Cybersecurity Today TV - Ep 68 - ISO 42001 and Cyber Trust: Setting the Standard for AI Governance

Cybersecurity Today TV - Ep 68 - ISO 42001 and Cyber Trust: Setting the Standard for AI Governance

🎙 CybersecurityToday 👥 492 📅 November 23, 2025 ⏱ 29 min 👁 112 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

ISO 42001AI governancecybersecurityrisk managementcompliance

Summary

In this episode of Cybersecurity Today, host Jim Wiggins interviews Dallas Bishoff, President of PROCESS 360, about ISO 42001 and its role in AI governance. The discussion begins with an overview of recent cybersecurity incidents, including a costly breach at Jaguar Land Rover and a FEMA/CBP breach, highlighting the importance of robust security measures. Bishoff then explains the rationale behind ISO 42001, published in December 2023, as a management system standard for AI, emphasizing the need for organizations to integrate AI governance into existing structures rather than creating new ones. He contrasts traditional IT governance with AI governance, noting that AI introduces novel risks such as hallucinations and maintainability issues. The conversation covers the integration of ISO 42001 with other management systems like ISO 27001, the alignment with the EU AI Act, and the value of certification for legal due diligence. Bishoff also compares ISO 42001 with the NIST AI RMF, highlighting differences in control coverage. The episode concludes with contact information for Bishoff and a wrap-up of the show’s key points.

172 words

Critical Evaluation

Value of the Information & Strength of the Argument

The episode provides valuable insights into ISO 42001 and AI governance, particularly from an expert with practical experience. Bishoff effectively argues that AI governance should be integrated into existing management systems rather than developed separately, using examples from his work with clients. He also highlights the legal and regulatory drivers for certification, such as the EU AI Act and due diligence defenses. The argumentation is coherent and grounded in professional experience, though it lacks detailed evidence or references to specific studies or cases beyond a few examples.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate: the discussion is based on the guest’s expertise and professional experience, but specific sources are not cited within the episode. The title accurately reflects the content, focusing on ISO 42001 and AI governance. The episode does not provide detailed references to standards documents or regulatory texts, which limits its depth for viewers seeking verifiable information. The title is appropriate and does not overstate the content.

172 words

Title / Content Match

The title accurately reflects the main topic of the episode, which focuses on ISO 42001 and its role in AI governance and cyber trust.

Quality & Reliability

7/10

The episode features an expert in AI governance and cybersecurity, providing informed perspectives on ISO 42001. However, the discussion is largely conversational and lacks detailed citations or references to specific sources, limiting its depth and verifiability.

Key Moments

Markers derived by PSI from the transcript: the creator did not define chapters.

Cited Sources

  • ISO 42001 — Mentioned as the standard for AI management systems.
  • ISO 27001 — Referenced as an existing information security management standard.
  • ISO 9001 — Mentioned as the quality management standard.
  • EU AI Act — Discussed in relation to ISO 42001 alignment.
  • NIST AI RMF — Compared with ISO 42001 in terms of controls.

Concurring Sources

  • ISO 42001 — The standard is the main topic and is presented as a key framework for AI governance.
  • EU AI Act — The discussion aligns with the EU AI Act's risk-based approach.

Contribution & Novelties

The episode provides a practical perspective on ISO 42001, emphasizing integration with existing management systems and the legal drivers for certification. It offers insights from an auditor’s viewpoint, highlighting common pitfalls and the importance of aligning AI governance with broader organizational governance.

Pour aller plus loin :

  • ISO 42001:2023 — Official standard page.
  • EU AI Act — Overview of the EU regulation.
  • NIST AI RMF — Framework for AI risk management.
  • Cloud Security Alliance AI Control Matrix — Cross-mapped controls for AI.

82 words

Radar Profile

The radar profile shows balanced scores across information quantity, quality, technical level, and reliability, indicating a well-rounded but not exceptionally deep or technical discussion. The episode is informative for a general audience but may lack the depth required for specialists.

Reliability 7/10

💬 No comments were provided for analysis.