Executive Guide

AI Governance

A comprehensive framework for governing artificial intelligence across your organisation — from risk classification and regulatory compliance to ethical oversight and continuous monitoring. Built for executives who need clarity, structure, and evidence-based control.

EU AI Act Ready
ISO/IEC 42001
NIST AI RMF
Board-Aligned
AI Governance Dashboard
Live Compliance Status
Risk Classification High-Risk Systems
EU AI Act Status Compliant
FRIA Coverage Complete
Model Inventory 12 Pending Review
Last Audit Q2 2026 — Passed
Governance Score 94/100

"AI governance is not about limiting innovation — it is about creating the structured conditions where innovation can happen responsibly, accountably, and at scale."

01 — Foundation

What Is AI Governance?

AI Governance is the system of rules, practices, processes, and organisational structures by which an organisation directs, manages, and controls its development and use of artificial intelligence. It spans legal compliance, risk management, ethical oversight, and operational accountability.

Effective AI governance ensures that AI systems are deployed in ways that are lawful, fair, transparent, and aligned with organisational values — while enabling innovation rather than blocking it.

Why It Matters Now

  • The EU AI Act is in effect — penalties up to €35 million or 7% of global turnover
  • Customers, investors, and partners increasingly demand AI transparency
  • Un governed AI creates legal, financial, and reputational risk
  • Board accountability for AI decisions is becoming a fiduciary duty

Compliance

Meet regulatory requirements across jurisdictions

Risk Control

Identify, assess, and mitigate AI-specific risks

Transparency

Explain AI decisions to stakeholders and regulators

Accountability

Clear roles, ownership, and decision trails

02 — Structure

The AI Governance Framework

A governance framework provides the structural foundation for how your organisation manages AI. These six pillars form an integrated system that covers the full scope of responsible AI oversight.

1. Strategy & Leadership

Board-level AI policy, executive sponsorship, governance charter, and strategic alignment. Defines why and how the organisation governs AI.

  • AI Governance Charter
  • Board AI Policy Statement
  • Executive Sponsor Assignment
  • Budget & Resource Allocation

2. Risk Management

Systematic identification, assessment, classification, and mitigation of AI risks. Includes risk registers, scoring methodologies, and treatment plans.

  • AI Risk Register
  • Risk Classification Matrix
  • FRIA Process (EU AI Act)
  • Risk Treatment & Monitoring

3. Policies & Standards

Documented rules that govern AI development, procurement, deployment, and use. Policies create consistency and set non-negotiable guardrails.

  • Acceptable Use Policy
  • Model Development Standards
  • Data Governance for AI
  • Third-Party AI Procurement Rules

4. Oversight & Monitoring

Continuous observation of AI systems in production. Tracks performance, drift, incidents, and compliance status with automated alerting.

  • Model Performance Dashboards
  • Drift & Bias Detection
  • Incident Response Protocols
  • Regular Compliance Audits

5. Ethics & Responsible AI

Principles-driven oversight ensuring AI systems respect human rights, fairness, and societal values. Goes beyond legal compliance to ethical alignment.

  • Ethics Review Board
  • Fairness & Bias Testing
  • Human-in-the-Loop Requirements
  • Stakeholder Impact Assessment

6. Regulatory Compliance

Adherence to applicable laws and standards including the EU AI Act, GDPR, sector-specific regulations, and voluntary frameworks like ISO/IEC 42001.

  • EU AI Act Conformity
  • GDPR Article 22 (Automated Decisions)
  • ISO/IEC 42001 Certification
  • NIST AI Risk Management Framework
03 — Compliance

Global Regulatory Landscape

AI governance operates within a rapidly evolving regulatory environment. Understanding which frameworks apply to your organisation is the first step to compliance.

EU Artificial Intelligence Act

The world's first comprehensive AI regulation. It classifies AI systems by risk level and imposes strict requirements on high-risk applications.

