Artificial Intelligence (AI) is re-shaping how enterprises operate, but its greatest impact is not on technology. It is on governance. As intelligent systems increasingly influence business decisions, the assumptions that have guided Governance, Risk and Compliance functions for decades are beginning to break down. Oversight designed for predictable, rule-based systems is being applied to models that continuously learn, adapt and evolve.
Yet governance has not kept pace with AI adoption. According to McKinsey, only 30 percent of organizations have achieved a mature level of strategy, governance and internal controls for their AI initiatives.1 As enterprises move beyond AI experimentation to large-scale deployment, this governance gap is becoming a strategic business risk rather than simply a compliance concern.

Closing that gap requires a fundamental re-thinking of how governance is designed, embedded and sustained across the enterprise. ISO/IEC 42001 provides the foundation for that shift by enabling organizations to govern AI consistently across the enterprise.
This evolution presents both operational challenges and an opportunity to re-assess how UM programs are structured, governed and executed.
This article provides an executive-level review of the CMS mandates shaping UM in 2026 and outlines key considerations health plans should evaluate as they prepare for the next phase of regulatory oversight. It is intended to offer clarity on what is changing, why it matters and how UM programs can evolve to remain compliant, clinically credible and operationally sustainable in an increasingly complex healthcare environment.
The Governance Shift Organizations Can No Longer Avoid
Traditionally, GRC frameworks operated in stable, rule-based environments, where controls were deterministic, risks were well understood and assurance was typically point-in-time. This model proved effective because business systems behaved predictably, allowing organizations to validate controls periodically and maintain confidence in their operating environment.
AI fundamentally changes these assumptions. As models continuously learn from new data and generate probabilistic outcomes, governance can no longer focus solely on whether a control worked at a specific point in time. Instead, it must determine whether AI systems continue to operate reliably, remain compliant and produce outcomes that organizations can trust.
This shift changes a fundamental governance question:
Organizations that continue applying legacy GRC practices to adaptive AI systems inevitably create governance blind spots. Existing frameworks were not designed to provide continuous oversight of evolving models, resulting in gaps across risk management, accountability and assurance.
Common governance gaps in AI adoption include:
AI solutions deployed without formal, specialized risk assessments, increasing undiscovered model risk and the likelihood of unintended outcomes
Lack of a centralized inventory of AI models,
limiting visibility into where AI is deployed, how it is used and who owns it
Absence of AI-specific Key Risk Indicators (KRI), with no mechanisms to monitor model performance, drift and emerging AI risks
Fragmented accountability, with an unclear division of responsibility for AI-related risks and decisions between business units and technology teams
Internal audit methodologies without embedded AI assurance, leaving existing audit approaches unequipped to assess model behavior, data quality and lifecycle risks
Left unaddressed, these gaps expose organizations to heightened regulatory scrutiny, reputational damage and operational risk that extend far beyond the IT function.
ISO/IEC 42001: The Foundation for Enterprise AI Governance
The governance gaps created by AI cannot be addressed through incremental enhancements to legacy GRC framework. Organizations need a framework that addresses the unique characteristics of intelligent systems while building on the governance foundations they already trust. This is where ISO/IEC 42001 represents a significant evolution in enterprise GRC.
Rather than asking enterprises to re-invent governance, ISO/IEC 42001 extends established GRC principles to address the dynamic nature of AI. At its core is an AI Management System (AIMS) that embeds governance across the entire AI lifecycle – from strategy and development to deployment, continuous monitoring and ongoing improvement. In doing so, it transforms AI governance from a technology-led initiative into an enterprise capability with clear accountability, oversight and measurable controls.

