Guide

AI Governance Framework: A Practical Guide

Most organizations are building AI governance from scratch, without a blueprint. Teams deploy AI tools under informal reviews, legal offers one-off opinions, and boards ask risk questions no one can answer systematically. An AI governance framework changes that — it provides the structured methodology for governing AI risk, accountability, and compliance across the enterprise, from initial deployment through ongoing monitoring.

By Nick Shevelyov 12 min read

Why ad hoc AI governance fails at scale

Every organization with a serious AI deployment problem has the same underlying structure: nobody owns AI risk at the enterprise level, and every team that needs an answer makes up a local one.

Building an AI governance framework after the fact is substantially harder than building one before deployment scales. The pattern is consistent: organizations that moved aggressively on AI in 2023 and 2024 are now doing retroactive work — auditing which AI tools are actually in use (usually double what IT approved), reviewing which vendor agreements permitted model training on company data, and explaining to regulators why their responsible AI program consists of email threads and ad hoc legal opinions.

Legal reviews a vendor contract and flags a data-processing concern. IT approves the tool on security grounds. Business deploys it and agrees to the vendor’s AI model training clause in the terms of service without anyone reading section seven. Six months later, customer data that was used to train a third-party model surfaces in a competitor’s AI output, and three teams point at each other.

This is not a technology failure. It is a governance failure. The cost of retroactive governance is higher than proactive governance — not just in dollars, but in the deployment decisions that were already made and cannot be unwound. The strategic oversight work that reaches board-level today increasingly starts with an AI exposure audit precisely because the first step is establishing what the organization is already governing without knowing it.

An AI governance framework provides the structure that prevents this cycle. Not by blocking AI adoption, but by channeling it through a repeatable decision process: What is this system? What risk does it carry? Who owns that risk? What controls apply? Who reports what to whom, on what cadence?

The sections below cover the major published frameworks that answer those questions, the components any enterprise AI governance framework needs, and how to build maturity from scratch.

The major published AI governance frameworks

Three frameworks dominate the enterprise AI governance landscape. Each serves a different purpose, and most mature programs draw from more than one.

NIST AI RMF: the operational standard

The National Institute of Standards and Technology published its AI Risk Management Framework in January 2023. It has become the default reference standard for U.S.-based organizations approaching enterprise AI governance — free to use, outcome-based, and designed for adaptability across industries and AI system types.

The NIST AI RMF organizes AI risk management into four core functions:

  • Govern establishes the organizational conditions for effective AI risk management — culture, policies, accountability structures, oversight processes, and workforce AI literacy. Govern is not a separate phase; it operates across and enables the other three functions. An organization that has not built governance infrastructure cannot Map, Measure, or Manage effectively.
  • Map categorizes AI systems and their deployment contexts, identifies relevant stakeholders, and surfaces the risks specific to each system’s use case. Mapping is where AI inventory meets context: the same model architecture deployed for credit decisioning carries different risks than the same architecture deployed for content recommendation.
  • Measure analyzes, assesses, and tracks AI risks using both quantitative and qualitative methods. This is the analytical layer — risk scoring, bias testing, model performance measurement, and ongoing monitoring.
  • Manage treats, prioritizes, and monitors AI risks on an ongoing basis. Treatment options include mitigation controls, deployment constraints, stakeholder disclosure, risk acceptance, or discontinuation. Manage is where governance produces operational decisions.

NIST also publishes the AI RMF Playbook — a companion resource that maps specific actions to each function. The framework is not certifiable, but it integrates cleanly with the NIST Cybersecurity Framework and provides a natural bridge for organizations running a cybersecurity risk management framework that needs AI risk coverage added to it.

Operator note: The Govern function is underimplemented at most organizations that have nominally adopted the NIST AI RMF. Teams do Map and Measure work — they inventory systems, run bias tests — but without Govern infrastructure (named accountable roles, board reporting cadence, documented AI risk appetite), the outputs of Map and Measure go nowhere. Govern is not optional setup. It is the precondition for everything else. Organizations that stand up Govern first move through Map and Measure substantially faster because accountability is already established before the analysis work begins.

