How AI governance works
What should an AI governance framework include?
Short answerAn AI governance framework should include nine working parts: an inventory of every AI system in use, a named owner for each, risk tiers, a written policy, controls that run on their own, monitoring, a path for handling incidents, records that prove what happened, and a scheduled review. NIST AI RMF 1.0, ISO/IEC 42001:2023, and the EU AI Act all ask for these same parts under different names. A company of 50 to 500 people can stand up a first working version in about 90 days by starting with the inventory and the owners.
A working AI governance framework has parts that keep running after the launch meeting, and each part produces evidence someone can check. The three references people search for, the NIST AI Risk Management Framework, ISO/IEC 42001, and the EU AI Act, describe those parts in their own vocabulary. This page maps each part to all three.
What are the parts of an AI governance framework?
- Inventory. Every AI system the company builds, buys, or lets staff use, including AI features inside existing software.
- Ownership. One accountable executive for AI risk overall, and a named owner for each system with the authority to pause it.
- Risk tiers. A short scale that decides how much control each system gets. Customer-facing decisions and personal data sit at the top.
- Policy. The written rules staff follow: approved tools, data that stays out, and who approves a new use. An acceptable use policy is the usual first document.
- Controls that run. Settings and software that apply the policy on every request, such as single sign-on to approved tools, blocked uploads, and redaction of identifiers before a prompt leaves the company.
- Monitoring. Someone watches what the systems actually do in production, on a schedule, with a threshold that triggers action.
- Incident handling. A written path for a leak, a wrong answer that reached a customer, or an agent that acted outside its limits: who is told, who can switch it off, and who informs the vendor.
- Records. Logs and documents that show what was asked, what the system did, and who approved it, kept long enough to answer an auditor or a regulator. Use AI governance auditing when the company needs a formal gap assessment and evidence review.
- Review. A dated, recurring look at the whole framework, with findings that change the inventory, the tiers, or the controls.
What is the NIST AI Risk Management Framework?
NIST AI RMF 1.0, published in January 2023, is voluntary and written for organizations of any size and sector. It sorts the work into four functions. Govern sets policy, roles, and accountability across the other three. Map sets the context and impacts of each system. Measure tests and tracks risk. Manage responds to risk, including monitoring, incident response, and recovery after deployment. NIST added the Generative AI Profile (NIST AI 600-1) in July 2024. It names twelve risks unique to or worsened by generative AI, from confabulation to data privacy and information security, and lists suggested actions against the same functions, starting with adding generative AI systems to the organizational inventory.
What is ISO 42001, and can a company be certified?
ISO/IEC 42001:2023, published in December 2023, is the international standard for an AI management system. ISO describes it as requirements for establishing, implementing, maintaining, and continually improving that system, for organizations that develop, provide, or use AI. Its clauses run through context, leadership, planning, support, operation, performance evaluation, and improvement, with AI-specific requirements such as an AI policy, an AI risk assessment, and an AI system impact assessment. Certification is voluntary and comes from independent certification bodies, which national accreditation bodies accredit.
What does the EU AI Act require, and when does it apply?
The EU AI Act (Regulation (EU) 2024/1689) applies to providers that place AI on the EU market and to deployers in the EU. It also reaches a company outside the EU when the output of its AI system is used in the EU. Its duties scale with risk, from banned practices to high-risk systems to transparency for chatbots and generated content. In July 2026 the Digital Omnibus on AI, Regulation (EU) 2026/1744, moved the high-risk dates later and reworded the AI literacy duty in Article 4 so that providers and deployers take measures to support their staff's AI literacy.
| Date | What applies |
|---|---|
| August 1, 2024 | The AI Act entered into force. |
| February 2, 2025 | Prohibited practices (Article 5) and the AI literacy duty (Article 4). |
| August 2, 2025 | Obligations for general-purpose AI models, and the governance rules. |
| August 2, 2026 | The Act applies generally, including transparency duties under Article 50, and enforcement begins. |
| December 2, 2026 | A new prohibition on AI that generates non-consensual intimate imagery or child sexual abuse material. Generative systems already on the market before August 2, 2026 must meet the Article 50(2) marking duty. |
| December 2, 2027 | High-risk rules for Annex III uses such as employment, education, credit, and biometrics. Moved from August 2, 2026 by the omnibus. |
| August 2, 2028 | High-risk rules for AI built into products covered by EU product law, such as machinery and toys. Moved from August 2, 2027. |
How do the parts map to NIST AI RMF, ISO 42001, and the EU AI Act?
NIST subcategories, the ISO clauses NIST's crosswalk assigns to them, and the matching EU AI Act articles. Most EU articles here bind high-risk systems; Articles 4 and 5 bind everyone.
