AI governance: what it is and how to run it
AI governance is how an organisation decides which AI it uses, who is accountable for each system, and how that is evidenced. In the EU it is no longer a matter of good intentions: the AI Act makes parts of it binding law, and ISO/IEC 42001 supplies the management structure to carry it.
Last updated: 8 September 2026
What binds, and when
What is AI governance?
AI governance is the way an organisation directs and controls its use of artificial intelligence: which systems are permitted, who owns each one, how their risks are assessed and treated, and what evidence exists that any of it actually happened. It is an accountability question before it is a technical one.
It is worth separating three things that get used interchangeably. AI ethics is a set of principles — fairness, transparency, human oversight. Model governance is the engineering discipline around a model: versions, datasets, drift, monitoring. AI governance is the layer that decides who is allowed to answer those questions, and keeps the record. Principles without a named owner and a dated record do not survive an audit, and a well-monitored model in an undocumented process does not either.
In practice a working setup has three parts and rarely more: an inventory of the AI systems actually in use, one accountable person per system, and a record that shows what was decided and when. Everything else — policies, risk registers, impact assessments — hangs off those three.
What governance looks like on screen
Screenshots from the AI Manager, the same screens a live account shows, filled with example data — not a demo account with empty tables.
Portfolio at a glance
See every AI system, its risk class, open risks and the next deadline the moment you open the tool — no report to assemble first.
Plan and deadlines together
A rough timeline to go-live sits next to the recurring reviews it triggers, so a plan and a compliance calendar are the same screen.
Tasks, as a board
The same tasks that show up on the calendar, sorted into planned, open and done — for teams who read a board faster than a list.
Which framework: the AI Act, ISO/IEC 42001 or the NIST AI RMF
They are not alternatives to one another. The AI Act is binding law wherever you place AI on the EU market, ISO/IEC 42001 is a voluntary management-system standard you can be certified against, and the NIST AI Risk Management Framework is a voluntary US framework with no certification behind it.
EU AI Act
Tells you which duties apply to a given system, based on its risk class and your role. It does not tell you how to organise yourself to meet them.
ISO/IEC 42001
Supplies the frame: scope, policy, roles, risk assessment and treatment, a statement of applicability, monitoring, internal audit, management review. Auditable by an accredited body.
NIST AI RMF
A shared vocabulary for describing and treating AI risk. Widely referenced in the United States, and not tied to any EU obligation.
The practical order is the same for most European companies. Start with the AI Act, because it is the only one of the three you can be fined under. Add ISO/IEC 42001 when you need the organisational frame — or when a customer asks for a certificate. Reach for the NIST framework when a US partner or contract asks for it by name.
Why we build on ISO/IEC 42001 and not the NIST AI RMF
The TSMONDO AI Manager implements the EU AI Act and ISO/IEC 42001. It does not implement the NIST AI Risk Management Framework, and there is no mapping to it in the product. If a NIST alignment is what you have been asked to produce, this is not the tool for that job, and we would rather say so here than at the end of a trial.
The reasoning is narrow and it is about fit, not quality. Our customers sell into the EU and are measured against an EU regulation; the standard that an auditor or an insurer here asks to see is ISO/IEC 42001, because it is the one with an accredited certification route behind it. The NIST framework has no certificate, so it cannot close that conversation.
It also has more search demand than most of the terms on this page, which is exactly why the honest answer belongs here rather than a vague section implying coverage we have not built. The overlap in substance is real — identify your systems, assess the risk, treat it, keep the record — so work done for one is rarely wasted for the other. But a mapping is a piece of software, not a sentence, and we have not written it.
Do you need an AI governance platform?
For one or two low-risk systems a spreadsheet and a folder are genuinely enough. A dedicated tool starts to earn its keep at around five systems, or the first time somebody outside the company — an auditor, a customer, an insurer — asks to see the register.
| Where you are | Spreadsheet and folder | Dedicated tool |
|---|---|---|
| One or two systems, all minimal risk | Enough | Not needed yet |
| Five or more systems across several departments | Starts to break | Pays off |
| At least one high-risk system under Annex III | Not realistic | Effectively necessary |
| Recurring reviews and refreshers on fixed dates | Needs a calendar beside it | Built in |
| An auditor or customer asks for the register | Days of assembly | Export on the spot |
| You must show who decided what, and when | Only if you kept versions | Recorded as you go |
What separates a useful AI governance tool from a pretty one is unglamorous: does it produce the documents an auditor asks for, does it keep dates, and does it survive the person who set it up leaving. Ours runs locally on your own machine with no cloud account — see what the AI Manager actually does before you decide whether you need anything at all.
