raises the governance stakes significantly. When an autonomous system can change live environments, every algorithmic decision brings risk.
That’s quickly led to expanded AI governance frameworks and new AI governance standards being rolled out. In the past, questions about technology security may have been a task for legal to translate for IT. But now IT leaders sit on the front lines: they deploy AI tools and must prove they’ve scoped, monitored, and audited them safely. AI governance has become a core IT architecture problem.
The three governance standards, in plain English
SOC 2, the security and data-handling baseline
Baseline in North America to prove vendor data security, including AI security.
What is it: an American Institute of Certified Public Accountants (AICPA) framework, independently audited, assessing controls across security and (depending on scope) availability, confidentiality, processing integrity, and privacy.Auditors deliver it as either a Type 1 report, which assesses design at a single point in time, or a Type 2 report, which evaluates operational effectiveness over a period of time, typically six months or more.
Who pursues it: Companies doing business in North America that need to show they handle customer data securely. However, SOC 2 does not provide visibility into how the vendor governs an AI model’s automated actions, decision-making logic, oversight, or underlying bias. ISO 42001 exists specifically to bridge that gap.
ISO/IEC 42001, the AI management system standard
Voluntary, not law. Global in scope (not EU-specific).
What is it: ISO 42001 is the first international standard for managing AI systems responsibly across their lifecycle, including AI data governance, risk, transparency, and accountability. It assesses and certifies an organization’s underlying management system for building, deploying, and monitoring AI. ISO 42001 is not mandatory.
Who pursues it: Organizations that build or heavily deploy AI and want a recognized way to show that they’re managing AI risk systematically, especially since SOC 2 alone doesn’t cover AI model-specific vulnerabilities like algorithmic drift, hallucination, or training data integrity. If your organization already holds ISO 27001, this is a natural next step: ISO 42001 extends that same management-system approach to address oversight specific to AI systems.
The EU AI Act, the legal mandate
Brand-new, legally binding mandate that applies to businesses whose AI system’s output touches the EU market.
What is it: the first comprehensive, horizontal AI law, using a risk-tiered framework of unacceptable, high, limited, and minimal risk categories. Regulatory obligations scale according to those categories, and companies that don’t comply will face penalties.
What’s the timing: At the time of this writing, it is now enacted law that standalone, high-risk system obligations must be met by December of 2027, while product-embedded high-risk obligations must be met by August of 2028. The related Article 50 transparency obligations, like disclosing AI interactions and labeling AI-generated content, took effect on August 2, 2026 (the one EU AI Act deadline that actually landed in 2026, even as the high-risk deadlines above were pushed out), and are being enforced (with a grace period for systems already on the market).
Who it will affect: Applies beyond EU-headquartered companies: EU AI Act compliance will be based on whether the AI system’s output touches the EU market, not where the company is based.
Most IT service management AI, including tools that summarize tickets, suggest fixes, or automate routine tasks, doesn’t fall into the EU AI Act’s high-risk Annex III categories, which are reserved for things like biometric identification, critical infrastructure control, and employment decisions. That means the sweeping compliance obligations tied to high-risk systems often don’t apply to the AI already running in your IT stack.
Two obligations still apply regardless of risk tier, though: the Article 50 transparency rules above, and Article 4 AI literacy, covered next.
Article 4 AI literacy is the one EU AI Act obligation that already applies to almost every IT team using AI today. It has bound deployers, that’s you, since February 2, 2025, requiring that staff have a sufficient level of AI literacy to use AI systems responsibly; the wording of that duty was softened on July 27, 2026, from an obligation to ensure literacy to one to take measures supporting it. Unlike the high-risk provisions still phasing in through 2027 and 2028, this one is already in force, regardless of whether the underlying AI system is high-risk.
One notable framework isn’t covered in this comparison: the NIST AI Risk Management Framework. It’s voluntary guidance rather than a certifiable standard, so it’s outside the scope of a piece comparing three certifiable or legally mandated standards, though many North American organizations use it alongside SOC 2 and ISO 42001.
How the three standards actually relate to each other
SOC 2, ISO/IEC 42001, and the EU AI Act represent complementary layers in a comprehensive AI governance stack.
- SOC 2 serves as an operational baseline, the foundational security and data handling layer. It’s the controls that enterprise buyers already expect, such as being able to verify that an organization safely handles customer data and secures its underlying cloud infrastructure.
