
A comprehensive framework for governing artificial intelligence across your organisation — from risk classification and regulatory compliance to ethical oversight and continuous monitoring. Built for executives who need clarity, structure, and evidence-based control.
"AI governance is not about limiting innovation — it is about creating the structured conditions where innovation can happen responsibly, accountably, and at scale."
AI Governance is the system of rules, practices, processes, and organisational structures by which an organisation directs, manages, and controls its development and use of artificial intelligence. It spans legal compliance, risk management, ethical oversight, and operational accountability.
Effective AI governance ensures that AI systems are deployed in ways that are lawful, fair, transparent, and aligned with organisational values — while enabling innovation rather than blocking it.
Meet regulatory requirements across jurisdictions
Identify, assess, and mitigate AI-specific risks
Explain AI decisions to stakeholders and regulators
Clear roles, ownership, and decision trails
A governance framework provides the structural foundation for how your organisation manages AI. These six pillars form an integrated system that covers the full scope of responsible AI oversight.
Board-level AI policy, executive sponsorship, governance charter, and strategic alignment. Defines why and how the organisation governs AI.
Systematic identification, assessment, classification, and mitigation of AI risks. Includes risk registers, scoring methodologies, and treatment plans.
Documented rules that govern AI development, procurement, deployment, and use. Policies create consistency and set non-negotiable guardrails.
Continuous observation of AI systems in production. Tracks performance, drift, incidents, and compliance status with automated alerting.
Principles-driven oversight ensuring AI systems respect human rights, fairness, and societal values. Goes beyond legal compliance to ethical alignment.
Adherence to applicable laws and standards including the EU AI Act, GDPR, sector-specific regulations, and voluntary frameworks like ISO/IEC 42001.
AI governance operates within a rapidly evolving regulatory environment. Understanding which frameworks apply to your organisation is the first step to compliance.
The world's first comprehensive AI regulation. It classifies AI systems by risk level and imposes strict requirements on high-risk applications.
2 February 2025 — Prohibited AI practices banned
2 August 2025 — GPAI model obligations active
2 August 2026 — High-risk system requirements enforceable
2 August 2027 — Full enforcement for all categories
The General Data Protection Regulation applies wherever personal data is processed by AI systems — which is almost always.
Where both regimes apply, organisations must satisfy both simultaneously. A FRIA under the AI Act and a DPIA under GDPR should be coordinated, not duplicated. The same governance infrastructure can serve both.
The international standard for AI management systems. Provides a certifiable framework for establishing, implementing, maintaining, and improving AI governance.
Certification demonstrates to regulators, customers, and investors that your AI governance is independently verified against an internationally recognised standard. It provides a structured path to compliance and can significantly reduce regulatory inspection friction.
A voluntary US framework for managing risks in the design, development, deployment, and use of AI systems. Structured around four core functions.
NIST AI RMF is voluntary and principle-based, while the EU AI Act is legally binding and prescriptive. Organisations operating in both jurisdictions should use NIST as a foundation and the AI Act as the compliance baseline. The frameworks are complementary, not competing.
MiFID II, Solvency II, ECB guidance on AI. Model risk management (SR 11-7), explainability requirements for credit decisions.
MDR/IVDR for AI medical devices, HIPAA (US), clinical evidence requirements, SaMD frameworks from IMDRF.
Equal opportunity and anti-discrimination laws, automated employment decision tools (NYC Local Law 144), worker consultation rights.
Under the EU AI Act and leading governance frameworks, AI systems are classified by their potential impact on fundamental rights, safety, and society. Each tier carries different compliance obligations.
| Risk Tier | Definition | Examples | Obligations |
|---|---|---|---|
| Prohibited | AI practices deemed unacceptable risk | Social scoring by governments, real-time biometric ID in public spaces, emotion recognition in schools/workplaces, AI that exploits vulnerabilities | Must cease. No compliance path. Immediate ban. |
| High Risk | AI systems that can significantly affect safety or fundamental rights | Recruitment AI, credit scoring, medical diagnosis AI, education grading, justice/risk assessment, critical infrastructure management | Conformity assessment, FRIA, risk management, data governance, transparency, human oversight, accuracy testing, CE marking, post-market monitoring |
| Limited Risk | AI with specific transparency obligations | Chatbots, AI-generated content (deepfakes), emotion recognition systems | Clear disclosure to users that they are interacting with AI. Labelling of synthetic content. |
| Minimal Risk | All other AI systems | Spam filters, AI-enabled video games, inventory management, recommendation systems (non-sensitive) | No mandatory requirements. Voluntary codes of conduct encouraged. |
| GPAI | General-Purpose AI Models | GPT-4, Claude, Gemini, Llama, Mistral | Transparency docs, systemic risk evaluation (high-compute), model weights security, incident reporting |
Deployers of high-risk AI systems must conduct a FRIA before deployment. This assessment evaluates the potential impact on fundamental rights including privacy, non-discrimination, data protection, and freedom of expression. The FRIA should be integrated with your existing DPIA process under GDPR to avoid duplication and ensure consistency.
