Guide · 20 min read
AI Governance Framework: A Practical Enterprise Guide
How to design, deploy, and operate an enterprise AI governance framework using NIST AI RMF 1.0, ISO/IEC 42001, the EU AI Act, and OMB M-24-10 — with concrete controls, evidence artifacts, and metrics you can put in production this quarter.
1. What is an AI governance framework?
An AI governance framework is the structured set of policies, roles, controls, and evidence practices an organization uses to ensure its AI systems — including agentic and generative AI — are lawful, safe, effective, and aligned with organizational values. In practice, it links three layers:
- Policy — the human-readable rules (acceptable use, human oversight, risk tiers).
- Process — the workflow that reviews, approves, monitors, and retires AI systems.
- Proof — tamper-evident evidence (audits, assessments, incident logs, model cards) that regulators, auditors, and customers can inspect.
A framework is not a document; it is an operating system. The document is the launch spec.
2. Why enterprises need one now
- Regulatory clock — the EU AI Act's high-risk obligations phase in through 2026–2027, with fines up to 7% of global turnover.
- Customer procurement — Fortune 500 buyers now include AI questionnaires (ISO 42001, NIST RMF alignment) in RFPs.
- Agentic risk — autonomous agents that use tools and make chained decisions break the assumptions of classic model-risk (SR 11-7) programs.
- Incident precedent — public failures (biased hiring models, hallucinated legal briefs, agent-triggered outages) create board-level attention that never fully recedes.
3. The major frameworks compared
| Framework | Type | Jurisdiction | Certifiable? | Best for |
|---|---|---|---|---|
| NIST AI RMF 1.0 | Voluntary guidance | US (global influence) | No | Operating model & culture |
| ISO/IEC 42001 | Management system standard | Global | Yes (accredited audit) | External assurance |
| EU AI Act | Binding regulation | EU market | Conformity assessment | High-risk use cases in EU |
| OMB M-24-10 | Federal directive | US federal agencies | No | Public-sector AI use |
| SR 11-7 | Supervisory guidance | US banking | Examination-based | Regulated financial models |
| OECD AI Principles | Intergovernmental principles | 38+ countries | No | Policy alignment |
Most enterprises adopt NIST AI RMF as their operating model, ISO/IEC 42001 as their certifiable management system, and layer EU AI Act obligations onto systems that touch EU users.
4. Deep dive: NIST AI RMF
NIST AI RMF 1.0 organizes trustworthy AI into four functions. Each function decomposes into categories and subcategories — 72 subcategories in total.
Govern
Policies, accountability, roles, culture. This is the layer that makes the other three enforceable.
Map
Context, use case, stakeholders, and impacts. You cannot manage risk on a system you have not scoped.
Measure
Performance, fairness, robustness, and security metrics — with methods documented and results archived.
Manage
Prioritize, respond, monitor, and retire. The loop that turns findings into actions.
5. Deep dive: ISO/IEC 42001
ISO/IEC 42001 is the first international AI management system (AIMS) standard. It follows the Annex SL structure familiar from ISO 27001 (ISMS) and ISO 9001, which makes it straightforward to integrate with an existing management system.
- Clauses 4–10 — context, leadership, planning, support, operation, evaluation, improvement.
- Annex A — 38 reference controls across policy, resources, impact assessment, lifecycle, data, information for interested parties, and third-party relationships.
- Certification — accredited certification bodies issue a certificate valid for three years with annual surveillance audits.
6. Deep dive: EU AI Act
The EU AI Act uses a risk-based classification and stacks obligations accordingly.
- Prohibited (Art. 5) — social scoring, manipulative techniques, untargeted biometric scraping.
- High-risk (Annex III) — employment, education, credit, essential services, law enforcement, migration, justice.
- Limited-risk — transparency obligations (Art. 50): disclose AI to users, label synthetic media.
- General-purpose AI (GPAI) — provider obligations for foundation-model developers, with systemic-risk tier for the largest models.
High-risk providers must maintain a QMS (Art. 17), risk management (Art. 9), data governance (Art. 10), technical documentation (Art. 11), logging (Art. 12), human oversight (Art. 14), robustness & cybersecurity (Art. 15), and post-market monitoring plus serious-incident reporting (Art. 73).