- ISO/IEC 42001 is the AI-specific management layer on top of that foundation, showing that AI risk is managed systematically, not ad hoc. It addresses model behavior, algorithmic bias, drift, and lifecycle oversight.
- The EU AI Act is the new mandatory statutory requirement that applies regardless of whether you pursue any certification at all, if your AI’s output reaches EU markets. It establishes non-negotiable legal parameters.
So, do you need ISO 42001 if you already have SOC 2? Yes, if you want visibility into how a vendor actually governs its AI models, since SOC 2 was never designed to assess algorithmic decision-making, bias, or drift.
SOC 2 and ISO 42001 are frameworks you choose to pursue to prove trustworthiness and earn market trust, while the EU AI Act is not a choice if your products fall in its scope.
What this means for IT teams, practically: an AI governance checklist
So, when IT teams are considering enterprise AI compliance in products and services, there are some important details to remember and questions to ask if you’re considering other vendors’ products. Here’s an overview.
| Category | Action item | Key verification |
| Vendor due diligence | Audit action logging: Ask if the tool generates time-stamped logs for every autonomous action (API calls, data writes, access changes). | Sample audit logs showing prompt, model output, decision confidence, and execution context. |
| Vendor due diligence | Oversight mechanism validation: Make sure the system includes human-in-the-loop approval workflows and emergency override features. | Documentation on approval thresholds and manual overrides. |
| Vendor due diligence | Clarify data handling: Ask whether customer data is used to train the vendor’s models, where it’s stored, what the retention window is, and who the subprocessors are. | Written answers on model training use, data residency, retention windows, and a current subprocessor list. |
| Internal readiness | Maintain an AI inventory: Map internal and third-party AI tools with details on their business purpose, underlying models, data sources, and system permissions. | IT inventory with risk-tier classifications for every AI tool used. |
| Internal readiness | Document human control points: Show the operational workflows in place that distinguish autonomous actions vs. those that need human intervention. | Architecture diagrams showing the human-in-the-loop workflows. |
| Internal readiness | Implement action logging: Make sure log infrastructure records inputs, decision confidence scores, and outputs for all agentic AI systems. | Log policy that shows AI model activity along with the typical event logs. |
And finally: don’t assume any overlap among certifications and obligations. SOC 2 compliance doesn’t cover AI governance, and ISO 42001 certification doesn’t satisfy the EU AI Act’s obligations.
Evaluating AI vendors against these standards
These certifications are a solid starting checklist when you’re evaluating any AI vendor, especially one that’s getting autonomous or semi-autonomous access to your environment. To put this in real-world terms, autonomous IT platform provider Atera recently became ISO 42001 certified, along with holding SOC 2 Type 2, ISO 27001, 27017, and 27018 certifications, and TX-RAMP L2 authorization, and aligning with ISO 27032 guidance, HIPAA, and GDPR.
Getting that certification mattered because of the nature of Robin by Atera, the platform’s autonomous IT agent, which already runs on configurable guardrails, approval workflows, and full audit trails. What the ISO 42001 certification adds is that an independent auditor reviewed how Atera governs AI across the lifecycle, which matters more when the product is taking real actions in a customer environment.
The standards will keep shifting. The discipline won’t.
Keep an eye on new standards emerging and what that will mean both for your business and when evaluating vendors; the EU AI Act names several key dates in 2027, for example.
More broadly, though, continue to practice the discipline of knowing what your AI does, who’s watching it, and how you’d prove it if asked. That ongoing work continues no matter which acronym is in the headlines next.
Related Articles
ISO 42001 for IT leaders: what the certification actually means for your stack
ISO 42001 is a still-new AI standards certification that’s becoming more popular in vendor security questionnaires. See what ISO 42001 for IT leaders means.
Read nowAtera is ISO/IEC 42001 certified. Here’s what that actually means.
AI governance is no longer a nice-to-have. Here's how Atera is staying ahead of it—and what that means for you.
Read nowAgentic AI Will Reorganize IT Before It Replaces Anyone
IT departments need to modernize away from the typical help desk support model, where tickets pile up to be triaged and solved, and technicians get stuck in a break/fix cycle. Agentic AI can reshape IT teams for the better without taking jobs.
Read nowThe Best AI Tools for IT Support Ticket Triage in 2026
Faster routing isn't the same as fewer tickets. We ranked the best AI ticket triage tools of 2026 — and explain why the smartest teams are skipping triage altogether.
Read nowEndless IT possibilities
Boost your productivity with Atera’s intuitive, centralized all-in-one platform










