AI governance framework
An AI governance framework you can actually enforce
Most frameworks stop at documents. A working one connects policy to evidence: every AI system is registered, tested against real attacks, assessed for impact, and blocked from release until the evidence meets your thresholds.
The six layers
Each layer feeds the next, in this order — so approval always rests on what came before.
1. Strategy & policies
Set direction and rules: an AI strategy, acceptable-use, human-oversight, transparency and data policies, each with an owner, version and review date.
2. Risk register
Record every risk for each AI system with probability, severity and a mitigation — eliminate, substitute or isolate.
3. Impact assessment
A fundamental-rights impact assessment (FRIA) covering the system, affected people, equity and necessity, submitted and approved before release.
4. Adversarial testing
120 control tests across 10 risk domains — prompt injection, jailbreak, data leakage, bias, toxicity, hallucination, system-prompt extraction, unsafe output, excessive agency and resource abuse.
5. AI security review
A security checklist that can only be approved when the latest test run passes every security domain.
6. Deployment gates
Inception, engineering and pre-deployment sign-offs. The final gate stays locked until the risk register, impact assessment and security review are all approved.
Two thresholds, one verdict
Every control domain is scored against two bars: the AI Regulatory Baseline (the minimum a regulator expects) and your Internal AI Targets (the stricter bar you set). A system can pass the law and still miss your own standard — the framework shows both, test by test.
Mapped to the standards you answer to
EU AI Act
Risk management (Art. 9), data governance (Art. 10), human oversight (Art. 14), accuracy and robustness (Art. 15), FRIA (Art. 27)
ISO/IEC 42001
AI management system: policy, risk assessment, impact assessment, operational controls and continual improvement
NIST AI RMF
Govern, Map, Measure and Manage functions
GDPR
Lawfulness and accuracy (Art. 5), automated decisions (Art. 22), security of processing (Art. 32)
OWASP LLM Top 10 & MITRE ATLAS
Technical attack coverage for language-model applications
Also mapped: US OMB M-24-10, UK DSIT principles, HIPAA and SOC 2 — 10 frameworks in total.
Put the framework to work
Register your first AI system and run its first assessment in minutes.

