DNA Advisory · AI Governance Benchmark

Technology Sector
AI Governance Readiness

Technology companies build AI for everyone else — but who governs the governor? This benchmark — measured against ISO 42001 — reveals where the technology sector stands and why the highest AI expertise doesn't automatically translate into the strongest AI governance.

Read the Analysis ↓
0
Industry Average
0%
Small (<200)
0%
Medium
0%
Large (1000+)
00 — URGENCY
The Clock Is Ticking
Technology companies face the heaviest regulatory burden of any sector under the EU AI Act — because provider obligations are significantly stricter than deployer obligations. Every day without a structured governance framework increases exposure to penalties, lost enterprise deals, and reputational risk.
Days Until EU AI Act
Provider obligations · Aug 2, 2026
LIVE
Colorado AI Act
Effective Feb 1, 2026
KSA PDPL
Full enforcement · Sep 2025
READY
EU GPAI Code
Code of Practice · May 2, 2025
01 — EXECUTIVE SUMMARY
The Technology AI Governance Paradox

Technology organisations are, on average, 53% ready for ISO 42001 certification — the highest of any sector. Large technology companies reach 65%, reflecting deep AI expertise, mature engineering infrastructure, and growing awareness of governance requirements. Yet the sector's core paradox remains unresolved: building AI is not the same as governing AI.

Technology companies have MLOps pipelines, model monitoring systems, responsible AI research teams, and published AI principles. What they lack is a structured, auditable management system — the documented policies, formal risk assessments, defined roles, systematic evidence collection, and continual improvement cycles that ISO 42001 demands. Silicon Valley's engineering culture solves problems with code. ISO 42001 requires solving problems with processes.

The regulatory window is closing and it hits technology companies first. The EU AI Act places the heaviest compliance burden on AI system providers — the companies that build and sell AI. Provider obligations (Articles 16–22) require quality management systems, technical documentation, conformity assessments, and post-market monitoring. ISO 42001 certification directly satisfies Article 17's quality management system requirement.