ISO/IEC 42001: the certifiable standard

ISO/IEC 42001, published in December 2023, is the first internationally certifiable standard for AI management systems. Its structure mirrors ISO 27001: a Plan-Do-Check-Act management system with defined requirements for policy, risk assessment, operational controls, and continual improvement, plus an Annex A of AI-specific controls organizations can select and apply.

The key distinction from the NIST AI RMF is certification. An organization that completes an ISO 42001 audit and receives certification can demonstrate to enterprise customers, regulators, and partners that its AI management system has been independently assessed. For organizations with international operations or enterprise sales cycles that require evidence of responsible AI practices, ISO 42001 provides the same commercial credential that ISO 27001 provides in information security.

ISO 42001’s scope covers the AI management system itself — not individual AI models or applications, but the organizational processes that govern them. Certification requires documented AI policy, a methodology for AI risk assessment, defined controls for the AI system lifecycle (development, procurement, operation, and decommissioning), supplier AI risk management, performance evaluation mechanisms, and management review processes.

The tradeoff is implementation overhead. Building and certifying an AI management system to ISO 42001 requires dedicated resources, internal audit capability, and the documentation discipline that any ISO management system demands. Organizations that need the certification for commercial or regulatory reasons will find the investment justified. Those that do not may find the NIST AI RMF covers the governance substance with far less process weight.

EU AI Act: the regulatory floor

The EU AI Act entered into force in August 2024 and represents the world’s most comprehensive AI-specific regulatory regime. Its risk-tiered structure is now the baseline regulatory framework for any organization operating in or selling to the European market — and increasingly referenced by U.S. regulators developing their own AI oversight approaches.

The Act organizes AI systems into four risk tiers:

Unacceptable risk AI systems are prohibited outright. This category includes social scoring systems used by governments or public authorities, real-time remote biometric identification in public spaces (with narrow law enforcement exceptions), AI that exploits psychological vulnerabilities to manipulate behavior, and AI used to assess the risk of criminal offending based on profiling alone.

High-risk AI systems face the most stringent obligations. This tier covers AI deployed in critical infrastructure operations, educational credentialing, employment screening and workforce management, essential private services such as credit and insurance, law enforcement, border management and immigration, and justice and democratic processes. High-risk systems must meet data governance requirements, undergo conformity assessment, maintain technical documentation, implement human oversight mechanisms, and satisfy accuracy and robustness standards before deployment.

Limited-risk AI systems — including general-purpose chatbots, AI-generated content, and deepfake generators — carry transparency obligations. Users must be informed they are interacting with AI or viewing AI-generated content.

Minimal-risk AI covers most AI applications and faces no specific obligations under the Act.

The Act also introduced a separate regime for general-purpose AI models — large-scale foundation models underlying most enterprise AI copilots — requiring systemic risk assessment and incident reporting for the most capable systems.

For enterprise AI governance frameworks built outside the EU, the Act’s risk classification logic still has practical value: categorizing your AI systems using the Act’s tiers forces the explicitness about use case, affected populations, and consequence severity that good AI governance requires regardless of jurisdiction.

Framework comparison

FrameworkPublishedTypeCertifiable?Best for
NIST AI RMFJanuary 2023Risk management frameworkNoU.S. organizations; program structure; CSF integration
ISO/IEC 42001December 2023Management system standardYesInternational operations; enterprise sales; regulatory engagement
EU AI ActAugust 2024 (in force)Regulatory frameworkN/A — compliance required for in-scope organizationsOrganizations in or selling to EU; risk classification baseline globally

Core components of an enterprise AI governance framework

Published frameworks provide the organizing logic. The actual AI governance framework an organization builds and operates needs these components functioning at the same time.

AI inventory and classification. Governance starts with visibility. A complete AI inventory catalogs every AI system in production or under evaluation, including AI embedded in third-party vendor products. Classification assigns each system to a risk tier, names its use case, documents the data it processes, and records vendor AI model dependencies. Without this foundation, governance is theoretical.

Accountability structure. Named accountable roles for AI risk — not team-level ownership. Who is responsible for a specific AI system’s risk profile? Who approves its deployment? Who is accountable if it produces biased outputs or violates a regulatory requirement? The cybersecurity governance discipline has worked through this accountability problem in security contexts; AI governance borrows and extends that model to AI-specific risk domains.

