Ethics · Fast-moving · Intermediate
AI Governance
The policies, roles and controls an organisation uses to decide what AI it deploys and under what conditions.
What AI Governance is
Governance answers who approves an AI use case, what evidence is required, who owns the risk, and how incidents are handled — the organisational counterpart to technical safety.
How it works
Typical structures include an inventory of AI systems, a risk-tiering framework, approval workflows, required documentation, vendor due diligence and periodic audit against a standard such as ISO/IEC 42001 or the NIST AI RMF.
Why it matters
Regulation increasingly assigns obligations by risk tier, and you cannot comply with rules about systems you have not inventoried.
Common uses
- →AI system inventories
- →Risk tiering and approvals
- →Vendor due diligence
- →Audit readiness
Strengths
- ✓Clear accountability
- ✓Evidence for regulators and customers
Watch for
- ✓Slows shadow experimentation
- ✓Needs senior sponsorship
Continue exploring
More in this collection
Browse all AI ConceptsSources & References
ISO/IEC 42001 — AI management systems