  • Prohibited AI: Social scoring, manipulation, biometric categorisation
  • High-Risk: HR, credit, education, justice, critical infrastructure
  • General-Purpose AI: Transparency, systemic risk evaluations
  • Limited Risk: Chatbot disclosure obligations
  • Penalties: Up to €35M or 7% global turnover

Key Deadlines

2 February 2025 — Prohibited AI practices banned

2 August 2025 — GPAI model obligations active

2 August 2026 — High-risk system requirements enforceable

2 August 2027 — Full enforcement for all categories

GDPR & AI

The General Data Protection Regulation applies wherever personal data is processed by AI systems — which is almost always.

  • Article 22: Right not to be subject to solely automated decisions with legal/significant effects
  • Article 13-14: Transparency about automated decision-making
  • Article 25: Data protection by design and default
  • Article 35: DPIA required for high-risk processing (including AI profiling)
  • Article 5: Lawfulness, fairness, purpose limitation

GDPR + AI Act Overlap

Where both regimes apply, organisations must satisfy both simultaneously. A FRIA under the AI Act and a DPIA under GDPR should be coordinated, not duplicated. The same governance infrastructure can serve both.

ISO/IEC 42001:2023

The international standard for AI management systems. Provides a certifiable framework for establishing, implementing, maintaining, and improving AI governance.

  • Context: Understanding org and stakeholder needs
  • Leadership: Management commitment and roles
  • Planning: Risk/opportunity assessment for AI
  • Support: Resources, competence, awareness
  • Operations: AI system lifecycle management
  • Evaluation: Monitoring, measurement, audit
  • Improvement: Corrective action and continuous refinement

Why Pursue ISO/IEC 42001?

Certification demonstrates to regulators, customers, and investors that your AI governance is independently verified against an internationally recognised standard. It provides a structured path to compliance and can significantly reduce regulatory inspection friction.

NIST AI Risk Management Framework

A voluntary US framework for managing risks in the design, development, deployment, and use of AI systems. Structured around four core functions.

  • Govern (GV): Cultures and processes for risk management
  • Map (MP): Context and risk identification
  • Measure (ME): Quantitative and qualitative assessment
  • Manage (MG): Risk treatment and response

NIST vs. EU AI Act

NIST AI RMF is voluntary and principle-based, while the EU AI Act is legally binding and prescriptive. Organisations operating in both jurisdictions should use NIST as a foundation and the AI Act as the compliance baseline. The frameworks are complementary, not competing.

Sector-Specific Requirements

Financial Services

MiFID II, Solvency II, ECB guidance on AI. Model risk management (SR 11-7), explainability requirements for credit decisions.

Healthcare

MDR/IVDR for AI medical devices, HIPAA (US), clinical evidence requirements, SaMD frameworks from IMDRF.

Employment / HR

Equal opportunity and anti-discrimination laws, automated employment decision tools (NYC Local Law 144), worker consultation rights.

04 — Risk

AI Risk Classification

Under the EU AI Act and leading governance frameworks, AI systems are classified by their potential impact on fundamental rights, safety, and society. Each tier carries different compliance obligations.

Risk Tier Definition Examples Obligations
Prohibited AI practices deemed unacceptable risk Social scoring by governments, real-time biometric ID in public spaces, emotion recognition in schools/workplaces, AI that exploits vulnerabilities Must cease. No compliance path. Immediate ban.
High Risk AI systems that can significantly affect safety or fundamental rights Recruitment AI, credit scoring, medical diagnosis AI, education grading, justice/risk assessment, critical infrastructure management Conformity assessment, FRIA, risk management, data governance, transparency, human oversight, accuracy testing, CE marking, post-market monitoring
Limited Risk AI with specific transparency obligations Chatbots, AI-generated content (deepfakes), emotion recognition systems Clear disclosure to users that they are interacting with AI. Labelling of synthetic content.
Minimal Risk All other AI systems Spam filters, AI-enabled video games, inventory management, recommendation systems (non-sensitive) No mandatory requirements. Voluntary codes of conduct encouraged.
GPAI General-Purpose AI Models GPT-4, Claude, Gemini, Llama, Mistral Transparency docs, systemic risk evaluation (high-compute), model weights security, incident reporting

Fundamental Rights Impact Assessment (FRIA)

Deployers of high-risk AI systems must conduct a FRIA before deployment. This assessment evaluates the potential impact on fundamental rights including privacy, non-discrimination, data protection, and freedom of expression. The FRIA should be integrated with your existing DPIA process under GDPR to avoid duplication and ensure consistency.

