AI Governance

An AI program that survives scrutiny

Model inventory, risk tiering, and controls mapped to NIST AI RMF and ISO/IEC 42001.

Book a consultation →

Most AI governance programs fail the same way. Someone writes a policy, it gets approved, and nothing about how the company actually builds and buys AI changes. Then a customer sends a security questionnaire with fourteen AI questions on it and everyone scrambles.

A governance program that works is not a document. It is knowing what AI you have, who owns each one, what could go wrong with it, and what gate it passed before it reached production.

Start with the inventory, because nobody has one

The first thing we do is find out what is actually running. Not the sanctioned platform, the whole picture: the vendor tools with AI features switched on, the department that expensed an API key, the model somebody fine-tuned last quarter, the agent a contractor built and left behind.

This is uncomfortable and it is always worth doing. You cannot govern what you have not enumerated, and the inventory usually settles arguments about scope faster than any framework discussion.

Then tier it by risk, not by enthusiasm

Not every AI system needs the same treatment. A tool that drafts internal meeting notes and a model that influences credit decisions do not belong in the same bucket, and treating them identically either paralyzes the low-risk work or under-governs the high-risk work.

We tier by what the system touches and what happens when it is wrong: consequential decisions about people, regulated data, customer-facing output, autonomous action. The tier determines how much review, testing, and monitoring a system gets. That is what keeps the program proportionate enough to survive.

NIST AI RMF and ISO/IEC 42001, and which you need

These get discussed as competitors. They are not.

The NIST AI Risk Management Framework is voluntary, free, and organized around four functions: govern, map, measure, manage. It is a way of thinking about AI risk. Nobody certifies you against it, which makes it a good starting structure and a poor answer when a customer asks for proof.

ISO/IEC 42001 is a certifiable management system standard, structured like ISO 27001. You can be audited and hold a certificate. That matters when procurement asks, and increasingly it does.

Our usual advice: build to NIST AI RMF because it is the better thinking tool, and structure the artifacts so ISO 42001 certification is a short step rather than a restart. If you already hold ISO 27001, much of the management system carries over and the marginal effort is smaller than people expect. We will also tell you when certification is not worth it yet.

The controls that actually get used

A policy nobody reads changes nothing. What changes behavior is a gate in the workflow.

That means an intake process so new AI use gets registered before it ships, with the friction scaled to the risk tier. Vendor assessment for third-party AI, because most of your exposure is bought rather than built, and the questions worth asking are about training data, retention, and subprocessors. Pre-deployment testing proportionate to tier, including bias evaluation where the system affects people. Monitoring after launch, since model behavior drifts and providers update models underneath you. And a documented human review path for consequential decisions.

Where those systems are agents that call tools and act, the technical controls come from our agentic AI security practice, and the governance layer here is what makes them auditable.

Built for the questions you will be asked

The practical test of a governance program is whether it survives contact with an outsider. A customer's security team asking how you evaluate model risk. A regulator asking how you prevent discriminatory outcomes. Your board asking whether AI exposure is understood.

We build the program so the evidence exists before those questions arrive, and so answering them is retrieval rather than a fire drill.

Get in touch and we will give you a straight read on where you are and what is actually worth building.

Outcomes

What you get

You know what you have

A complete inventory of AI in use, built and bought, with an owner and a risk tier on each one.

A program proportionate to risk

Low-risk work moves without friction. Consequential systems get real review. Teams stop guessing what is allowed.

Answers ready before the questions

Evidence for the security questionnaire, the auditor, and the board already assembled rather than reconstructed under pressure.

Questions

Frequently asked

Do we need ISO 42001 certification?

Only if someone is asking for it, or you expect them to. If procurement teams in your market have started requesting AI assurance, certification is worth the effort. If not, build to NIST AI RMF and keep the artifacts structured so certification is a short step later.

We only use vendor AI, we do not build models. Does this apply?

Yes, and this is the most common situation. Most exposure comes from purchased tools with AI features. The governance work shifts toward vendor assessment and configuration rather than model development, but the inventory and tiering are the same.

How is this different from our existing security program?

It overlaps and should connect to it. What is different is what AI risk covers: model behavior, training data, bias, hallucination in consequential contexts, and autonomy. Your SOC 2 controls do not address any of that.

How long does it take?

A gap assessment and inventory typically runs four to six weeks. Standing up a full program including intake, policy, and controls is usually three to four months depending on size and how much already exists.

Does this slow down our AI adoption?

Done badly, yes. Done well it speeds it up, because teams stop waiting for someone to decide whether something is allowed. Risk tiering exists so low-risk work moves fast and only the consequential systems get heavy review.

Who typically owns this internally?

Usually security or risk, sometimes legal, occasionally a dedicated AI lead. What matters more than the title is that someone owns it with enough authority to say no. We help define that ownership as part of the engagement.