17 free courses, no signup wall
Architect-led enterprise cloud, security & AI
Fixed-price engagements, scoped on a discovery call
Skip to content
Governance lead

AI Governance

Governance is the artifact you hand a risk committee, not a policy nobody can evidence.

Who this is for

Risk, compliance, and governance owners mapping AI systems to a framework.

What you should be able to do

Map a deployment to NIST AI RMF and ISO/IEC 42001 control by control, with evidence.

Career ladder

The titles this track maps onto. Levels differ between companies. The useful part is the direction, and what each step adds to the one before it.

  1. Compliance Analyst
  2. AI Governance Specialist
  3. AI Risk Manager
  4. Head of AI Governance
  5. Chief Risk / AI Officer

Tech stack

What the work is actually done with. Grouped by the job each tool does, so the list reads as a system rather than a pile of names.

Frameworks
NIST AI RMFISO/IEC 42001ISO/IEC 27001EU AI Act
Regulated
HIPAAGDPRFedRAMPSOC 2
Practice
Model cardsRisk registerEvidence packsApproval workflow

The delivery flow

The order the work actually happens in. Each step is where a decision gets made and written down, not a chapter heading.

  1. System register
  2. Ownership + accountability
  3. Risk classification
  4. Control mapping
  5. Evidence collection
  6. Approval workflow
  7. Periodic review
  8. Audit pack

Reference repository structure

A starting layout for this track. The directories are the ones that get added late and hurt. Decisions, evals, policy, lineage. Promoted to the top level where they are visible.

ai-governance/
├── register/              # every AI system, with a named owner
├── risk/
│   ├── classification.md  # tiering criteria, applied consistently
│   └── register.csv
├── controls/
│   ├── nist-ai-rmf/       # mapped control by control
│   └── iso-42001/
├── evidence/              # the artifact an auditor actually reads
│   └── <system>/<control>/
├── approvals/             # who signed, when, on what basis
├── model-cards/
└── reviews/               # scheduled, with dates that are kept

Primary sources

The standards, framework documents, and vendor references this track is built against. Go here when you need the authoritative wording rather than a summary. In a security review or an audit, the source is what counts.