7. Cross-framework mapping
The frameworks converge on the same operational controls; the labels differ. A single implementation, mapped correctly, can satisfy all of them.
| Operational control | NIST AI RMF | ISO/IEC 42001 | EU AI Act |
|---|---|---|---|
| AI policy in force | GOVERN 1.1 | Clause 5.2 | Art. 17 (QMS) |
| Per-system risk assessment | MAP 2 / MEASURE 2 | Clause 6.1 · A.5.2 | Art. 9 |
| Tamper-evident logging | MANAGE 4.1 | Clause 7.5 | Art. 12 |
| Human oversight | MANAGE 1.3 | A.6.2.6 | Art. 14 |
| Incident response | MANAGE 4 | A.9.3 | Art. 73 |
| Third-party / GPAI providers | MAP 4.1 | Annex A.10 | Art. 25 · 26 · 53 |
Aiudit maintains this mapping live for every deployed system — see the Security & Compliance page for the full crosswalk.
8. Roles & RACI
Governance fails without named accountability. A minimum viable RACI:
- Accountable — Chief AI Officer or equivalent executive.
- Responsible — AI Governance Lead (day-to-day operator).
- Consulted — Legal, Privacy, Security, Ethics Committee, business owners.
- Informed — Board Risk Committee (quarterly), regulators (as required).
9. The AI system lifecycle
- Intake — register the use case, classify risk tier, run an impact assessment.
- Design — data governance, model selection, human-oversight design.
- Build — evaluations, red-team testing, guardrail compilation.
- Deploy — release gate, monitoring plan, rollback plan.
- Operate — continuous telemetry, drift detection, incident workflow.
- Retire — controlled shutdown, evidence retention, lessons learned.
10. The 12 core controls
Every mature program we see runs on these twelve controls, regardless of framework label:
- Approved AI policy, versioned and signed.
- Central AI system inventory with owner and risk tier.
- Impact / risk assessment on every system before launch.
- Data governance: lineage, consent, license conflicts.
- Evaluation suite: performance, fairness, robustness.
- Red-team & adversarial testing on high-risk systems.
- Runtime guardrails compiled from policy.
- Human-in-the-loop review for high-impact decisions.
- Tamper-evident audit chain for governance actions.
- Incident detection, response, and regulator clock.
- Third-party / GPAI provider due diligence.
- Sealed evidence packages ready for auditors.
11. KPIs & board reporting
- Coverage — % of AI systems with a current assessment (target: 100%).
- Timeliness — median days from intake to approval (target: < 15).
- Guardrail hit rate — blocked / total attempts, trended by policy.
- Incident MTTR — median time-to-remediate by severity.
- Regulator clock compliance — % of reportable incidents notified within window.
- Evidence freshness — median age of sealed evidence per system.
12. 90-day rollout plan
Days 1–30 · Foundations
- Publish v1 AI policy, name the accountable executive, stand up the governance committee.
- Inventory every AI system in production and in pilot; classify by risk tier.
- Adopt NIST AI RMF as the operating model; select ISO/IEC 42001 as the certification target.
Days 31–60 · Controls
- Run impact assessments on all high-risk systems; remediate top findings.
- Deploy tamper-evident logging and telemetry ingestion for agentic systems.
- Compile runtime guardrails from policy; wire into the deployment pipeline.
Days 61–90 · Assurance
- Run an internal audit against ISO/IEC 42001 Annex A; open corrective actions.
- Table-top a high-severity incident end-to-end; measure regulator-clock compliance.
- Deliver first quarterly report to the Board Risk Committee.
13. Common pitfalls
- Policy without proof — governance PDFs without audit chains fail every audit.
- One-off assessments — assessments must be re-run on material change, not filed once.
- Ignoring agentic risk — chained tool use invalidates single-model assessments.
- Shadow AI — inventory must include employee-adopted GPAI, not just IT-approved systems.
- Framework shopping — pick one operating model, then map others onto it. Don't run three programs in parallel.
14. FAQ
Is ISO/IEC 42001 mandatory?
No, but certification is increasingly required in enterprise procurement and is the strongest external signal of a functioning AI management system.
Do we need a separate program if we already have SR 11-7 model risk management?
Extend, don't replace. SR 11-7 covers model validation well but does not address agentic behaviour, prompt injection, or the EU AI Act's transparency and post-market monitoring obligations.
How does the EU AI Act apply to a US company?
It applies whenever your AI system's output is used in the EU, regardless of where the provider is established. Extraterritorial scope mirrors GDPR.
What's the fastest way to demonstrate governance to a customer?
A sealed, signed evidence package containing your policy, current assessment, control mapping, and recent audit-chain excerpt — exactly what Aiudit generates one click at a time.
Operationalize this framework
See it running on your systems
Aiudit implements every control in this guide out of the box — policy registry, tamper-evident audit chain, guardrail compiler, incident response with regulator clock, and sealed evidence packages mapped to NIST AI RMF, ISO/IEC 42001, and the EU AI Act.