AI Governance
Governance is the artifact you hand a risk committee, not a policy nobody can evidence.
Who this is for
Risk, compliance, and governance owners mapping AI systems to a framework.
What you should be able to do
Map a deployment to NIST AI RMF and ISO/IEC 42001 control by control, with evidence.
The delivery flow
The order the work actually happens in. Each step is where a decision gets made and written down, not a chapter heading.
- System register
- Ownership + accountability
- Risk classification
- Control mapping
- Evidence collection
- Approval workflow
- Periodic review
- Audit pack
Reading path
9 published guides on this track. Every one is a live page on this site — nothing here is a placeholder.
- AI Compliance in 2026: HIPAA, FedRAMP, and GDPR for ML Systems
- A Phased Governance Rollout for AI Agents: Crawl, Walk, Run
- AI Governance for the Enterprise: A Practical Framework
- AI for Healthcare in Africa: HIPAA Meets NDPR
- AWS Security Audit Kit – Free — Citadel Cloud Management
- Audit Trails for AI Agents: Making Every Action Attributable
- FedRAMP Cloud Services — Compliant Solutions
- Mapping AI Agent Deployments to ISO/IEC 42001 and NIST AI RMF
- SOC 2 Type II for SaaS Products: The Developer's Playbook
Reference implementations
Citadel’s open-source repositories for this track — Terraform modules, MCP servers, and reference architectures you can read, fork, and run. Apache/MIT licensed; check each repository for its terms.
- GitHubmulti-industry-ai-assistantHIPAA/SOX/OSHA AI assistant for Healthcare, Finance, Oil & Gas. Plugin architecture, PII detection, NLI faithfulness validation, audit logging. FastAPI + Python.multi-industry-ai-assistant on github.com (external site, opens in a new tab)
- GitHubterraform-aws-security-baselineAWS security baseline module with GuardDuty, Security Hub, Config, CloudTrail, Macie, and Access Analyzerterraform-aws-security-baseline on github.com (external site, opens in a new tab)
- GitHubai-agent-soc-triageAI-powered SOC alert triage agent with MITRE ATT&CK classification, severity scoring, and automated response playbooksai-agent-soc-triage on github.com (external site, opens in a new tab)
Primary sources
The standards, framework documents, and vendor references this track is built against. Go here when you need the authoritative wording rather than a summary — in a security review or an audit, the source is what counts.
- NIST AI Risk Management Framework (external site, opens in a new tab)
- EU AI Act full text (external site, opens in a new tab)
- NIST SP 800-53 security controls (external site, opens in a new tab)
- FedRAMP (external site, opens in a new tab)
- ISO/IEC 42001 AI management systems (external site, opens in a new tab)
- ISO/IEC 27001 information security (external site, opens in a new tab)