AI risk assessment process. A repeatable methodology for evaluating new AI deployments before they go live. This includes use-case analysis, data flow documentation, bias and fairness assessment, third-party AI model vendor review, and regulatory classification under applicable regimes. The assessment is a gate, not an audit — it happens before deployment, not after something goes wrong.

AI governance policy. A documented policy that establishes what AI uses are permitted, what data can be used to train or fine-tune models, what disclosure requirements apply to AI-assisted outputs, and what escalation path governs edge cases. The policy is one output of the governance framework — it guides day-to-day decisions without requiring every question to reach an oversight committee.

Oversight and board reporting cadence. AI risk reaching the board requires a defined reporting cadence. What AI risk metrics reach board-level visibility? How frequently? Who is responsible for that reporting? Organizations that have invested in cybersecurity governance structures can extend those reporting chains to cover AI risk rather than building parallel governance infrastructure.

Incident and harm response. What happens when an AI system produces a harmful output, violates a regulatory requirement, or is found to have been used outside its approved scope? Incident response for AI requires different playbooks than cybersecurity incident response — the harm patterns, affected parties, and remediation options differ in important ways.

Continuous monitoring. AI systems drift over time as data patterns shift, user behavior changes, and model updates are deployed by vendors. Continuous monitoring tracks performance, fairness metrics, and regulatory compliance status for deployed AI systems on an ongoing basis — not just at initial deployment.

AI governance maturity model

Most organizations entering AI governance work are at level one: AI is deployed, but governance is reactive and informal. The following maturity model describes the progression toward systematic enterprise AI governance and can serve as both a diagnostic and a planning tool.

LevelNameCharacteristicsTypical timeline to reach
1Ad HocNo formal AI governance framework. Deployments are approved informally or not at all. No maintained AI inventory. Governance is reactive, triggered by incidents or regulatory inquiries rather than proactive process.Starting state for most organizations
2DefinedAI inventory exists and is actively maintained. Accountability is assigned at the system level with named owners. An AI governance policy is in place. A risk assessment process exists for new deployments. AI risk reporting reaches executive level.6–9 months from framework adoption
3ManagedRisk assessments are routine and documented. AI governance metrics are tracked and reported. AI risk reaches board-level reporting. Vendor AI risk management is operating. Continuous monitoring is in place for high-risk systems.12–18 months from framework adoption
4OptimizedThe AI governance framework drives deployment decisions proactively. Risk metrics inform strategic AI investment. Continuous improvement cycles refine the framework. AI governance is fully integrated with enterprise risk management and cybersecurity programs.24–36 months from framework adoption; continuous discipline thereafter

The maturity model is not a grading system. Most boards do not need an organization to be at level four — they need to know where the organization actually sits today and what the trajectory looks like. An honest level-two organization with a credible level-three plan is in a better position than an organization claiming level-three maturity that cannot produce the inventory or risk assessments that would evidence it.

Operator note: The gap between level two and level three is almost always an accountability problem, not a process problem. Organizations at level two have documentation — a policy exists, a nominal inventory exists. What they do not have is someone whose performance depends on whether governance actually runs. The shift to level three requires AI governance to be someone’s defined responsibility, not a committee’s shared background task. In security programs, this is the CISO’s function. AI governance needs the same: a named owner with authority and accountability, not a working group that meets quarterly.

Building your AI governance framework: an implementation roadmap

Phase 1: Establish visibility (months 1–2)

AI governance cannot start without knowing what you are governing. The first deliverable is an AI inventory — a catalog of every AI system in use, including AI embedded in third-party products. This is harder than it sounds. Business units have often deployed AI tools without IT awareness, and vendor agreements embed AI processing in ways that are not labeled as AI.

The inventory should produce: system name and owner, use case, data inputs and processing, vendor AI model dependency where applicable, current approval status, and a preliminary risk tier classification.

Concurrent with inventory: review existing vendor agreements for AI-related clauses covering model training rights, data use, and output ownership. This review regularly surfaces data exposure decisions no one consciously made — and that are easier to renegotiate before the vendor relationship is embedded in critical operations.

Phase 2: Assign accountability and establish policy (months 2–4)

With inventory in hand, assign named accountable roles to each AI system in production. For systems above minimal risk, assign a business owner, a technical owner, and an oversight reviewer. Define escalation paths for edge cases and a process for handling policy exceptions.

