AI & GRC

MAJ 05.07.2026

AI Act: What the EU AI Regulation Means for GRC

AI Act and GRC governance

Prepare your AI systems for compliance

Iskera helps you map and govern your AI systems in line with AI Act requirements.

Thomas Delaunay

Auteur de l'article

Understand how the AI Act affects governance, risk and compliance, and the frameworks organizations need to put in place to govern the use of AI.

Artificial intelligence is becoming increasingly embedded in organizations' processes, tools and decision-making. With the AI Act, its use now falls within a European regulatory framework that introduces new requirements for governance, transparency and risk management.

For risk, compliance, internal control and audit functions, the challenge therefore goes far beyond regulatory compliance alone. AI systems need to be integrated into existing governance frameworks, and organizations must be able to demonstrate that they remain under control.

‍

What is the AI Act?

The AI Act, the European Union's regulation on artificial intelligence, establishes a common framework for the development, placing on the market and use of AI systems within the European Union.

Its central principle is a risk-based approach: the applicable obligations vary depending on the nature of the AI system, how it is used and the level of risk involved.

The regulation distinguishes, in particular, prohibited AI practices, high-risk systems, certain systems subject to transparency obligations, and general-purpose AI models.

The AI Act entered into force on 1 August 2024 and applies progressively. Prohibitions on certain AI practices and provisions relating to AI literacy have applied since February 2025. Governance rules and obligations for general-purpose AI models have applied since August 2025, while other provisions became applicable in August 2026. The timetable for high-risk systems extends into 2027 and 2028.

‍

Why is the AI Act a GRC issue?

The AI Act turns artificial intelligence into a genuine governance issue.

Organizations can no longer simply ask whether an AI tool works or improves productivity. They also need to know where AI is used, for what purpose, with which data, under whose responsibility and with what risks.

This directly reflects the fundamentals of GRC: identifying risks, defining responsibilities, implementing controls, documenting decisions, tracking incidents and providing evidence of compliance.

For high-risk AI systems, this convergence is particularly clear. The regulation includes requirements relating to continuous risk management and event logging, among other areas.

The AI Act therefore does more than introduce another regulation to monitor. It adds a new scope that must be integrated into the organization's governance framework.

‍

1. Map AI systems and use cases

The first challenge is often understanding exactly where artificial intelligence is being used.

Business applications with new AI features, SaaS solutions, generative AI assistants, internal automation and in-house models can be spread across many departments.

Compliance therefore starts with building an inventory of AI systems and use cases.

For each use case, the organization should be able to centralize information such as:

  • the system or model being used;
  • its purpose;
  • the processes concerned;
  • the data being used;
  • users and owners;
  • the relevant provider, where applicable;
  • its level of criticality;
  • associated risks and controls.

This inventory provides the foundation for determining which obligations apply.

‍

2. Assess and classify AI risks

Not all AI systems present the same level of risk.

The AI Act's approach therefore requires organizations to classify systems and assess the risks associated with their use.

This assessment should not be isolated from the broader risk management framework. An AI system may create or amplify risks related to data protection, cybersecurity, discrimination, data quality, reliability of outputs or business continuity.

AI therefore becomes an additional component of the organization's overall risk map.

For systems classified as high-risk, the AI Act requires an ongoing risk management process throughout their lifecycle.

‍

3. Define clear responsibilities

Who approves the use of an AI system? Who assesses its risks? Who monitors how it operates? Who steps in when an incident occurs?

AI governance requires a clear allocation of roles across business teams, compliance, risk, IT, security, legal, data protection and other relevant functions.

This governance can be supported by internal policies, approval workflows and formally assigned responsibilities.

The objective is to prevent AI use from expanding without a common framework or clearly identified ownership.

‍

4. Implement appropriate controls

Once risks have been identified, they need to be linked to appropriate control measures.

Depending on the systems concerned, organizations may implement controls covering areas such as:

  • data quality and provenance;
  • access rights;
  • human oversight;
  • reliability of outputs;
  • system security;
  • compliance with internal policies;
  • available documentation;
  • provider monitoring.

