AI Governance

AI governance is where most risk functions are currently improvising. The frameworks arrived faster than the practice, so teams end up holding a copy of the NIST AI Risk Management Framework and the EU AI Act text without a clear view of which one binds them or what either demands on a Monday morning.

What is collected here is the operational layer: how the EU AI Act risk classification actually sorts your systems, how the NIST AI RMF maps onto controls you already run, what belongs in an AI risk register, and how to write a generative AI acceptable use policy that employees will follow rather than route around. Agentic and autonomous systems get their own treatment, because delegating actions to a model raises questions that model validation checklists were never built to answer.

If you are assessing AI you bought rather than built, pair this with third-party risk and governance, risk and compliance. For the wider program context, see enterprise risk management.

Receive the latest articles in your inbox