05 — Process

AI Governance Lifecycle

Governance is not a one-time exercise. It is a continuous lifecycle that follows AI systems from conception through retirement. Each phase has distinct governance activities, deliverables, and decision gates.

Phase 01

Strategy & Intake

Define the AI use case, business case, and strategic alignment. Complete the intake questionnaire to trigger governance workflows.

  • AI Use Case Intake Form
  • Business Case Documentation
  • Initial Risk Screening
  • Stakeholder Identification
Phase 02

Risk Classification

Classify the AI system according to the EU AI Act risk tiers. Determine which compliance obligations apply.

  • Risk Tier Assessment
  • Regulatory Scope Analysis
  • Jurisdiction Mapping
  • Compliance Obligation Checklist
Phase 03

Design & Development

Embed governance into the development process. Data governance, model documentation, and ethics review occur here.

  • Model Card Documentation
  • Data Quality & Provenance
  • Bias Testing & Fairness Metrics
  • Ethics Review Gate
Phase 04

Assessment & Approval

Conduct FRIA/DPIA, conformity assessment, and final review before deployment authorisation.

  • Fundamental Rights Impact Assessment
  • DPIA (if personal data involved)
  • Conformity Assessment
  • Board / Committee Approval
Phase 05

Deployment & Operation

Deploy with human oversight, transparency measures, and logging enabled. Monitor from day one.

  • Human-in-the-Loop Configuration
  • Transparency Disclosures
  • Event Logging & Audit Trail
  • User Training & Documentation
Phase 06

Monitoring & Review

Continuous monitoring of model performance, drift, bias, and compliance. Regular review cycles.

  • Performance Dashboards
  • Drift & Degradation Alerts
  • Periodic Re-assessment
  • Incident Tracking
Phase 07

Audit & Reporting

Internal and external audit of AI governance controls. Regulatory reporting where required.

  • Internal Audit Program
  • Regulatory Reporting (e.g., serious incidents)
  • Evidence Vault Maintenance
  • Board Reporting
Phase 08

Retirement / Update

Decommission or significantly update the AI system. Ensure proper data handling and stakeholder communication.

  • Retirement Decision Documentation
  • Data Retention / Deletion
  • Stakeholder Notification
  • Lessons Learned Capture
06 — Organisation

Governance Functions & Roles

Clear accountability is essential. Every AI governance framework needs defined roles with specific responsibilities across the three lines of defence model.

Board / Executive

1st Line — Ownership

  • Approve AI governance policy
  • Appoint AI Governance Lead
  • Set risk appetite
  • Receive regular reporting
  • Approve high-risk AI deployments

AI Governance Committee

2nd Line — Oversight

  • Cross-functional oversight body
  • Review and approve AI use cases
  • Monitor compliance posture
  • Escalate issues to Board
  • Own governance framework updates

AI Governance Lead

2nd Line — Execution

  • Day-to-day governance operations
  • Own policies and procedures
  • Manage AI system inventory
  • Coordinate FRIAs and assessments
  • Report to Committee and Board

Data Protection Officer

2nd Line — Privacy

  • Advise on GDPR compliance for AI
  • Oversee DPIAs
  • Monitor data subject rights
  • Liaise with supervisory authorities
  • Integrate privacy into AI governance

Ethics Review Board

Advisory

  • Review ethically sensitive use cases
  • Assess societal impact
  • Advise on fairness and bias
  • Provide external perspective
  • Recommend policy enhancements

Internal Audit

3rd Line — Assurance

  • Independent assessment of controls
  • Verify compliance evidence
  • Report findings to Board
  • Track remediation actions
  • Annual AI governance audit
07 — Documentation

Essential Policies & Procedures

Written policies are the backbone of demonstrable governance. Regulators and auditors look for documented rules that are actually followed. These are the core policies every AI-governed organisation needs.

