ISO/IEC 42001 is the international standard for AI Management Systems (AIMS), published in 2023. The standard defines a framework within which organizations manage the design, development, and deployment of AI systems. Certification against ISO 42001 is voluntary, but it is increasingly cited as proof of readiness on the provider side of the EU AI Act.
The EU AI Act defines two distinct roles with different sets of obligations. Provider (Article 16) bears the obligations set out in Articles 9 to 15: risk management, data quality, technical documentation, record-keeping, transparency, human oversight by design, accuracy, and robustness. Deployer (Article 26) bears the operational obligations during actual use: use according to instructions, oversight, logging, incident reporting, DPIA, FRIA, and informing employees. ISO 42001 primarily covers the provider side, with components that become relevant for deployers.
SAP SE achieved ISO/IEC 42001 certification for SAP Business AI products in the first quarter of 2026. The SAP Responsible AI page (sap.com/products/artificial-intelligence/ai-ethics.html, Q1/2026) positions SAP accordingly as a provider within the meaning of Article 16.
On May 11, 2026, the first day of SAP Sapphire 2026 in Orlando, CEO Christian Klein reinforced this positioning: We plan to announce some fundamental changes to our portfolio to infuse this deep domain know-how into SAP's AI agents, and we will govern the agentic AI layer for our customers. Source: Constellation Research April 2026, Diginomica April 2026, IgniteSAP April 2026, SAVIC Technologies May 11, 2026.
The strategic consequence: SAP is positioning itself not only as a provider with ISO 42001 certification but also as a governance layer for SAP’s own agents within SAP systems. This has two implications for SAP customer organizations.
First implication: The provider side is covered by SAP for SAP products. Anyone using Joule, Joule Studio Agent Builder, SAP Business AI, or the Business Data Cloud expanded by the Reltio acquisition (completed May 7, 2026) can rely on the SAP provider certification as a building block for their own compliance argument.
Second implication: The deployer side remains with the customer. Klein’s statement does not change the non-transferability of Article 26 obligations. The SAP governance claim covers SAP agents in SAP systems. What your own agents, third-party agents, or community MCP servers do within the SAP landscape does not fall under SAP’s governance claim.
Level 1: Provider verification by SAP. Anyone using SAP AI products can document SAP SE’s ISO 42001 certification as part of their own supplier assessment. This is the connection point for NIS2 supply chain security obligations (Article 21 NIS2) and DORA third-party risk management obligations (Regulation (EU) 2022/2554, applicable since January 17, 2025). SAP has been classified as a Critical ICT Third-Party Service Provider (CTPP) since November 2025 and is subject to direct lead overseer supervision.
Level 2: Your own ISO 42001 implementation as a deployer. Operators who develop their own AI models, build their own Joule Studio agents, or integrate third-party AI components into SAP processes can maintain their own ISO 42001 implementation. The standard requires a documented lifecycle, defined roles, and continuous improvement. It is a management system standard in the style of ISO 9001 or ISO 27001, not a detailed technical standard.
Level 3: Operational interfaces with EU AI Act Articles 12 and 14. ISO 42001 requires risk management, record-keeping obligations, and human oversight. These elements partially overlap with Articles 9, 12, and 14 of the EU AI Act. An ISO 42001 implementation can therefore serve as an organizational framework for Article 26 compliance, but it does not replace the specific obligations.
Risk 1: Confusion between provider and operator roles. Klein's statement that we will govern the agentic AI layer for our customers is sometimes interpreted by stakeholders in practice as SAP assuming full compliance responsibility for customers. That is not the content of the statement. Under the AI Act, providers and operators are separate roles with separate obligations. Confusion leads to compliance gaps on the operator side.
Risk 2: Limited scope of the SAP governance commitment. The statement applies to SAP's AI agents, i.e., Joule and the agents built in Joule Studio. It does not apply to Microsoft Copilot, which is used productively in many DACH companies via the SAP-Microsoft partnership. It does not apply to Salesforce Agentforce or Workday agents. It does not apply to community MCP servers (more than 30 inventoried projects in the marianfoo registry as of April 2026) and not to ARC-1 as an enterprise-oriented community server (Marian Zeis, April 27, 2026).
Risk 3: ISO 42001 is a management system standard, not a compliance stamp. The standard requires processes, documentation, and improvement. It does not certify that a specific AI system is compliant with Articles 9 to 15 of the EU AI Act. A conformity assessment according to Article 43 is a separate process that typically requires a lead time of three to six months.
