Start with an inventory you can trust
You cannot govern what you cannot enumerate. Every AI system, its owner, the data it touches, the systems it writes to, the model and version behind it, and its risk tier. Most enterprises discover twice as many live AI systems as they expected, mostly embedded in SaaS products they already bought.
Risk tiering that maps to real controls
Three tiers work in practice. Tier one: read-only, internal, human-reviewed output — light controls, fast approval. Tier two: customer-facing or writes to a system of record — evaluation gates, audit trail, human escalation path. Tier three: consequential decisions affecting credit, coverage, employment or clinical care — full model documentation, bias testing, human decision authority and regulator-ready evidence. Tie the tier to the controls in writing so teams know the cost of the path they choose.
Evaluation gates and change control
The operational core: a golden evaluation set per workload, run in CI, with a pass threshold that blocks deploy; documented approval for model, prompt or index changes; and rollback capability. This is where governance stops being policy and becomes engineering — and it is the part most frameworks omit entirely.
Audit trails and evidence
Log the input, the retrieved sources, every tool call and its authorisation, the output, and the human decision if any — retained per your records policy. When a regulator, a client or your own risk committee asks how a specific decision was reached, the answer must be a query, not an investigation.
Mapping EU AI Act and NIST AI RMF onto delivery
The EU AI Act's high-risk obligations — risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness — map cleanly onto tier three above. NIST AI RMF's Govern, Map, Measure and Manage functions map onto inventory, risk tiering, evaluation and change control respectively. Implement the controls once, and produce the frameworks as reports rather than running parallel programs.
- Inventory first — most enterprises have twice the AI systems they think
- Three risk tiers with pre-agreed controls remove per-project negotiation
- Evaluation gates in CI turn governance from policy into engineering
- Implement controls once; produce EU AI Act and NIST AI RMF evidence as reports
Questions leaders ask us
- What is an AI governance framework?
- A structured set of controls covering AI system inventory, risk tiering, evaluation gates, audit trails, model change control and human oversight — designed so a workload can reach production against pre-agreed criteria rather than a bespoke review each time.
- Does AI governance slow delivery down?
- Poorly designed governance does. Tiered controls agreed in advance speed delivery up, because teams know exactly which evidence a workload needs before it can ship.
- How do EU AI Act and NIST AI RMF fit together?
- EU AI Act high-risk obligations map onto the highest control tier — risk management, data governance, documentation, logging, human oversight and robustness. NIST AI RMF's Govern, Map, Measure and Manage map onto inventory, risk tiering, evaluation and change control. Implement once and report to both.