€35M
Max EU AI Act Penalty
Or 7% of global turnover
80%
Lack Mature AI Governance
Deloitte State of AI, 2026
Art. 16-22
Provider Obligations
Heaviest in the EU AI Act
65%
Large Tech Readiness
Highest of any sector
Benchmark scores are directional estimates derived from regulatory analysis, ISO adoption research, and industry governance maturity patterns. They reflect expected readiness levels based on published data and are updated periodically as the market matures.
02 — AI GOVERNANCE LANDSCAPE
Approaches to AI Governance
AI governance is not a single framework — it's a discipline with multiple approaches, each with distinct strengths and limitations. Understanding the full landscape is essential before choosing a path, and helps explain why ISO 42001 has emerged as the leading certifiable option for organizations serious about structured AI governance.
ApproachWhat It IsStrengthsLimitations
Internal AI PoliciesSelf-defined governance frameworks developed in-houseFlexible, quick to implement, tailored to organizationNo external validation, inconsistent across teams, not recognized by regulators or clients as proof of governance
EU AI Act ComplianceMeeting requirements of Regulation 2024/1689Mandatory in EU, clear penalties create urgency, detailed requirements for high-risk AIJurisdiction-specific, not certifiable, reactive (compliance ≠ governance), doesn't cover full management lifecycle
NIST AI RMF 1.0Voluntary US framework: GOVERN, MAP, MEASURE, MANAGE functions
Source: NIST AI 100-1, January 2023
Well-structured, free, aligns with ISO 42001 concepts. Colorado AI Act affirmative defence.Voluntary only — no certification, no audit mechanism, US-centric, no enforcement
IEEE Ethically Aligned DesignEthics-focused standards for autonomous systems
Source: IEEE P7000 series
Strong on fairness, transparency, and human rightsNarrow scope (ethics, not full governance), not widely adopted, not a management system
Responsible AI PrinciplesPublished company AI principles (Google, Microsoft, Anthropic, etc.)Signal commitment, guide internal culture, basis for specific policiesNot auditable, not enforceable, inconsistent across companies, principles ≠ governance
ISO/IEC 42001:2023International standard for AI Management Systems (AIMS)
Source: ISO/IEC 42001:2023, published December 2023
Certifiable by accredited bodies worldwide. Covers full lifecycle (Clauses 4–10 + 39 Annex A controls). Directly satisfies EU AI Act Art. 17 QMS requirement. Continuous improvement built in.Relatively new (27 months old). Certification body capacity still scaling. Requires genuine organizational commitment.
03 — WHY ISO 42001
The Case for ISO 42001
ISO 42001 is not the only approach to AI governance — but for technology companies seeking to convert informal practices into auditable, sustainable processes while simultaneously meeting EU AI Act provider obligations, it is the strongest available option.
The Only Certifiable AI Framework
Published AI principles are not auditable. NIST AI RMF is not certifiable. EU AI Act compliance is not a certificate. ISO 42001 is the only framework where an accredited auditor verifies your implementation and issues an internationally recognized certificate. For enterprise customers evaluating vendor AI governance, a certificate is proof.
Source: ISO/IEC 42001:2023, Clause 1 — Scope. Certification per ISO/IEC 17021-1.
EU AI Act Art. 17 — Direct Alignment
Article 17 requires providers of high-risk AI to establish a quality management system. ISO 42001 is explicitly designed as an AI management system. Certification provides documented evidence of compliance. ISO 42001 is submitted for harmonization under the EU AI Act framework — making it the natural compliance pathway.
Source: EU AI Act Recital 40 references harmonized standards.
A Sales Enabler, Not Just Compliance
Enterprise customers face their own AI governance obligations. They will increasingly require vendors to demonstrate AI governance certification. ISO 42001 becomes a competitive differentiator in enterprise sales — answering the procurement question "how do you govern your AI?" with audited evidence rather than marketing claims.
Source: Enterprise procurement trends in regulated industries (financial services, healthcare, government).
Automate Governance Into Engineering
ISO 42001 doesn't require stopping innovation. The most effective implementations automate governance into the engineering pipeline — automated bias testing in CI/CD, model cards generated from training metadata, drift monitoring as a deployment prerequisite. This is governance that engineering culture embraces because it's built, not imposed.
Source: ISO Annex SL harmonized structure; ISO/IEC 42001:2023 Annex D.
39 Controls Across the Full AI Lifecycle
Annex A provides 39 specific controls covering data governance (A.4), transparency (A.5), accountability (A.6), bias and fairness (A.7), reliability (A.8), security (A.9), privacy (A.10), human oversight (A.11), documentation (A.12), and third-party AI management (A.13).
Source: ISO/IEC 42001:2023, Annex A — Reference control objectives and controls.
What ISO 42001 Does Not Cover
Jurisdiction-specific compliance. ISO 42001 is a governance framework, not a legal compliance tool. Technology companies must still address EU AI Act conformity assessments, Colorado AI Act disclosure requirements, and CCPA/CPRA AI provisions separately — though ISO 42001 provides the foundation.
Technical AI safety. The standard covers governance and management of AI risks, but does not prescribe specific technical solutions for model testing, adversarial robustness, or algorithmic fairness. Organizations must select appropriate technical approaches within the governance framework.
Our position: For technology companies that build and sell AI, ISO 42001 certification is both a governance accelerator and a commercial differentiator. It converts informal practices into auditable processes while answering the market question: "Who governs the governor?"
The Benchmark
The technology sector averages 53% readiness.
The certification threshold is 75%.
Here's the clause-by-clause breakdown of where that gap lives.
04 — CLAUSE ANALYSIS
Clause-by-Clause Benchmark
How technology companies score across each of the 7 mandatory ISO 42001 management system clauses — from context and leadership through planning, support, and operations to performance evaluation and improvement. Scores reflect the degree to which current industry practices align with each clause's specific requirements. Click any clause to see the detailed analysis, key gaps, and recommendations.
Estimated readiness based on regulatory analysis, ISO Survey certification adoption data (2019–2024), published AI governance maturity research, and industry-specific compliance infrastructure patterns across technology companies.
Building AI is not the same as governing AI. MLOps automates engineering — ISO 42001 governs the system.
05 — ANNEX A CONTROLS
Control Maturity by Domain
ISO 42001 Annex A defines 39 controls across 12 groups, which we organize into 5 operational domains for clarity. Each domain is scored on a 1–5 maturity scale based on typical implementation patterns observed across technology companies. Lifecycle & Reliability leads at 3.0/5.0 — reflecting mature MLOps infrastructure — while Oversight & Documentation at 2.4/5.0 reveals the gap between engineering docs and management system documentation.
Maturity scores estimated from regulatory compliance patterns, published AI governance research, and industry-specific control implementation analysis across technology companies.
The EU AI Act hits technology companies hardest — provider obligations are the strictest in the regulation.
06 — CRITICAL GAPS
Top 5 Gaps in Technology
The most significant AI governance gaps we consistently identify across technology companies — ranked by severity, with ISO 42001 clause references and estimated remediation timelines for each.
ISO 42001 doesn't slow innovation down — it captures what already happens and makes it auditable.
07 — REGULATORY LANDSCAPE
Technology AI Regulations
A comprehensive reference of every regulation affecting AI governance in the technology sector — current status, enforcement dates, penalty structures, and the specific impact on technology operations. Technology faces more AI-specific regulation than any other sector due to provider obligations.
RegulationJurisdictionStatusPenaltiesImpact on TechnologyISO 42001 Alignment
EU AI ActEU/EEAHigh-risk: Aug 2026€35M / 7%Provider obligations (Art. 16-22): QMS, technical docs, conformity assessment, CE marking, post-market monitoring. GPAI obligations (Art. 51-56).Cl.5-10 · A.3-A.13
Colorado AI ActColorado, USAEffective Feb 2026AG enforcementDevelopers must use "reasonable care" against algorithmic discrimination. Disclosure, documentation, public statements required.A.5 · A.7 · A.12
GPAI Code of PracticeEUMay 2025Part of AI ActGPAI model providers: transparency, documentation, copyright. Systemic risk models face additional requirements.Cl.8 · A.5 · A.12
NIST AI RMF 1.0USAVoluntaryNo direct penaltiesGOVERN, MAP, MEASURE, MANAGE. Creates rebuttable presumption under Colorado AI Act. EO 14110 rescinded Jan 20, 2025.Cl.6 · Cl.9 · A.3 · A.8
CCPA/CPRACalifornia, USAIn force$7,500/violationAI processing of personal data. Automated decision-making rights. Opt-out of profiling.A.4 · A.10 · A.5
SEC AI DisclosureUSAGuidance emergingSecurities enforcementMaterial AI risks must be disclosed. Governance posture relevant to investors.Cl.4 · Cl.6
UK AI Safety InstituteUKOperationalVoluntaryPre-deployment safety evaluations for frontier AI. Voluntary but influential.Cl.8 · A.8
KSA PDPLSaudi ArabiaFull: Sep 2025SAR 5MApplies to tech companies processing Saudi data in AI systems.A.4 · A.9 · A.10
DORAEU/EEALive since Jan 2025€10M / 5%ICT third-party risk. Tech companies as critical ICT providers face direct oversight.Cl.8 · A.9 · A.13
The regulatory multiplier: Technology companies face regulation in every jurisdiction their customers operate in. A single ISO 42001 certification provides the governance foundation that satisfies the EU AI Act (provider QMS), Colorado AI Act (reasonable care framework), NIST AI RMF (governance alignment), and enterprise customer requirements simultaneously.
08 — METHODOLOGY
How This Benchmark Was Built
Scores were derived by mapping each ISO 42001 clause requirement against known industry practices, regulatory compliance maturity data, and published AI governance maturity research. Each score reflects alignment adjusted for technology-specific factors: MLOps maturity, responsible AI practices, engineering culture, and provider-side regulatory exposure.
Data Sources
  • EU AI Act (Regulation 2024/1689) — Articles 16–22, 51–56
  • Colorado AI Act (SB24-205, signed May 17, 2024)
  • Deloitte State of AI in the Enterprise 2026 (3,235 leaders)
  • NIST AI RMF 1.0 (January 2023) — EO 14110 rescinded Jan 20, 2025
  • OECD AI Policy Observatory (80+ jurisdictions)
  • ISO Survey of Management System Certifications (2019–2024)
Important Caveats
  • Technology is heterogeneous — a 5,000-person SaaS company and a 20-person AI startup differ fundamentally
  • MLOps maturity is a genuine advantage — engineering infrastructure for governance exists
  • Provider obligations are the differentiator — no other sector faces the same regulatory burden
  • Open-source AI governance is the industry's unique structural challenge
  • Certification typically requires 70–75% readiness to engage and 80–85% to certify
09 — ABOUT THE AUTHOR
Mike Merdinian
Founder · Digital North Associates