AI governance training: the duty that already applies
Article 4 of the AI Act requires providers and deployers to take measures that support a sufficient level of AI literacy among the staff and other people who operate their AI systems on their behalf. As reworded by Regulation (EU) 2026/1744 it no longer asks you to guarantee a particular level of competence per person. It has applied since 2 February 2025, with no size threshold and no exemption for small companies.
What “sufficient” means is deliberately left open: it depends on which systems are in use, what people do with them, and the consequences if they get it wrong. Somebody drafting marketing copy needs less than somebody letting a model pre-sort job applications.
The part that gets forgotten is not the training, it is the record. A short briefing that nobody wrote down is, for supervisory purposes, a briefing that did not happen. Keep the date, the participants and the topics covered; that is the whole obligation for most companies. The deadlines and duties under the AI Act are set out in more detail on the regulation page.
How to start
- Write down every AI system you actually use — including the ones already embedded in software you licence. Most lists are shorter than feared and longer than expected.
- Give each system one accountable owner — a named person, not a department. This is the single step that most often does not happen.
- Classify the use, not the tool — prohibited, high risk, transparency, or none of these. Most business use lands in the last box, and knowing that shrinks the work.
- Cover the Article 4 literacy duty and keep the record — it already applies and is the cheapest obligation on the list.
- Set the recurring dates before you need them — review, internal audit, management review. A governance system without a calendar is a folder.
Frequently asked questions
What is AI governance?
AI governance is the way an organisation directs and controls its use of artificial intelligence: which systems are permitted, who is accountable for each one, how their risks are assessed and treated, and what evidence exists that it happened. It is distinct from AI ethics, which is a set of principles, and from model governance, which is the engineering practice around a single model.
Is AI governance a legal requirement in the EU?
Parts of it are. The AI Act, Regulation (EU) 2024/1689, makes specific duties binding: the AI literacy obligation in Article 4 since 2 February 2025, the transparency obligations in Article 50 since 2 August 2026, and the high-risk obligations from 2 December 2027. The wider practice of governance is not itself prescribed, but you cannot demonstrate compliance with those duties without it.
What is the difference between the EU AI Act and ISO/IEC 42001?
The AI Act is binding law and states what must be achieved for a given risk class and role. ISO/IEC 42001 is a voluntary management-system standard that states how to organise yourself to achieve it, and can be certified by an accredited body. A certificate does not create a presumption of conformity with the regulation, but the two overlap enough that building the system once is the proportionate route.
Should we use the NIST AI Risk Management Framework instead?
Only if something specific asks you to. The NIST framework is voluntary, has no certification route, and carries no weight under EU law. For a company selling into the EU, ISO/IEC 42001 is the standard an auditor or insurer expects to see. The TSMONDO AI Manager does not implement the NIST framework and offers no mapping to it.
Do we need an AI governance platform?
Not at one or two low-risk systems — a spreadsheet and a folder will do. A tool becomes worthwhile at around five systems, as soon as one system is high-risk under Annex III, or the first time an auditor, customer or insurer asks to see the register and the dates behind it.
Who should own AI governance in a small company?
One named person with the authority to stop a deployment, supported by the owner of each individual system. In companies below roughly 250 staff this is usually an existing role — the person who already handles data protection or information security — rather than a new hire. What matters is that the name is written down.
What does AI governance training have to cover?
Article 4 does not prescribe content. In practice a sufficient briefing covers which AI systems the organisation uses, what they may and may not be used for, where human oversight is required, and how to report a problem. Depth should match the role. Keep the date, the participants and the topics, because the record is the part that is checked.
From a policy nobody reads to a register you can show
The TSMONDO AI Manager takes you through classification, roles, obligations, deadlines and the documents — locally, on your own machine, with no cloud account.