TL;DR: ISO/IEC 42001 certification formalises a structured AI management system covering ethics, risk, transparency, accountability, and continuous monitoring, with implementation spanning governance, legal, operations, and technical teams, according to Unosecur. For identity practitioners, the point is that AI governance is no longer a side policy; it is becoming a lifecycle discipline that must be auditable, explainable, and tied to access, oversight, and control ownership.
NHIMG editorial — based on content published by Unosecur: Unosecur achieves ISO/IEC 42001 certification and outlines its AI governance approach
By the numbers:
- 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems.
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security.
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job.
Questions worth separating out
Q: How should security teams govern AI in cybersecurity operations?
A: Security teams should govern AI in cybersecurity operations as a workflow control, not just a detection feature.
Q: What breaks when identity mapping is treated as enough for AI governance?
A: What breaks is the assumption that knowing an agent’s owner means the organisation can trust the agent’s behaviour.
Q: Why does human oversight matter for AI governance?
A: Human oversight matters because AI outputs can look confident while still being wrong, biased, or incomplete.
Practitioner guidance
- Define AI ownership and accountability Assign named business and technical owners for every AI system that can affect access, security actions, or operational decisions.
- Map AI systems to access boundaries Document what data, tools, APIs, and workflows each AI system can reach, then compare that scope to the minimum required for the job.
- Build reviewable human override paths Create explicit intervention points for high-risk AI decisions so humans can pause, approve, or reverse actions before they complete.
What's in the full article
Unosecur's full blog covers the implementation detail this post intentionally leaves at the governance level:
- The certification journey across governance assessment, control design, and audit preparation for an AI management system.
- The documentation, oversight, and accountability artefacts used to support ISO/IEC 42001 certification.
- The internal audit and management review steps that validated readiness before external certification.
- The specific AI governance practices Unosecur says it aligned with emerging regulatory expectations.
👉 Read Unosecur's analysis of ISO/IEC 42001 certification and AI governance →
ISO 42001 for AI governance: what identity teams should take from it?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
ISO 42001 is becoming an identity governance problem, not just an AI governance problem. Once AI systems can influence operational decisions, the question shifts from model assurance to access assurance. Identity teams have to care because the same control failures that affect service accounts and NHI lifecycles now apply to AI systems that can act on behalf of the organisation. The practitioner conclusion is straightforward: AI governance must be wired into identity governance, not appended beside it.
A few things that frame the scale:
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to the 2026 Infrastructure Identity Survey.
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security.
A question worth separating out:
Q: Who is accountable when an AI system makes a harmful decision?
A: Accountability should follow the identity chain that authorized, configured, or triggered the action, including the human owner, the platform team, and any delegated agent or tool account. If the organisation cannot name that chain, the governance model is too weak for regulated AI use.
👉 Read our full editorial: ISO/IEC 42001 certification changes AI governance for identity teams