From a GRC perspective, the standard complements established frameworks such as COSO Enterprise Risk Management (ERM), ISO 31000, ISO 27001 and the Three Lines Model to address AI-specific risks. Rather than operating as a standalone compliance framework, it enables organizations to embed AI governance into existing risk management, compliance, internal audit, data governance, cybersecurity and business operations, creating a coordinated and consistent approach to managing AI across the enterprise.
How ISO/IEC 42001 Extends Traditional GRC
Executive Perspective: Business Value Across the C-suite
Chief Risk Officers (CRO): Greater visibility into AI risks, enabling more informed risk decisions and stronger enterprise resilience
Chief Compliance Officers (CCO): Improved regulatory readiness through standardized governance, continuous oversight and auditable controls
Heads of Internal Audit: Greater confidence in the integrity of AI models through independent assurance and lifecycle-based governance
Chief Financial Officers (CFO): Increased trust in AI-enabled financial processes through stronger transparency, data integrity and clear accountability
Operationalizing AI Governance: The 5-Phase Maturity Roadmap
Moving from fragmented, ad hoc oversight to enterprise-wide AI governance requires a structured approach that is repeatable and scalable. AI governance cannot operate in isolation; it must be engineered as a natural extension of the enterprise’s existing GRC capabilities. A mature implementation aligns AI governance with:
Governance
AI Steering Committees
Executive accountability
Board reporting
Policy management
Risk Management
AI risk taxonomy
ERM
Scenario analysis
AI-specific KRIs
Risk appetite integration
Compliance
Regulatory obligation management
Control mapping
Evidence management
Continuous compliance monitoring
Internal Audit
AI assurance methodology
Model governance reviews
Control effectiveness testing
Independent assurance over AI lifecycle controls
Third-Party Risk
Vendor AI due diligence
Contractual governance requirements
Continuous supplier monitoring
AI procurement standards
That alignment depends on rigorous execution, embedding AI-specific controls into existing Risk and Control Matrices (RCM), defining clear data and algorithmic policies and establishing continuous monitoring across automated business processes. When these elements are integrated, the first (operations), second (risk and compliance) and third (audit) lines of defense gain complete visibility into model risk exposure and can operate within standardized, audit-ready frameworks that stand up to regulatory scrutiny.
To guide this transition systematically, organizations can follow a 5-phase AI governance maturity roadmap. This phased approach helps enterprises build the foundation, strengthen governance capabilities and achieve complete alignment with ISO/IEC 42001.
Technology Is an Enabler. Governance Is the Differentiator
While process engineering and strategic methodology dictate the governance framework, technology platforms serve as the critical operational backbone for scaling it. Technology platforms alone cannot establish effective governance, but leading integrated GRC platforms are rapidly evolving to incorporate specialized AI governance capabilities.
When properly implemented and integrated into the broader corporate architecture, these systems allow enterprises to:
Maintain dynamic, automated inventories of all enterprise AI applications and models
Monitor AI control effectiveness and track shifting global regulatory obligations in real-time
Automate complex AI risk assessments across highly distributed business units
Manage policy exceptions, enable continuous assurance and support seamless, data-driven reporting to executive leadership
Ultimately, technology delivers its greatest value not by replacing governance, but by operationalizing it at enterprise scale. Organizations that integrate AI governance into their existing GRC operating models are better positioned to maintain consistency, transparency and regulatory readiness as AI adoption continues to accelerate.
Governance Maturity in the AI Economy
ISO/IEC 42001 should not be viewed as another compliance initiative led by technology or risk functions in isolation. Instead, it provides an architectural framework for building governance capabilities that evolve alongside AI adoption. As organizations move from experimentation to enterprise-wide deployment, the ability to establish consistent oversight, accountability and trust will become just as important as scaling AI itself.
Ultimately, competitive advantage in the AI economy will not be defined by who deploys the most advanced AI models, but by who governs them most effectively. In that context, ISO/IEC 42001 is more than an AI management standard – it provides the foundation for the next evolution of enterprise Governance, Risk and Compliance.
Talk to our experts to assess your AI governance maturity, integrate AI oversight into your enterprise GRC operating model and build resilient controls at scale.
About the Authors
Nikunj Sharma
Corporate Vice President,
Finance and Accounting Practice

Nikunj is a Corporate Vice President and Global Record-to-Analyze (R2A) Capability Leader at WNS. A chartered accountant with over 25 years of experience, he specializes in steering finance transformations, scaling intelligent operations and embedding AI-driven solutions to deliver robust strategic outcomes for global CFOs.
Kamalpreet Kaur
Director – GRC Capability,
Finance and Accounting Practice

Kamalpreet Kaur, CA, CIA, CFE, is a GRC leader and catalyst with 20+ years of experience driving risk, compliance, controls transformation and AI governance. She specializes in ERM, SOX and GRC transformation, helping organizations build resilience and sustainable growth.
References
-
https://www.mckinsey.com/capabilities/tech-and-ai/our-insights/tech-forward/state-of-ai-trust-in-2026-shifting-to-the-agentic-era