AI Acceptable Use Policy

Defines what AI tools and use cases are permitted, prohibited, or require approval. Covers employee use of public AI (ChatGPT, Copilot), approved tool lists, data input restrictions, and the approval workflow for new AI applications.

  • Approved vs. prohibited AI tools
  • Data classification rules for AI input
  • Employee self-service guidelines
  • Approval escalation paths
AI System Risk Classification Procedure

The step-by-step methodology for classifying AI systems under the EU AI Act and internal risk frameworks. Includes assessment criteria, decision trees, role assignments, and documentation requirements.

  • Risk tier determination methodology
  • Decision trees and scoring criteria
  • Reviewer and approver roles
  • Classification register maintenance
Fundamental Rights Impact Assessment (FRIA) Procedure

Templates and workflows for conducting FRIAs on high-risk AI systems. Aligned with both EU AI Act requirements and GDPR DPIA processes to maximise efficiency.

  • FRIA template and guidance
  • DPIA integration workflow
  • Reviewer and sign-off process
  • Re-assessment triggers
AI Model Documentation Standard

Requires Model Cards and System Cards for all AI systems in production. Standardises documentation so models can be understood, audited, and transferred.

  • Model Card template and required fields
  • System Card for end-to-end systems
  • Data Card for training datasets
  • Documentation review and approval
AI Incident Response Procedure

Defines how to identify, classify, respond to, and report AI-related incidents. Includes serious incident reporting to regulators and post-incident review.

  • Incident classification criteria
  • Response team and RACI
  • Regulatory reporting obligations
  • Post-incident review and lessons learned
Third-Party AI Procurement Policy

Governs the procurement of AI-powered products and services from vendors. Ensures due diligence covers compliance, security, data handling, and contractual protections.

  • Vendor AI due diligence checklist
  • Contractual AI clauses
  • Data processing and sovereignty requirements
  • Ongoing vendor monitoring
Human Oversight & Intervention Policy

Specifies where and how humans must remain in the loop for AI-driven decisions. Defines intervention rights, override procedures, and training requirements.

  • Human-in-the-loop requirements by risk tier
  • Override and intervention procedures
  • Competency and training requirements
  • Logging of human decisions
AI Training & Awareness Policy

Ensures all relevant staff understand AI governance requirements, their responsibilities, and how to identify and escalate AI-related risks.

  • Role-based training curriculum
  • Mandatory vs. optional training
  • Completion tracking and reporting
  • Annual refresher requirements
08 — Principles

Responsible AI & Ethics

Legal compliance is the floor, not the ceiling. Responsible AI ensures your systems operate ethically, fairly, and transparently — building trust with users, employees, and society.

Transparency

Users and stakeholders can understand how AI makes decisions

Fairness

AI systems do not discriminate or produce biased outcomes

Accountability

Clear ownership and responsibility for AI decisions and outcomes

Human Agency

Humans retain meaningful control over AI-driven decisions

Fairness Testing Checklist

  • Define protected attributes relevant to context
  • Measure demographic parity across groups
  • Test equalised odds and opportunity
  • Calibrate for individual fairness metrics
  • Document fairness trade-off decisions
  • Re-test after model retraining or update

Explainability Requirements

  • Provide meaningful information to users
  • Document decision logic in plain language
  • Offer recourse paths for adverse decisions
  • Enable human reviewer understanding
  • Maintain explainability evidence
  • Match explanation depth to risk tier
09 — Measurement

Governance Metrics & KPIs

What gets measured gets managed. These metrics provide the Board and governance team with objective evidence that AI governance is functioning effectively.

