Strategic Transformations Advisory (STA) - AI Governance In Practice

AI Governance in Practice: What ISO/IEC 42001 Actually Requires of Singapore Enterprises

Boards across Singapore are being told they need “AI governance,” but few executives can say precisely what that means in operational terms. ISO/IEC 42001, published in December 2023, is the first attempt to answer that question with a certifiable standard rather than a set of principles. It specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System, or AIMS, within organizations that develop, provide, or use AI-based products and services (ISO). Understanding what it actually requires, clause by clause, matters more than repeating that it is “the world’s first AI management system standard.

Why This Standard Exists and Who It Applies To ?

ISO/IEC 42001 was developed jointly by the International Organization for Standardization and the International Electrotechnical Commission to address a gap that principles-based AI ethics frameworks left open: a lack of a certifiable, auditable structure that regulators, customers, and boards could point to as evidence of due diligence (ISO). It is deliberately industry-agnostic. It applies to organizations of any size, in any sector, whether they build AI models, integrate third-party AI into products, or simply use AI tools in their operations, and it is relevant to public sector agencies as much as private companies (ISO).

In Singapore, adoption has moved quickly from theory to certificate. Cedars Digital, a Singapore-based AI and sustainability technology firm, achieved ISO/IEC 42001 certification in June 2026, with the certificate issued by SGS following advisory support from Deloitte (PR Newswire). Regional technology providers have followed the same path: SGS awarded Huawei ISO/IEC 42001 certification covering five core business areas including ICT infrastructure, cloud, and intelligent automotive solutions, with the audit assessing AI governance practices across the entire lifecycle from data management through deployment and operational monitoring (SGS). Financial services firms operating in Singapore, including fund administrator IQ-EQ, have also pursued certification specifically to demonstrate governed use of AI in client-facing operations (IQ-EQ).

The value of ISO/IEC 42001 for a CIO or transformation lead lies in its structure, which follows the same high-level format as ISO 27001 and ISO 9001, making integration with existing management systems more straightforward. Clause 4 requires the organization to determine internal and external issues relevant to its AI activities, including applicable regulation and the board’s risk appetite, and to define and document the scope of the AIMS, specifying which AI systems, business units, and roles are covered (Konfirmity). This scoping exercise alone tends to surface uncomfortable truths in large enterprises, where “AI” is often running in pockets nobody has inventoried.

What the Clauses Actually Require ?

Clause 5 places accountability squarely with top management, who must demonstrate commitment by integrating the AIMS into business processes, providing adequate resources, and establishing a documented AI policy that states the organization’s position on responsible AI (Konfirmity). This is not a delegable task pushed down to a data science team; the standard expects governance ownership at the executive level, with clearly assigned roles and authorities.

Clause 6 is where the substantive risk work happens. It requires a defined AI risk assessment process to identify, analyze, and evaluate risks created by AI systems using consistent and repeatable criteria, followed by risk treatment decisions and a Statement of Applicability that identifies which Annex A controls apply and why. Critically, it also requires an AI system impact assessment process, distinct from the risk assessment, that considers effects on individuals, groups, and society (Konfirmity). Many organizations that have run AI ethics workshops have never formalized this as a repeatable, documented process, which is precisely what an external auditor will test.

Clause 7 covers support functions: ensuring competence of personnel making AI-related decisions, evidenced by training or experience records, establishing organization-wide awareness, and controlling documented information such as the AI policy, risk assessments, and impact assessments through version control and access management (Konfirmity). The remaining clauses (8 through 10) address operational control, performance evaluation, and continual improvement, mirroring the plan-do-check-act cycle familiar from other ISO management system standards.

Positioning ISO 42001 Within a Broader Compliance Stack

For Singapore enterprises, ISO/IEC 42001 does not stand alone. It sits alongside domestic obligations that already touch AI-adjacent systems: the Personal Data Protection Act governs the personal data that most AI systems process (ArkShield), and the Cyber Security Agency’s Cyber Trust mark now explicitly extends into AI Security as one of its assessed domains, alongside Cloud Security and Operational Technology Security, for organizations with more extensive digitalized operations (CSA). Enterprises pursuing ISO/IEC 42001 certification should map its Annex A controls against existing PDPA data handling processes and Cyber Trust assessments rather than running three parallel compliance efforts. SGS explicitly frames its ISO/IEC 42001 service as part of a broader “Digital Trust” offering that spans cybersecurity, privacy, AI governance, and digital compliance across the technology lifecycle, reflecting this convergence in how certification bodies now approach the space (SGS).

What Boards Should Ask Before Committing to Certification ?

Certification is a meaningful signal to regulators, enterprise customers, and procurement teams, but it is not free and it is not fast. Before committing resources, boards should ask three questions grounded in the clause structure itself. First, can management name every AI system in scope, including embedded AI in vendor software, or will scoping under Clause 4 become a multi-month discovery exercise? Second, does the organization already run a repeatable AI risk and impact assessment process under Clause 6, or does it rely on ad hoc ethics reviews that will not survive an audit? Third, who owns the AI policy at the leadership level under Clause 5, and do they have the authority and budget the standard expects them to demonstrate?

Enterprises that answer these honestly before engaging a certification body will spend less time in remediation and more time building an AIMS that actually reduces AI-related risk, rather than one built only to pass an audit. The standard’s real value is not the certificate on the wall. It is the discipline of documenting, in a form a third party can verify, how an organization actually decides what AI it will build, buy, and deploy, and how it will know if that AI is causing harm.

Leave a Comment

Your email address will not be published. Required fields are marked *