Draft the AI governance policy — at minimum: permitted and prohibited uses of AI, data handling requirements for AI processing, disclosure requirements for AI-assisted outputs, and the deployment approval process for new AI systems. The policy should be specific enough to guide decisions, not so comprehensive that no one reads it.

Select the primary AI governance framework appropriate for the organization’s context. For most U.S.-based organizations, NIST AI RMF provides the right structural foundation. For organizations with EU operations or enterprise sales requiring evidence of responsible AI practices, ISO/IEC 42001 certification should be on the roadmap from the start rather than added later.

Phase 3: Build the risk assessment process (months 3–6)

Establish a repeatable AI risk assessment methodology for evaluating new AI deployments. The assessment should cover: use case and affected populations, data inputs and processing, model provenance (vendor, open source, or internal), regulatory classification, bias and fairness evaluation criteria, human oversight requirements, and a continuous monitoring plan.

Run the assessment process against existing high-risk AI systems in the inventory — not just new deployments. This produces the risk register that governance reporting draws from and surfaces remediation work that would otherwise wait for an incident to trigger it.

Integrate the AI risk assessment process with the existing cybersecurity risk management framework. AI systems introduce new attack surfaces, data exposure vectors, and model integrity risks that cybersecurity controls need to address — and the two programs share governance infrastructure that should not be built twice.

Phase 4: Operationalize reporting and monitoring (months 5–9)

Connect AI governance outputs to executive and board reporting. Baseline metrics for board-level reporting: AI risk register summary (count of systems by risk tier), open governance findings, significant incidents (bias events, regulatory triggers, data exposure), and a policy exception log. Boards can act on that information. They cannot act on process descriptions.

For high-risk AI systems, establish continuous monitoring — ongoing tracking of model performance, fairness metrics, and operational compliance. Monitoring cadence should reflect system risk: daily automated checks for high-volume decision systems, monthly review cycles for lower-frequency AI applications.

Phase 5: Mature and integrate (months 9–24)

As the framework stabilizes, integration becomes the priority. Connect AI governance to the enterprise risk management program so AI risk appears in the same risk register as operational, financial, and reputational risks. Extend third-party risk management processes to cover AI vendors specifically — most third-party risk programs were designed before AI model dependencies became material, and standard questionnaires do not capture AI-specific risks adequately.

Begin annual AI governance policy review cycles to incorporate regulatory developments, new AI system types, and lessons from the incident log.

Anti-patterns that stall AI governance programs

Understanding what fails in practice is as useful as understanding what works.

Treating the framework document as the deliverable. Organizations that complete a framework adoption project and declare victory typically have documentation with no operational effect. The AI governance framework is not the goal — systematic AI risk management is the goal. If the framework produces shelf-ware policies that do not affect deployment decisions, the program has failed regardless of how comprehensive the documentation appears.

Inventorying only IT-approved AI. Shadow AI — tools deployed by business units without IT approval — often represents more than half of actual AI use in organizations. A governance program that covers only approved AI is governing the visible fraction of the problem while ignoring the part most likely to generate an incident.

Conflating compliance with governance. EU AI Act compliance for high-risk systems requires specific technical and documentation obligations before deployment. That compliance work is necessary but not sufficient for effective AI governance. Compliance is a condition met at a point in time. Governance is ongoing. Organizations that build compliance programs but not governance programs are managing a short-term certification while a long-term risk accumulates.

Skipping the board reporting connection. AI governance that operates only at the operational level, without board visibility, lacks the authority and funding to function as enterprise governance. Boards are increasingly asking AI risk questions; governance programs that cannot answer with data will be reorganized by executives who can no longer tolerate the gap.

Vendor-led AI risk assessment. Relying on AI vendors to self-assess their risk profile is not AI governance. Vendor attestations and security questionnaires are inputs, not independent assessment. The organization must develop the capability to evaluate AI vendor claims — including claims about data handling, model behavior, and bias testing — and not accept vendor representations as a substitute for its own assessment process.

