AI Governance Framework
Knowledge Reference
43
Controls
4
Source Frameworks
6
Lifecycle Domains
2
Assessment Tiers
Quick Links
All 43 Controls
Browse controls with audit checklists
4 Source Frameworks
ISO 42001, NIST AI RMF, OWASP
Quick Reference
Implementation roadmap guide
Audit Checklists
Per-control verification and evidence
Cross-Reference Matrix
Framework-to-control mapping
Search
Find any control, framework, or guidance
Lifecycle Domains
| Domain | Description | Tier 1 | Tier 2 | Total |
|---|---|---|---|---|
| GOVERN | Establish organizational structure, policies, roles, accountability, and risk appetite for AI systems. | 4 | 3 | 7 |
| BUILD | Ensure AI systems are developed, integrated, and tested with security, quality, and compliance built into the pipeline from day one. | 4 | 3 | 7 |
| SECURE | Implement AI-specific threat detection, vulnerability management, and adversarial resilience across all AI systems and agent architectures. | 4 | 4 | 8 |
| DEPLOY | Manage safe, versioned, and auditable deployment of AI models and agent systems with rollback capabilities and environment isolation. | 4 | 3 | 7 |
| MONITOR | Continuously observe AI system behavior, detect drift, measure fairness, and maintain audit trails for regulatory compliance and incident response. | 4 | 3 | 7 |
| IMPROVE | Drive maturity through structured reviews, gap analysis, post-incident learning, and continuous alignment with evolving frameworks and organizational goals. | 4 | 3 | 7 |