Enterprise AI Governance

Enterprise AI Governance

A practical reference library for governing enterprise AI and agentic systems — the major regimes (EU AI Act, ISO/IEC 42001, NIST AI RMF) and a hands-on agentic-AI governance checklist, each with scope, key requirements, implementable controls, a checklist and common pitfalls. Built for people and AI agents.

The Agentic Control Matrix

Framework

5
GOV-003Framework

NIST AI Risk Management Framework

The NIST AI RMF 1.0 is a voluntary, widely-adopted framework for managing AI risk across the lifecycle. It is organized around four functions — Govern, Map, Measure and Manage — and a set of characteristics of trustworthy AI (valid and reliable, safe, secure and resilient, accountable and transparent, explainable, privacy-enhanced, and fair with harmful bias managed). A companion Generative AI Profile adapts it to GenAI risks. Unlike the EU AI Act it is not law, but it is a common backbone for operational AI governance.

GOV-005Framework

Enterprise AI Governance Framework

An umbrella operating model for governing AI across an organization. It defines the principles, accountability (RACI), AI risk taxonomy, lifecycle gates and policy hierarchy that keep AI use lawful, safe and aligned with risk appetite. It harmonizes the EU AI Act, ISO/IEC 42001 and NIST AI RMF into one internal program — comply once, reuse everywhere — and composes the agentic governance checklist as its concrete control set. Use it to give every production AI system a named owner, a risk tier and a gate that can actually block a non-compliant deployment.

GOV-006Framework

Audit Framework for Agentic Systems

A practical, vendor-neutral framework for making an agent auditable and for auditing it. It defines the evidence an independent reviewer needs — immutable, correlated traces of every decision and tool call, model and version provenance, evaluation reports, approval and incident records — and how to test controls and sample high-volume runs. Each evidence type maps to ISO/IEC 42001 and NIST AI RMF so an auditor can verify the agent stayed within its governed bounds. Use it to design auditability in from the start, not as an afterthought.

GOV-008Framework

OWASP Top 10 for LLM Applications

The OWASP Top 10 for LLM Applications is the shared vocabulary for what goes wrong in systems built on language models. It is not a control framework and does not tell you what to implement — it names the vulnerability classes, from prompt injection through excessive agency to unbounded consumption, so that teams, auditors and vendors can argue about the same things. Its practical value is as a checklist over your own architecture and as the common language in which findings get reported.

GOV-009Framework

MITRE ATLAS

MITRE ATLAS is the adversary's side of the map. Where OWASP names the vulnerability classes in your application, ATLAS catalogues the tactics and techniques attackers actually use against AI-enabled systems — reconnaissance of a model, gaining access to it, staging an attack, evading defences, exfiltrating data — organised the way MITRE ATT&CK organises conventional intrusions, and grounded in documented case studies rather than hypotheses.