Risk 4: The LeanIX AI Agent Hub view is SAP-centric. In Q1/2026, SAP introduced the LeanIX AI Agent Hub as a central inventory dashboard for AI agents. Inventory, yes; cross-vendor governance, no. Anyone who views the hub as a complete answer to the inventory obligation leaves Microsoft, Salesforce, and community agents out of the picture. What is considered visible becomes reality for the observer; what remains invisible still has an effect within the system.
Risk 5: Solutive AG does not have ISO 42001 certification. This is an important negative disclosure. Solutive AG's statements regarding capability mappings to Articles 12, 14, and 15 are provider declarations, not certified compliance outcomes. The only externally attested statement regarding Solutive AG is the 70 percent reduction in SOX ITGC audit effort at Bruker.
First: Create a role matrix. Clarify the roles for every AI system in the SAP landscape: provider, operator, importer, distributor. Who is the provider in the specific use case (SAP for SAP Business AI, Microsoft for Copilot, the internal CISO for internally developed models), who is the operator, and who has operational oversight?
Second: Collect and verify provider certificates. Maintain ISO 42001 certificates from SAP and other providers as part of the supplier file. Monitor expiration dates. Explicitly check the scope of the certification. SAP has certification for SAP Business AI products. Anyone using a different product should verify the scope.
Third: Consider your own ISO 42001 implementation for complex operator landscapes. Organizations that deploy AI in multiple Annex III areas and must simultaneously comply with DORA, NIS2, and the EU AI Act benefit from implementing an ISO 42001 management system as an integrating framework. Implementation typically takes nine to twelve months to reach certification readiness.
Fourth: Manage cross-vendor agents separately. If you don't govern what SAP doesn't govern, someone else will—or no one will. Microsoft Copilot with productive access to SAP data, Salesforce agents with data flows into SAP customer records, community MCP servers with ABAP write access: define a specific governance element for each of these constellations, with a designated responsible party within your own organization.
Fifth: Classify Klein's statement as a vendor commitment, not a release from operator liability. Clear language is essential when communicating with auditors, financial examiners, and the BSI market surveillance authority. SAP assumes vendor obligations for SAP-native agents. The operator remains responsible for their deployment within their own context.
Sixth: Strategically categorize the Reltio acquisition. With the Reltio acquisition completed on May 7, 2026 (now Reltio, an SAP company), SAP covers the data side of AI provisioning. This provides the foundation for Annex IV data quality requirements, but it does not address the question of who is responsible for changes to productive systems triggered by AI agents.
Tools in the ISO 42001 and provider-deployer landscape are divided into three functional areas.
Vendor / ToolISO 42001 AIMSAnnex IV DocumentationAgent InventoryProvider-Deployer Role SeparationIBM watsonx.governancePartial (model lifecycle)Annex IV generatorModel levelVendor-orientedCredo AIPartial (model lifecycle)Annex IV generatorModel levelVendor-orientedValidaitorAudit focusAnnex IV moduleModel levelVendor-orientedArkForge MCPMCP compliance focusAnnex IV moduleMCP server levelHybridModelOpModel lifecycle governancePartialModel levelVendor-orientedGalileoModel observabilityNot in scopeModel levelVendor-orientedSAP Joule Studio Agent BuilderInternal (ISO 42001 SAP)Joule Studio audit trailJoule Studio agentsSAP as vendorSAP LeanIX AI Agent HubNot in scopeNot in scopeSAP-centricNot in scopeConsulting partners (TÜV, DEKRA, Bureau Veritas)Certification supportNot in scopeNot in scopeAdvisoryESM Suite (Solutive AG)¹Not in scopeNot in scopeNot in scopeOperational audit trail layer via ALM¹ Solutive AG is the initiator of the Change Orchestration Institute. Solutive AG itself does not hold ISO/IEC 42001 certification. Capability statements regarding the ESM Suite are provided by the vendor.
The table shows a clear division of tasks: AI model governance tools cover the vendor side (Annex IV, model lifecycle). Change governance tools cover the operator side during the change process (logging, escalation). Inventory tools like LeanIX Agent Hub offer visibility but not comprehensive cross-vendor governance.
SAP achieved ISO/IEC 42001 certification for SAP Business AI products in Q1 2026, positioning itself as a provider under Article 16 of the EU AI Act. Klein's Sapphire statement on May 11, 2026, reinforces this positioning with a governance commitment for SAP-native agents. Neither statement changes the operator obligations under Article 26: these remain with the SAP customer, are non-transferable by contract, and take effect on August 2, 2026, unaffected by the Digital Omnibus of May 7, 2026.