These controls should then be monitored, assessed and documented like any other part of the internal control framework.

‍

5. Strengthen traceability and documentation

The ability to demonstrate compliance is another central aspect of the AI Act.

For high-risk systems, the regulation includes requirements relating to documentation, event logging and, for providers, the establishment of a documented quality management system.

From a GRC perspective, organizations need to be able to quickly retrieve the information associated with an AI system: assessments, controls, approvals, documents, incidents, action plans and owners.

Compliance therefore depends not only on having rules in place, but also on the organization's ability to provide evidence that those rules are being applied.

‍

6. Integrate AI providers into third-party risk management

Many organizations do not develop their own AI models. Instead, they use solutions provided by software vendors or integrate external models into their processes.

AI Act compliance therefore directly intersects with third-party risk management.

Organizations need to identify relevant providers, assess the solutions being used, centralize available documentation and monitor related dependencies.

For general-purpose AI models, the AI Act includes documentation obligations designed to help downstream actors understand their capabilities and limitations and meet their own obligations.

‍

7. Manage incidents and action plans over time

AI governance does not end when a system is approved or deployed.

Risks evolve as models, data, use cases and providers change. Governance arrangements therefore need to be monitored over time.

Anomalies, incidents, failed controls or new requirements may lead to new action plans and a reassessment of risks.

This turns AI Act compliance into a continuous process rather than a one-off compliance exercise.

‍

Move beyond spreadsheets to structured AI governance

At first, an inventory of AI systems may be maintained in a spreadsheet. But this approach quickly reaches its limits as the number of use cases, owners, controls and documents grows.

The challenge is no longer simply to maintain a list of AI systems, but to connect:
AI systems → requirements → risks → controls → owners → incidents → documents → action plans.

This is precisely where the AI Act intersects with traditional GRC challenges.

A centralized platform makes it possible to structure these relationships, standardize approval processes and maintain a consolidated view of the governance framework.

‍

How can your organization prepare for the AI Act?

Compliance can be structured around a number of priority steps:

  1. Identify AI systems and use cases across the organization.
  2. Classify their role and level of risk to determine the applicable requirements.
  3. Assign owners and formalize governance workflows.
  4. Link risks to controls designed to manage them.
  5. Centralize documentation and evidence required for compliance.
  6. Monitor providers, incidents and action plans over time.
  7. Train relevant employees to ensure AI is used within an appropriate framework.

The objective is not to create an entirely separate framework dedicated to artificial intelligence, but to progressively integrate AI into the governance mechanisms already in place.

‍

AI Act and GRC: towards integrated AI governance

The AI Act makes artificial intelligence a cross-functional governance issue for organizations.

Risk, compliance, internal control, audit, data protection, cybersecurity and third-party risk management are all directly affected by the need to govern AI systems and demonstrate that they are under control.

For organizations that already have a structured GRC framework, many of the required mechanisms already exist: risk maps, controls, responsibilities, workflows, documentation, audits and action plans.

The next step is to extend this governance framework to the use of artificial intelligence.

Thomas Delaunay

Auteur de l'article

Thomas specializes in risk management and internal control. He helps organizations connect risk mapping, control plans and operational management within a consistent GRC framework.

Suivre l'auteur

Blog

Related GRC articles

Portrait of Bertrand Rubio, Iskera's new Deputy CEO and Chief Operating Officer
News

Bertrand Rubio joins Iskera as Deputy CEO and Chief Operating Officer (COO)

The European GRC technology group is strengthening its executive team to accelerate growth, product innovation and expansion across Europe. Iskera announces the appointment of Bertrand Rubio as Deputy CEO and Chief Operating Officer (COO).

Read article
Risk mapping and continuous risk management
Risk Management

Risk Mapping: From an Annual Exercise to Continuous Risk Management

Learn how to turn risk mapping from an annual exercise into a continuous management tool connected to controls, incidents, indicators and action plans.

Read article