Building an AI governance framework that avoids these patterns requires the same discipline as any other governance program: named ownership, defined process, operational metrics, and board visibility. The frameworks covered here — NIST AI RMF, ISO/IEC 42001, and the EU AI Act’s risk-tier structure — provide the vocabulary and organizing logic. The work of making an AI governance framework function is organizational, not technical.


vCSO.ai is the operator-led AI and cybersecurity advisory practice of Nick Shevelyov, former 15-year Chief Security Officer at Silicon Valley Bank. His book Cyber War…and Peace covers the strategic disciplines that connect governance structure to real risk reduction. For the foundational definition, see our what is AI governance guide. For AI governance in the context of security program design, see cybersecurity governance and the cybersecurity risk management framework overview.

Questions & answers

What is an AI governance framework?

An AI governance framework is a structured set of policies, processes, roles, and controls that organizations use to identify, assess, and manage risks from AI systems while enabling responsible AI adoption at scale. It connects technical AI deployment decisions to business accountability structures, compliance obligations, and board-level oversight. Major published frameworks include the NIST AI RMF (2023), ISO/IEC 42001 (2023), and the EU AI Act's risk-tier structure.

What are the four functions of the NIST AI RMF?

The NIST AI Risk Management Framework, published in January 2023, organizes AI risk management into four core functions: Govern (establishing organizational culture, policies, accountability, and oversight for AI risk), Map (categorizing AI systems and their contexts, identifying risks), Measure (analyzing and assessing AI risks quantitatively and qualitatively), and Manage (prioritizing, treating, and monitoring AI risks on an ongoing basis). The Govern function operates across the other three — it establishes the organizational conditions that make Map, Measure, and Manage effective.

What is ISO/IEC 42001 and how does it support AI governance?

ISO/IEC 42001, published in December 2023, is the first certifiable international standard for AI management systems (AIMS). Modeled on the Plan-Do-Check-Act structure of ISO 27001, it defines requirements for establishing, implementing, operating, and continually improving an AI management system. It covers AI policy, risk assessment methodology, supplier relationships, performance evaluation, and an Annex A of AI-specific controls. Organizations needing a certifiable AI governance credential for enterprise sales, regulatory engagement, or international operations use ISO 42001 as their primary standard.

What are the EU AI Act risk tiers?

The EU AI Act, which entered into force in August 2024, applies a risk-tiered approach to AI regulation. Unacceptable-risk AI systems are prohibited outright, including social scoring by governments, real-time biometric surveillance in public spaces (with narrow law enforcement exceptions), and subliminal manipulation. High-risk AI systems face the most stringent obligations and include AI used in critical infrastructure, employment decisions, essential services, law enforcement, and justice. Limited-risk AI such as chatbots carries transparency obligations. Minimal-risk AI faces no specific regulatory requirements under the Act.

How do you implement an AI governance framework?

AI governance framework implementation follows a phased approach: start with an AI inventory (you cannot govern what you have not found), then assign named accountable owners, establish a policy foundation, build a repeatable risk assessment process for new AI deployments, and connect the framework to existing cybersecurity and enterprise risk management programs. The biggest failure mode is treating framework adoption as a documentation project. The framework must drive actual deployment decisions, vendor assessments, and board reporting to produce real risk management.

What is an AI governance maturity model?

An AI governance maturity model describes the progression from reactive, ad hoc AI oversight to systematic, optimized AI risk management. A four-level model runs from Ad Hoc (no formal framework, reactive responses) through Defined (policies exist, inventories maintained, accountability assigned) and Managed (risk assessments routine, metrics tracked, governance drives deployment decisions) to Optimized (continuous improvement, full integration with enterprise risk programs). Most organizations should target Defined maturity within 6 to 9 months of framework adoption and Managed within 18 months.

How does an AI governance framework differ from a cybersecurity framework?

AI governance and cybersecurity governance are distinct but overlapping disciplines. A cybersecurity risk management framework addresses how to protect systems from external threats and manage security risk. An AI governance framework addresses how to manage the risks that AI systems themselves create, including model bias, explainability failures, training data quality, third-party AI model risk, and regulatory compliance with AI-specific laws such as the EU AI Act. Organizations should integrate their AI governance framework with their cybersecurity program rather than operating them as parallel silos.

Ready to turn this into a working plan?

Our team helps growth-stage companies, PE/VC sponsors, and cybersecurity product teams translate security questions into board-ready decisions. First call is strategy, not vendor pitch.

Contact us We’ll be in touch →