This article was originally published in Greek in Netweek magazine (July-August 2026). Author: Giorgos Papoulias.
The convergence of Artificial Intelligence with ITSM promises major leaps in efficiency, but brings new security and compliance risks to the forefront. The ISO/IEC 42001 standard emerges as the ultimate ally for safeguarding trust, offering a robust governance framework that fits perfectly with ITIL.
BY GIORGOS PAPOULIAS
The rapid adoption of Artificial Intelligence (AI) in IT Service Management (ITSM) is reshaping the way organisations design, deliver and manage their services. From automated incident resolution and predictive analytics to intelligent customer service centres, AI is significantly boosting efficiency, response speed and the overall quality of the services delivered. At the same time, however, harnessing these capabilities introduces new and complex risks, making it necessary to adopt a structured governance framework that safeguards trust, accountability and organisational resilience.
The international standard ISO/IEC 42001 for Artificial Intelligence Management Systems (AIMS) provides a comprehensive governance framework for AI across its entire lifecycle. Within IT Service Operations, the standard helps organisations systematically identify, assess and mitigate the risks associated with processes supported by AI systems. At the same time, it facilitates alignment with established best-practice frameworks such as ITIL and COBIT.
Risk Management and Organisational Resilience
A core principle of ISO/IEC 42001 is the risk-based approach. Within the context of ITSM, this principle translates into a systematic assessment of the risks associated with critical processes such as Incident Management, Change Management and Service Request Management. For this reason, organisations must implement mechanisms for the continuous control and monitoring of model performance, ensuring their reliability and ongoing oversight.
Equally important are the principles of transparency and accountability. AI systems used in IT operations must be explainable and auditable, particularly when their decisions affect service quality or the user experience. ISO/IEC 42001 places particular emphasis on clear documentation, defined roles and responsibilities, as well as mechanisms for human intervention where required. In this way, AI functions as a tool that supports decision-making without undermining the accountability of IT teams.
ISO 42001 & ITIL: A Powerful Synergy
The mapping presented in the accompanying infographic highlights the complementary role of the ISO/IEC 42001 and ITIL frameworks. Specifically, ISO 42001 defines the AI governance requirements — the “what” that must exist at the level of policies, controls and management mechanisms — while ITIL provides the operational framework for implementation, i.e. the “how” these requirements are embedded into day-to-day service operations. This synergy allows organisations to convert AI governance principles into measurable business value through the effective management of services, risks and continual improvement processes.
In conclusion, managing the risks associated with Artificial Intelligence in IT service operations requires a holistic approach that combines effective governance, systematic risk management and established best practices.
Artificial Intelligence should not be treated solely as an object of regulation and restriction, but as a strategic accelerator of organisational transformation — one that can deliver substantial value when it operates within a strong and effective governance framework.