100%
High-Risk Systems Assessed
<5 days
FRIA Completion Target
0
Open Critical Findings
98%
Staff Training Completion

Compliance Metrics

  • % of AI systems with completed risk classification
  • % of high-risk systems with valid FRIA
  • % of systems with approved Model Cards
  • Days since last compliance audit
  • Open regulatory findings by severity
  • Incident reporting timeliness

Operational Metrics

  • Average time from intake to deployment approval
  • % of AI systems meeting performance SLAs
  • Model drift detection count
  • Human override rate and reasons
  • AI system uptime and availability
  • Cost of governance per AI system

Trust Metrics

  • Employee AI governance training completion
  • Internal audit findings trend
  • User complaints related to AI decisions
  • Third-party audit results
  • Board reporting adherence
  • Policy exception requests and approvals
10 — Execution

Implementation Roadmap

Building AI governance is a phased journey. This roadmap provides a practical sequence from foundational setup through mature, audited governance operations.

Phase 1 — Foundation (Months 1-2)

Establish Governance Structure

  • Board AI governance resolution
  • Appoint AI Governance Lead
  • Form AI Governance Committee
  • Define scope and risk appetite
  • Initial AI system inventory
Phase 2 — Assessment (Months 2-4)

Assess & Classify

  • Complete AI system risk classifications
  • Conduct FRIAs for high-risk systems
  • Map regulatory requirements
  • Identify gaps vs. EU AI Act
  • Baseline maturity assessment
Phase 3 — Build (Months 3-6)

Develop Policies & Infrastructure

  • Draft core policies and procedures
  • Deploy governance technology (M365)
  • Create Model Card templates
  • Build evidence vault structure
  • Establish monitoring dashboards
Phase 4 — Operationalise (Months 5-8)

Launch & Train

  • Policy approval and publication
  • Roll out training program
  • Activate intake and approval workflows
  • Begin continuous monitoring
  • First monthly governance report
Phase 5 — Validate (Months 7-10)

Audit & Improve

  • Internal audit of governance controls
  • Remediate findings
  • Refine policies based on experience
  • Board review and endorsement
  • Prepare for external certification (optional)
Phase 6 — Mature (Ongoing)

Continuous Improvement

  • Quarterly governance reviews
  • Annual comprehensive audit
  • Regulatory horizon scanning
  • Benchmarking and maturity advancement
  • ISO/IEC 42001 certification maintenance
11 — Technology

Governance Technology Stack

Governance that relies on manual processes and scattered documents will fail under scrutiny. The right technology enables scalable, evidence-based AI governance that operates continuously without manual intervention.

Evidence Vault

A structured document repository for all governance artefacts — FRIAs, Model Cards, policies, audit reports, and incident records.

  • SharePoint / Teams native integration
  • Version control and audit history
  • Sensitivity labels and access control
  • Structured metadata for discovery

Model Registry

Centralised inventory of all AI systems with risk classification, ownership, status, and linked documentation.

  • AI system catalog with search
  • Risk tier visual indicators
  • Owner and approver assignment
  • Status workflow automation

Monitoring Layer

Automated monitoring of model performance, compliance status, and governance metrics with alerting.

  • Performance dashboards
  • Compliance scorecards
  • Drift and anomaly alerts
  • Automated reporting

Microsoft 365 Native Approach

Running AI governance inside Microsoft 365 — using SharePoint for the Evidence Vault, Teams for collaboration, Purview for data governance and compliance, Lists for the Model Registry, and Copilot Studio for governance assistants — means governance lives where your organisation already works. No new vendor relationships, no adoption friction, and full data sovereignty within your existing tenant.

Next Steps

Ready to Implement AI Governance?

Whether you are preparing for the EU AI Act, pursuing ISO/IEC 42001 certification, or building governance from the ground up — structured, evidence-based governance is achievable inside your existing Microsoft 365 environment.