KI FÜR MÜNCHEN AI adoption. Done right.

UC-03 / GOVERNANCE

AI governance in our own house: working to ISO/IEC 42001 and 27001

Before we sold governance, we built it — for the most AI-driven organisation we know: our own.

Disclosure

Transparency: this case, too, concerns our own company. It is the blueprint we use to lead client projects through stage 1.

A-01 — STARTING POINT

Starting point

An organisation in which AI drives every core process does not have the governance question in theory — it has it daily: which data may go into which system? Who is accountable for automated decisions? Which application falls into which EU AI Act risk class? Without solid answers, our own operation would not be manageable.

A-02 — IMPLEMENTATION

Implementation

We built our AI management system along ISO/IEC 42001: an AI policy with clear usage rules, a role model with a named accountable person, a risk register in which every AI application is classified per the EU AI Act, and an approval process for everything new. Information security follows ISO/IEC 27001 — consistently self-hosted where sensitive data is involved.

A-03 — OUTCOME

Outcome

Every AI application in the house is classified, documented and assigned to an accountable person. New tools pass a defined approval path instead of growing wild. And from building our own system came the blueprint we use to lead clients through stage 1 — including the mistakes you no longer have to make thanks to us.

WHERE THIS FITS IN OUR APPROACH

This case IS stage 1 — applied to ourselves. Gap analysis, AIMS, risk register, training: we walk the same path with you.

Stage 1 — Governance & Readiness →

NEXT STEP

A similar starting point at your company?

In an initial consultation we check whether this path carries for your company too — and where it would have to look different in your case.