Enterprise AI governance has settled on two reference points. ISO/IEC 42001:2023 specifies requirements for an AI management system, in the same certifiable style as ISO/IEC 27001 for information security. The NIST AI Risk Management Framework, released in January 2023 and extended with a generative AI profile in 2024, organises the work into four functions: Govern, Map, Measure and Manage.
They are written for different audiences. ISO/IEC 42001 is built for certification and management review. The NIST framework is voluntary and descriptive. Procurement teams increasingly ask about both.
The shared dependency
Put the two side by side and a common requirement appears in almost every clause: you have to be able to show what the system did.
- Mapping a system's context requires knowing what data it actually touches, not what the architecture diagram says.
- Measuring performance and drift requires the inputs and outputs of real decisions over time.
- Managing incidents requires reconstructing a specific decision after the fact.
- Management review requires evidence that controls operated, not that they were designed.
Each of those depends on a decision log that is complete, tamper-evident and tied to the version of the model, prompt or rule that produced it. Without it, a governance programme becomes a set of policies describing a system nobody can inspect.
Build the log first
That is why Opsian treats the audit trail as infrastructure rather than a reporting feature. Identity, live state and bounded decisions are only useful if every decision can be replayed: who, what, when, and on what evidence. An organisation that has that record can adopt ISO/IEC 42001, answer a NIST-aligned questionnaire or respond to a regulator with the same material. One that does not will be writing it by hand for each.