Mike Merdinian works at the intersection of governance and AI, helping organizations scale decision-making at machine speed without losing control.

He is a transformation leader specializing in governance, large-scale change, and AI-driven operating models, with over 20 years of experience across North America, Europe, and the GCC. He has led complex transformation and M&A initiatives across banking, supply chain, retail, and the public sector — working both as a strategic advisor and as an internal transformation leader.

He has advised members of parliament from more than 20 Commonwealth countries on technology and governance strategy, and teaches emerging technologies at leading international universities. He holds an AI Strategy and Leadership certification from MIT and is currently pursuing Applied Agentic AI for Organizational Transformation (MIT, expected May 2026).

He is the founder of Digital North Associates, an AI governance and transformation firm focused on enabling organizations to operate at machine speed while maintaining control through policy-driven governance.

Under his leadership, DNA is on track to become a fully AI-augmented organization by May 2026, with intelligent systems embedded across sales, marketing, advisory, operations, delivery, and finance.

Mike Merdinian
Founder · March 2026
Digital North Associates
AI Governance & Digital Transformation · Strategic Advisory & Purpose-Built Technology
© 2026 Digital North Associates. All rights reserved. Distribution requires written permission.
Where does your organization stand? Take the free ISO 42001 assessment — 15 minutes, no commitment.
Take Free Assessment