The operational consequence is a clear role matrix within your own organization, a cross-vendor agent inventory that goes beyond the SAP-centric view, and, if necessary, your own ISO 42001 implementation as an integrating management framework. Solutive AG does not hold ISO 42001 certification and is not active at the vendor model governance level; Solutive's capability statements are at the change governance level.
First key takeaway: SAP has been ISO 42001 certified since Q1 2026 and is a provider under Article 16 of the EU AI Act. Klein's Sapphire statement on May 11, 2026, reinforces this positioning with a governance commitment for SAP-native agents. This addresses the vendor side, not the operator side.
Concrete recommendation: Include SAP's ISO 42001 certificate in your supplier files, explicitly check the scope, and monitor expiration.
Second key takeaway: Operator obligations under Article 26 remain with the customer. Contractual transfer is not possible. August 2, 2026, is the hard deadline, unaffected by the Digital Omnibus of May 7, 2026.
Concrete recommendation for action: Build a roles matrix within your organization. Clearly assign the roles of provider, operator, importer, and distributor for each AI system. Manage cross-vendor agents separately.
Third key takeaway: ISO 42001 is a management system standard, not a compliance stamp. Implementing it is worthwhile if your organization is active in multiple Annex III areas and must simultaneously comply with DORA, NIS2, and the EU AI Act.
Concrete recommendation for action: Plan for an implementation effort of nine to twelve months. Contact certification partners (TÜV, DEKRA, Bureau Veritas) at an early stage.
ISO/IEC 42001:2023, Information Technology, Artificial Intelligence, Management System (T1). SAP Responsible AI page, sap.com/products/artificial-intelligence/ai-ethics.html, Q1 2026 (T1). Regulation (EU) 2024/1689, EUR-Lex, Articles 16, 26, 27, 43 (T1). Constellation Research, SAP Sapphire 2026 themes with Klein source, April 2026 (T2). Diginomica, Klein interview Learning Curve AI, April 2026 (T2). IgniteSAP, SAP Financial Results Q1 2026, April 2026 (T2). SAVIC Technologies, Sapphire 2026 Post-Keynote, May 11, 2026 (T2). SAP News Center, SAP Business AI Release Highlights Q1 2026, April 21, 2026 (T1). SAP News Center, SAP Completes Acquisition of Reltio, May 7, 2026 (T1). Reltio Blog, Reltio, an SAP company, May 7, 2026 (Provider). Bird and Bird, Digital Omnibus Provisional Agreement, May 7, 2026 (T2). Modulos AI, EU AI Act Delayed, May 7, 2026 (T2). Credo AI, Forrester Wave Q3 2025 Leader (T2). IBM watsonx.governance product documentation (Provider). ArkForge, MCP EU AI Act tools (Provider). innobu.com, SAP Joule 2026, April 2026 (T2). uniorg.de, SAP and the EU AI Act, March 2026 (T2). Plesner Law Firm, Article 6 deadline missed, April 6, 2026 (T2). isms.online, Are You Legally Ready for Article 26, 2025/2026 (T2). Regulation (EU) 2022/2554 (DORA), EUR-Lex (T1). ESA, SAP CTPP-Designation, November 2025 (T1). DSAG Investment Report 2026, dsag.de, February 2026 (T1). digital-chiefs.de, Chief AI Officer 2026, April 2026 (T2). Solutive AG, ESM Suite v6.4.5 Documentation, March 2026 (Provider source).
EU AI Act Article 26: What operator obligations mean from August 2026 despite the Digital Omnibus, Digital Omnibus on AI of May 7, 2026: What the postponement shifts, The Frankenstein Architecture: Cross-Vendor Agents, Triple Compliance 2026: NIS2, DORA, and the EU AI Act, SAP Business AI Q1 2026: Joule Studio in general availability.
Christian Steiger is co-founder and Managing Director of Solutive AG and has been working for over 15 years with SAP Application Lifecycle Management, change orchestration, and transport governance in complex landscapes. His focus is on bridging SAP Basis practice with modern governance architectures and integrating regulatory requirements into operational SAP processes.
Thomas A. Anderson (pseudonym) is a co-author focusing on technical systems, architectural decisions, and framework design. He supports the Change Orchestration Institute on topics related to AI toolchains, provider-deployer separation, and cross-vendor governance.
The Change Orchestration Institute is an independent knowledge resource for SAP ALM, change orchestration, and AI governance. Initiator and research partner: Solutive AG, solutive.ag/kontakt.