AI Governance EU AI Act AI Risk Management ISO 42001 GDPR & AI Data Governance Enterprise Risk Forensic Technology Regulatory Compliance Regulated Financial Services

My Personal Journey From Separate Frameworks to One Integrated Model™

Drawing on years of my personal experiences across ISO control environments, GDPR accountability roles, and investigative governance, this article explores how my AI risk management evolved from fragmented compliance efforts into a real-life working integrated framework aligned with the EU AI Act.

About This Article
Author background
DPO · ISO · Forensics
Topic
Integrated AI governance
Regulation
EU AI Act · GDPR · ISO 27001

Over the past decade, I have worked across ISO-aligned control environments, GDPR implementation programmes, forensic investigations, regulatory response exercises, and formal DPO accountability structures. For most of that time, these domains were treated as distinct disciplines. It was only through applying these frameworks repeatedly, separately at first, then in partial alignment, and eventually in combination, that a clearer pattern emerged.

AI governance does not sit cleanly within any one of them. It sits right at their intersection.

The frameworks I was working across

ISO frameworks
Information security and management systems, covering governance, audit and control environments
GDPR
Privacy, accountability obligations, and DPO responsibilities
Forensic investigations
Regulatory response, evidence, data lineage, and audit trail integrity
AI systems
Assessed through fragmented control lenses, none of them sufficient on their own

How I came to the realisation

When operating as a compliance lead and DPO, I observed that each framework solved part of the problem but none solved the whole.

GDPR DPIA
Necessary but insufficient for AI risk, because it did not capture model behaviour
ISO 27001
Provided structure but not ethical proportionality
Risk registers
Captured exposure but not model behaviour over time
Investigative readiness
Required traceability that went beyond privacy documentation
The key insight
The EU AI Act has effectively formalised what practitioners have been experiencing, which is that AI risk cannot be managed through siloed compliance instruments. It requires architectural integration.

How my model evolved

ISO as structural discipline
Defined governance ownership, documented control environments, auditability, and management system integration
GDPR as ethical calibration
Purpose limitation, data minimisation, transparency, and lawful basis, forcing proportionality and defensibility into design
Forensics as reality check
Model outputs as evidence, data lineage under legal challenge, and audit trails that cannot be theoretical

The EU AI Act as a convergence point

When reviewing the EU AI Act through this practitioner lens, it became evident that it does not introduce an entirely new philosophy. It codifies the convergence. The Act’s emphasis on risk classification, technical documentation, human oversight, post-market monitoring, and conformity assessment mirrors what integrated ISO, GDPR, and risk management structures already attempt to achieve, provided they are properly aligned.

The difference
The EU AI Act makes the integration explicit and enforceable. Organisations that have already aligned their frameworks start from a stronger position than those treating AI compliance as a separate workstream.

The integrated approach I now apply

Step 1
Risk classification
AI system purpose and context assessed against EU AI Act risk tiers
Step 2
ISO control mapping
Governance, security, and management system controls embedded formally
Step 3
GDPR rights and DPIA overlay
Data protection, fairness, and accountability stress-tested at design stage
Step 4
Investigative defensibility review
Traceability, model lineage, audit trails, and oversight validated against scrutiny
Step 5
Board-level reporting
AI risk reflected within enterprise risk and regulatory dashboards
Outcome
Operational integration
Not theoretical alignment, but something born from applying each framework and deliberately connecting them

Closing reflection

The future of AI governance in Europe will not be determined by who produces the most documentation. It will be determined by who builds integrated, defensible control architectures that align enterprise risk, data protection, security, investigations, and regulatory compliance.

The frameworks already exist. The challenge, and the real opportunity, lies in connecting them intentionally.

Ready to integrate your compliance frameworks?
The CORA™ Gap Assessment maps your AI systems, GDPR obligations, and ICT risk posture simultaneously, producing a single integrated remediation roadmap for a fixed fee of €999.
Book a Scoping Call Explore CORA™
TAKE ACTION

The August 2026 deadline is 4 months away.

Run your free assessment and download the playbook — both free, both ready now.

Run Free Assessment → Download Playbook
← Back to Morclear Brief