AI governance framework

An AI governance framework you can actually enforce

Most frameworks stop at documents. A working one connects policy to evidence: every AI system is registered, tested against real attacks, assessed for impact, and blocked from release until the evidence meets your thresholds.

The six layers

Each layer feeds the next, in this order — so approval always rests on what came before.

1. Strategy & policies

Set direction and rules: an AI strategy, acceptable-use, human-oversight, transparency and data policies, each with an owner, version and review date.

2. Risk register

Record every risk for each AI system with probability, severity and a mitigation — eliminate, substitute or isolate.

3. Impact assessment

A fundamental-rights impact assessment (FRIA) covering the system, affected people, equity and necessity, submitted and approved before release.

4. Adversarial testing

120 control tests across 10 risk domains — prompt injection, jailbreak, data leakage, bias, toxicity, hallucination, system-prompt extraction, unsafe output, excessive agency and resource abuse.

5. AI security review

A security checklist that can only be approved when the latest test run passes every security domain.

6. Deployment gates

Inception, engineering and pre-deployment sign-offs. The final gate stays locked until the risk register, impact assessment and security review are all approved.

Two thresholds, one verdict

Every control domain is scored against two bars: the AI Regulatory Baseline (the minimum a regulator expects) and your Internal AI Targets (the stricter bar you set). A system can pass the law and still miss your own standard — the framework shows both, test by test.

Mapped to the standards you answer to

EU AI Act

Risk management (Art. 9), data governance (Art. 10), human oversight (Art. 14), accuracy and robustness (Art. 15), FRIA (Art. 27)

ISO/IEC 42001

AI management system: policy, risk assessment, impact assessment, operational controls and continual improvement

NIST AI RMF

Govern, Map, Measure and Manage functions

GDPR

Lawfulness and accuracy (Art. 5), automated decisions (Art. 22), security of processing (Art. 32)

OWASP LLM Top 10 & MITRE ATLAS

Technical attack coverage for language-model applications

Also mapped: US OMB M-24-10, UK DSIT principles, HIPAA and SOC 2 — 10 frameworks in total.

Put the framework to work

Register your first AI system and run its first assessment in minutes.