Untitled
This module contains AI governance frameworks, compliance materials, and risk management resources.
Overview
The AI Governance module provides comprehensive resources for implementing responsible AI practices, including regulatory compliance, risk management frameworks, and governance templates.
Relationship to Other Directories
This directory is the implementation layer of a wider AI knowledge base: it holds the control templates, risk artefacts, and organisation-specific program material that operationalise what the sibling directories describe normatively. Use the siblings for the authoritative deep-dives; use this directory for the templates that put them into practice.
| Directory | Role | Use it for |
|---|---|---|
This directory (AI-Governance/) | Implementation — controls, templates, risk artefacts, organisation program | Putting standards into practice (registry, transparency cards, incident response, monitoring, risk registers) |
standards/ | Normative technical/management standards | Canonical deep-dives: ISO/IEC SC 42 family (42001, 23894, …), NIST AI RMF, EU AI Act |
../AI-security/ | Threat models & ISMS | MITRE ATLAS, NCSC/CISA/ASD secure-development guidance, ISO/IEC 27001/27701 |
../AI-assurance/ | Engagement & regulator layer | How controls are independently assured — ASAE 3000/3150, APES 110, IIA, APRA AI letter, SOC 2 |
../AI-security/agentic/ | Agentic security tooling | Sandboxing, agent identity, policy controls, prompt security for AI agents |
Avoiding duplication-with-drift: several documents here summarise standards that have authoritative deep-dives in the sibling directories. Where a summary and a deep-dive both exist, the deep-dive is canonical and this directory’s copy should be treated as an implementation-oriented digest:
- NIST AI RMF — canonical deep-dive:
standards/NIST-AI-RMF-Deep-Dive.md - ISO/IEC 27001 / 42001 — canonical deep-dives:
../AI-security/ISO-IEC-27001-Deep-Dive.mdandstandards/ISO-IEC-42001-Deep-Dive.md - OWASP AISVS / assurance use — see
../AI-assurance/OWASP-AISVS-and-TEA-AssurancePlatform-Deep-Dive.md - SOC 2 — canonical treatment:
../AI-assurance/SOC2-Trust-Services-Criteria.md
The AI Governance Mega-Map (frameworks/The Company Ethos/Ai_Governance_Mega_Map.md) is the cross-framework spine that ties these together; see AI-Knowledge-Base-Mega-Map-Index.md for the control-by-control map to sibling-directory deep-dives.
Structure
AI-Governance/├── README.md # This file├── standards/ # Normative deep-dives (ISO/IEC SC 42, NIST AI RMF, EU AI Act)├── frameworks/ # Governance implementation layer│ ├── controls/ # Control frameworks, incident response, monitoring, registry, transparency templates│ ├── risk-management/ # Risk appetite statement, risk register templates│ ├── NIST RMF/ # Framework summary, core 100-1 RMF, 600-1 GenAI profile, crosswalks│ ├── OWASP/ # OWASP AI threats/controls libraries│ ├── MIT/ # MIT AI Risk Repository consolidated analysis│ └── The Company Ethos/ # Materials from The Company Ethos (CC BY 4.0): AI use policy, mega-map, risk management, impact assessment checklist└── references/ # Curated external reference extracts ├── anthropic/ # RSP, Clio privacy, third-party testing ├── australian/ # National AI Plan, Responsible AI Index, voluntary safety standard ├── UK/ # UK AISI frontier AI reports ├── US/ # NAIC AI adoption guide ├── International AI Safety/ # International AI safety reporting └── International Standards/ # International AI standards summaryKey Resources
Frameworks
- AI Controls Framework: Comprehensive control implementation guide
- AI Governance Framework: Overall governance structure
- AI Risk Management: Risk assessment and mitigation strategies
- Incident Response: AI incident response procedures
- Monitoring Dashboard: AI system monitoring framework
References
- Anthropic: RSP (Responsible Scaling Policy), Clio privacy, third-party testing guidance
- Australian: National AI Plan, Responsible AI Index, voluntary safety standard
- UK: UK AISI frontier AI and threat reports
- US: NAIC AI adoption guide 2025
- International: AI safety reporting, international standards summaries
Compliance Materials
- ISO Integration: ISO 27001 and 42001 integration matrices
- Risk Registers: AI system risk tracking templates
- System Registry: AI system documentation templates
- Transparency Cards: Client-facing AI transparency documentation
Getting Started
- Review Framework Overview: Start with
frameworks/controls/AI_Governance_Framework_Overview.md - Assess Current State: Use gap analysis templates in the
frameworks/directory - Implement Controls: Follow control frameworks in
frameworks/controls/ - Monitor Compliance: Set up monitoring using dashboard frameworks
Key Documents
Core Frameworks
AI_Governance_Framework_Overview.md- Main governance frameworkAI_Controls_Framework.md- Detailed control implementationAI_Risk_Appetite_Statement.md- Risk tolerance guidelines
Templates
AI_Risk_Register_Template.md- Risk tracking templateAI_System_Registry_Template.md- System documentation templateClient_AI_Transparency_Card_Template.md- Client transparency template
Implementation
Implementation_Roadmap.md- Governance implementation guideAI_Incident_Response_Procedure.md- Incident response proceduresAI_Monitoring_Dashboard_Framework.md- Monitoring setup guide
Compliance Standards
This module supports compliance with:
- ISO 27001: Information security management
- ISO 42001: AI management systems
- Australian AI Standards: Voluntary and mandatory guidelines
- Industry Best Practices: Anthropic RSP, responsible AI principles
Usage Guidelines
For Organizations
- Adapt frameworks to organizational context
- Customize templates for specific use cases
- Implement monitoring and controls incrementally
- Regular review and updates based on regulatory changes
For Development Teams
- Integrate AI governance into development lifecycle
- Use risk assessment templates for new AI systems
- Implement required controls and monitoring
- Document AI systems using provided templates
Contributing
When contributing to AI governance resources:
- Ensure compliance with current regulations
- Reference authoritative sources
- Provide practical implementation guidance
- Update related templates and frameworks
- Maintain consistency with existing structure
License
Governance frameworks and templates are provided under applicable organizational licenses. Reference materials maintain their original licensing.