| Part | NIST AI RMF | ISO/IEC 42001 | EU AI Act |
|---|---|---|---|
| Inventory | Govern 1.6; Govern 6.1 for third-party systems | Clause 4 context and scope; resource documentation controls | Article 6 and Annex III high-risk classification |
| Ownership | Govern 2.1 roles; Govern 2.3 executive responsibility | 5.3 roles, responsibilities and authorities | Article 26(2) human oversight by competent people; Article 4 AI literacy |
| Risk tiers | Govern 1.3; Map 5.1 likelihood and magnitude | 6.1.2 AI risk assessment; 6.1.4 AI system impact assessment | Article 5 bans; Article 6 high-risk; Article 50 transparency; Article 27 rights impact assessment for some deployers |
| Policy | Govern 1.2; Govern 1.4 | 5.2 AI policy | Article 26(1) use according to the provider's instructions |
| Controls that run | Manage 1.3 risk responses; Manage 2.4 ability to deactivate | 6.1.3 AI risk treatment | Article 14 human oversight; Article 50(4) deepfake disclosure |
| Monitoring | Measure 2.4; Manage 4.1 | 9.1 monitoring, measurement, analysis and evaluation | Article 26(5) deployers monitor operation; Article 72 post-market monitoring |
| Incident handling | Govern 4.3; Manage 4.3 | 9.3 management review inputs; clause 10 corrective action | Article 26(5) inform the provider of serious incidents; Article 73 reporting |
| Records | Measure 2.4; Govern 4.2 documented impacts | 7.5 documented information; event log controls | Article 12 record-keeping; Article 26(6) deployers keep logs at least six months |
| Review | Govern 1.5 periodic review | 9.2 internal audit; 9.3 management review | Article 9 risk management with regular systematic review |
How does a 50 to 500 person company start in 90 days?
This plan fits a company with a CFO or COO who owns risk, an IT lead, outside counsel, and staff already using AI.
- Days 1 to 30: inventory, owners, and policy. List every AI tool, copilot, and AI feature in use from team surveys, sign-in logs, and expenses. Name one executive accountable for AI risk and an owner for each system. Publish a one-page acceptable use policy naming approved tools and the data that stays out.
- Days 31 to 60: tiers and controls. Put every system on a three-level scale, and check each top-tier system against EU AI Act Annex III if any of its output reaches the EU. For the top tier, switch on the controls that enforce the policy: approved accounts only, logging on, redaction of identifiers, and a named person who can switch the system off.
- Days 61 to 90: monitoring, incidents, records, and review. Set a monthly check of what each top-tier system did. Write a one-page incident path. Set log retention, with six months as the floor for any EU high-risk deployment. Hold the first review and decide whether ISO/IEC 42001 certification is a goal for next year.
How do you know the framework is real?
Test each part for evidence. A control that runs leaves a log; a policy on its own leaves a signature. AI governance versus theater and enforced or written down give the questions to ask, and complying with several regimes shows one set of controls and records serving several regulators.
Frequently asked questions
- What are the four functions of the NIST AI RMF?
- Govern, Map, Measure, and Manage. Govern covers policy, roles, and accountability and applies across the other three; Map sets the context and impacts of each system; Measure assesses and tracks risk; Manage responds to it, including monitoring and incident response after deployment.
- Is the NIST AI Risk Management Framework mandatory?
- No. NIST describes AI RMF 1.0 as voluntary and use-case agnostic. Companies adopt it because it gives a shared vocabulary that customers, auditors, and boards recognize.
- Is ISO 42001 certification required?
- No. ISO states that certification to ISO/IEC 42001 is voluntary and is carried out by independent certification bodies. Companies pursue it when customers or partners ask for independent proof of an AI management system.
- When do EU AI Act high-risk rules apply?
- After the Digital Omnibus on AI, Regulation (EU) 2026/1744, high-risk rules for Annex III uses such as hiring, education, and credit apply from December 2, 2027. High-risk AI built into products covered by EU product law follows on August 2, 2028.
- Does the EU AI Act apply to a US company?
- Yes, when the company places AI on the EU market or when the output of its AI system is used in the EU. Article 2 of the Act covers providers and deployers outside the EU in that case.
- What are the fines under the EU AI Act?
- Using a prohibited practice carries fines up to 35 million euros or 7% of worldwide annual turnover, whichever is higher. Breaching most other operator obligations carries up to 15 million euros or 3%.
- What is the difference between AI governance and AI compliance?
- Governance is the system a company runs to decide, control, and review its use of AI. Compliance is showing that this system meets a specific law or standard, such as the EU AI Act or ISO/IEC 42001, with evidence an auditor accepts.
- What should an AI governance policy include?
- It should name the approved tools, the data that stays out, who approves a new use, and the rules staff follow. The wider framework connects that policy to owners, risk tiers, controls, monitoring, incidents, records, and review.
- What are common AI governance challenges?
- The recurring challenges are finding every system in use, assigning an owner with authority to pause it, applying controls on every request, monitoring production behavior, and keeping evidence current enough for review.
- What is the AI governance framework development process?
- Start with inventory, owners, and policy in days 1 to 30. Add risk tiers and operating controls in days 31 to 60. In days 61 to 90, establish monitoring, incident handling, record retention, and the first scheduled review.
Sources
- NIST, AI 100-1: Artificial Intelligence Risk Management Framework (AI RMF 1.0) (January 2023). Read October 8, 2026.
- NIST, AI 600-1: Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (July 2024). Read October 8, 2026.
- NIST AI Resource Center, Crosswalk Documents. Read October 8, 2026.
- NIST AI Resource Center, NIST AI RMF to ISO/IEC FDIS 42001 AI Management System Crosswalk. Read October 8, 2026.
- ISO, ISO/IEC 42001:2023 Information technology: Artificial intelligence: Management system. Read October 8, 2026.
- ISO, ISO/IEC 42001 explained: what it is. Read October 8, 2026.
- EUR-Lex, Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 2, 4, 5, 6, 9, 12, 14, 26, 27, 50, 72, 73, and 99. Read October 8, 2026.
- EUR-Lex, Regulation (EU) 2026/1744 (Digital Omnibus on AI), OJ L 24.7.2026. Read October 8, 2026.
- European Commission, AI Act: regulatory framework for AI (updated August 3, 2026). Read October 8, 2026.
Reviewed