Free AI governance resources — Quick Check, Risk Assessment and Acceptable Use Policy.Explore free resources
AI governance framework

Build AI governance as an operating system — not a policy folder.

An AI governance framework defines how an organisation knows what AI it uses, who owns the decisions, how risks are assessed, what needs approval, which controls and evidence are required, and how AI use is reviewed over time.

DEFINITION

What is an AI governance framework?

An AI governance framework is the repeatable operating model an organisation uses to govern AI across its lifecycle. It turns broad principles such as accountability, safety, privacy and human oversight into named owners, approval routes, controls, evidence and review routines.

Visibility

✓ Know which AI systems and use cases exist.

✓ Identify owners, affected people, data and dependencies.

Decisions

✓ Apply consistent intake, risk and approval rules.

✓ Escalate higher-impact or uncertain uses.

Evidence

✓ Keep records of controls, approvals, incidents and training.

✓ Review the system and improve it as AI use changes.

Practical test: if a manager asks “Which AI are we using, who approved it, what could go wrong, what controls are in place and when will we review it?”, your governance framework should make the answer easy to produce.

Framework vs policy vs risk framework vs management system

TermPrimary purposeWhat it gives you
AI policySet rules and expectations.What people may or may not do with AI.
AI governance frameworkDefine the operating model.Roles, inventory, approvals, risk, controls, evidence, incidents and review.
AI risk frameworkStructure risk identification and treatment.A consistent method for understanding, measuring and managing AI risk.
AI management systemManage AI through a formal management-system structure.Policies, objectives, processes, responsibilities, monitoring and continual improvement.

These concepts overlap. Organisations often combine them rather than choosing only one.

CORE COMPONENTS

Seven layers of a practical AI governance framework

The exact design varies by organisation, but these seven layers cover the decisions and evidence most teams need.

1 · Scope and principles

Define which AI systems, third-party tools, embedded AI features and use cases are covered. Set a small number of decision principles such as accountability, proportionality, privacy, security, human oversight and evidence.

2 · Ownership and accountability

Name the governance owner, business owner, specialist reviewers and approvers. Keep accountability with people even when AI performs automated work.

3 · AI inventory

Maintain a usable record of systems and material use cases: owner, purpose, data, vendor, status, approval, risk, controls and review date.

4 · Intake and approval

Create a repeatable route for new tools and use cases. Low-impact uses may follow a light process; sensitive or consequential uses should trigger deeper review.

5 · Risk assessment and controls

Assess the real use case, not just the vendor. Consider data, people, decisions, accuracy, security, fairness, dependency, legal exposure and operational impact. Record controls and residual risk.

6 · Operation and evidence

Put policy into practice through approved tools, human oversight, output verification, vendor controls, incident handling, access controls, training and evidence that controls actually operate.

7 · Monitoring and review

Review incidents, exceptions, new tools, material changes, overdue actions, training, risk and governance metrics. Update the framework when the organisation or AI landscape changes.

IMPLEMENTATION

How to build an AI governance framework in six steps

1 · Establish ownershipAssign one accountable governance owner and define specialist escalation.
2 · Inventory AIRecord current tools and the material use cases they support.
3 · Set rulesPublish acceptable-use and data-handling rules that staff can follow.
4 · Assess & approveUse proportional risk assessment and a documented approval route.
5 · Operate controlsImplement oversight, verification, vendor, incident and training controls.
6 · Review & improveRun recurring governance review and update the framework using evidence.
For SMEs: keep the number of roles and forms small. Lightweight governance should reduce ambiguity, not create a miniature bureaucracy. One person can hold several roles, but the decisions, evidence and escalation routes should still be clear.
REFERENCE POINTS

How recognised AI frameworks fit into your operating model

You do not need to invent AI governance from zero. Use recognised references to shape your framework, then adapt the operating model to your size, sector, jurisdictions and risk profile.

NIST AI Risk Management Framework

NIST AI RMF 1.0 is voluntary, non-sector-specific and use-case-agnostic. Its four functions — Govern, Map, Measure and Manage — provide a useful structure for AI risk management and can be applied by organisations of different sizes.

NIST AI Risk Management Framework →

ISO/IEC 42001

ISO/IEC 42001:2023 specifies requirements for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System. It is applicable to organisations that provide or use AI-based products or services.

ISO/IEC 42001 overview →

OECD AI Principles

The OECD AI Principles provide internationally recognised principles for innovative and trustworthy AI. They are useful as a principles layer, while an organisational governance framework still needs concrete roles, controls, decisions and evidence.

OECD AI Principles →

Regulation is an additional layer. Standards and voluntary frameworks do not replace applicable law. Map the jurisdictions, sectors and use cases relevant to your organisation and obtain specialist advice where required.

Free tools to start implementing the framework

You can start with one control today and build from there.

FROM FRAMEWORK TO SYSTEM

Need the controls connected into one operating model?

Evidelis AI Governance combines policies, inventory, tool approval, use-case risk assessment, vendor review, human oversight, incidents, AI literacy evidence, regulatory screening and management review in editable Word and Excel files.

The core operating model can be adapted internationally. The current edition includes EU-focused regulatory screening, so organisations elsewhere should map local legal and sector requirements separately.

Evidelis AI Governance | EU Edition

€129

One-time purchase · Single Organisation License · editable Word + Excel.

Get Evidelis AI Governance

Frequently asked questions

What is an AI governance framework?

An AI governance framework is a repeatable operating model that defines who is accountable for AI, which systems and use cases are in scope, how risk and approval decisions are made, which controls and evidence are required, and how AI use is reviewed over time.

Is an AI policy the same as an AI governance framework?

No. A policy states rules and expectations. A framework connects those rules to ownership, inventory, approvals, risk assessment, controls, evidence, incidents and recurring review.

Can a small business use an AI governance framework?

Yes. A smaller organisation can keep the framework lightweight. The aim is not to create more bureaucracy; it is to make ownership, decisions, controls and evidence repeatable.

How do NIST AI RMF and ISO/IEC 42001 relate to AI governance?

NIST AI RMF provides a voluntary risk-management structure organised around Govern, Map, Measure and Manage. ISO/IEC 42001 specifies requirements for an AI management system. Both can inform an organisation's governance design, alongside applicable law and sector requirements.