Governance is not a one-time exercise. It is a continuous lifecycle that follows AI systems from conception through retirement. Each phase has distinct governance activities, deliverables, and decision gates.
Define the AI use case, business case, and strategic alignment. Complete the intake questionnaire to trigger governance workflows.
Classify the AI system according to the EU AI Act risk tiers. Determine which compliance obligations apply.
Embed governance into the development process. Data governance, model documentation, and ethics review occur here.
Conduct FRIA/DPIA, conformity assessment, and final review before deployment authorisation.
Deploy with human oversight, transparency measures, and logging enabled. Monitor from day one.
Continuous monitoring of model performance, drift, bias, and compliance. Regular review cycles.
Internal and external audit of AI governance controls. Regulatory reporting where required.
Decommission or significantly update the AI system. Ensure proper data handling and stakeholder communication.
Clear accountability is essential. Every AI governance framework needs defined roles with specific responsibilities across the three lines of defence model.
1st Line — Ownership
2nd Line — Oversight
2nd Line — Execution
2nd Line — Privacy
Advisory
3rd Line — Assurance
Written policies are the backbone of demonstrable governance. Regulators and auditors look for documented rules that are actually followed. These are the core policies every AI-governed organisation needs.
Defines what AI tools and use cases are permitted, prohibited, or require approval. Covers employee use of public AI (ChatGPT, Copilot), approved tool lists, data input restrictions, and the approval workflow for new AI applications.
The step-by-step methodology for classifying AI systems under the EU AI Act and internal risk frameworks. Includes assessment criteria, decision trees, role assignments, and documentation requirements.
Templates and workflows for conducting FRIAs on high-risk AI systems. Aligned with both EU AI Act requirements and GDPR DPIA processes to maximise efficiency.
Requires Model Cards and System Cards for all AI systems in production. Standardises documentation so models can be understood, audited, and transferred.
Defines how to identify, classify, respond to, and report AI-related incidents. Includes serious incident reporting to regulators and post-incident review.
Governs the procurement of AI-powered products and services from vendors. Ensures due diligence covers compliance, security, data handling, and contractual protections.
Specifies where and how humans must remain in the loop for AI-driven decisions. Defines intervention rights, override procedures, and training requirements.
Ensures all relevant staff understand AI governance requirements, their responsibilities, and how to identify and escalate AI-related risks.
Legal compliance is the floor, not the ceiling. Responsible AI ensures your systems operate ethically, fairly, and transparently — building trust with users, employees, and society.
Users and stakeholders can understand how AI makes decisions
AI systems do not discriminate or produce biased outcomes
Clear ownership and responsibility for AI decisions and outcomes
Humans retain meaningful control over AI-driven decisions
What gets measured gets managed. These metrics provide the Board and governance team with objective evidence that AI governance is functioning effectively.
Building AI governance is a phased journey. This roadmap provides a practical sequence from foundational setup through mature, audited governance operations.
Governance that relies on manual processes and scattered documents will fail under scrutiny. The right technology enables scalable, evidence-based AI governance that operates continuously without manual intervention.
A structured document repository for all governance artefacts — FRIAs, Model Cards, policies, audit reports, and incident records.
Centralised inventory of all AI systems with risk classification, ownership, status, and linked documentation.
Automated monitoring of model performance, compliance status, and governance metrics with alerting.
Running AI governance inside Microsoft 365 — using SharePoint for the Evidence Vault, Teams for collaboration, Purview for data governance and compliance, Lists for the Model Registry, and Copilot Studio for governance assistants — means governance lives where your organisation already works. No new vendor relationships, no adoption friction, and full data sovereignty within your existing tenant.
Whether you are preparing for the EU AI Act, pursuing ISO/IEC 42001 certification, or building governance from the ground up — structured, evidence-based governance is achievable inside your existing Microsoft 365 environment.
© Executive Shield Partners. This guide is provided for informational purposes and does not constitute legal advice. Consult qualified legal counsel for advice specific to your organisation.