Skip to content
infoloop
infoloop

AI governance framework: a practical checklist

Updated AI7 min read

Checklist of AI governance controls mapped to NIST AI RMF, ISO/IEC 42001 and the EU AI Act

Here is what a framework covers, the policies to write first, and a checklist you can use this quarter.

An AI governance framework is the set of rules, roles and checks that decides how your company builds, buys and uses AI. It names an owner for each AI system, sorts every system by risk, and keeps records that prove the controls work. To start, you need an owner, a full inventory and a risk review.

Key takeaways

  • Start with three things: one named owner, a list of every AI system in use, and a risk tier for each one.
  • Keep each policy short and tie it to evidence, such as an approval record, a test result or a log.
  • Map one set of controls to the frameworks you answer to, such as the NIST AI RMF, ISO/IEC 42001 and the EU AI Act.

This guide answers the questions teams ask most often. It includes a checklist you can adapt as an AI governance framework template. It also maps that work to three frameworks that customers and auditors often ask about.

What is AI governance in simple terms?

AI governance means deciding who may use AI, for which tasks, and how you will know each system is safe and working. It covers models your team builds and AI tools it buys. That includes chat assistants, coding copilots and AI features inside existing software.

A framework writes those decisions down so they survive staff changes, customer questions and audits. Without one, each department makes its own rules. Nobody can then say how many AI systems the company uses or who answers for them.

Governance is also different from an ethics statement. A statement describes what you value. Governance turns those values into steps, owners and records that someone can verify.

What are the pillars of AI governance?

Most AI governance frameworks rest on five pillars: accountability, risk management, transparency, data protection and monitoring. Your AI governance principles are the short rules behind each pillar. One example: “A person reviews every high-risk decision before it takes effect.”

PillarWhat it meansEvidence you keep
AccountabilityEvery AI system has a named owner, and one group approves new usesOwner list, approval records
Risk managementSystems are sorted by the harm they could cause, and checks grow with the riskRisk tier and review notes for each system
TransparencyYou can explain what each system does, what data it uses and where it is usedSystem records, notices to users
Data protectionPersonal and confidential data is handled lawfully and kept secureData sources, access rules, retention periods
MonitoringSystems are checked after launch for accuracy, drift, cost and complaintsDashboards, incident log, review dates

NIST’s AI Risk Management Framework groups this work into four functions called Govern, Map, Measure and Manage. NIST released version 1.0 on January 26, 2023, and organizations may use it voluntarily. NIST added a Generative AI Profile in July 2024 and says it is revising the framework under the White House AI Action Plan. The five pillars fit inside those four functions, so your team can work with whichever view feels clearer.

What are examples of AI governance policies?

Most companies need five to seven short policies rather than one long manual. Each AI governance policy should state what is allowed, who approves exceptions and which record proves the policy was followed.

Common examples:

  • Acceptable use sets which AI tools employees may use and which information must never go into them, such as customer records.
  • Vendor review covers what you check before buying AI software, including where your data goes and whether it trains the vendor’s models.
  • Risk classification explains how each system is placed in a low, medium or high tier, and which checks each tier requires.
  • Human review lists the outputs a person must approve first, such as a maintenance alert that would stop a production line.
  • Testing and release defines the tests a system must pass before launch, and again after every model update or prompt change.
  • Incident response describes how employees report an AI error, who investigates it, and when affected customers are informed.
  • Retirement decides when a system is switched off, and what happens to its data, documentation and records afterward.

The details depend on your industry and on who sees the output. An online store might require a person to check AI-written product claims before they go live. An EdTech platform might require a teacher to confirm any AI-assigned grade before a student sees it. A B2B SaaS company might need a separate policy for AI features that its customers can switch on themselves.

How do you implement an AI governance framework in a large organization?

Start small: name an owner, list every AI system in use, and sort each one by risk before writing detailed rules. After that, add review gates, documentation and production monitoring, in that order, as the program matures. In a large organization, pilot the process in one business unit before rolling it out across the company.

Use this checklist:

  1. Name an owner: choose one senior executive, supported by a small group from legal, security, data, IT and the business.
  2. Build an inventory: list every AI model, feature and third-party tool, with its purpose, owner and data sources.
  3. Set risk tiers: define low, medium and high risk in plain language, then place every system in one tier.
  4. Write the core policies: start with acceptable use, vendor review and human review, then add the others.
  5. Add review gates: decide what each tier must pass before launch, and who signs off on the result.
  6. Document each system: record its purpose, data sources, known limitations and test results in one place.
  7. Keep evidence: store approvals, changes and incident reports where an auditor can find them quickly.
  8. Monitor after launch: track accuracy, drift, cost and user complaints, and name the person who reviews the results.
  9. Train your people: teach employees the acceptable use rules and show them how to report a problem.
  10. Review every quarter: update the inventory, retire unused systems and check for new regulations.

Next, map your controls to the frameworks you answer to. Map each control once, so one piece of evidence can serve several frameworks at the same time.

FrameworkWhat it isWhat it asks for
NIST AI RMF 1.0Voluntary US framework, released January 2023, now under revisionRisk practices grouped into Govern, Map, Measure and Manage
ISO/IEC 42001:2023International standard, published December 2023Requirements to set up, maintain and improve an AI management system
EU AI ActEU law, Regulation (EU) 2024/1689, in force since August 1, 2024, amended in July 2026Rules by risk tier, from banned practices to transparency duties, with high-risk rules from December 2, 2027

ISO/IEC 42001 is the first management system standard for AI. It suits organizations of any size that develop, provide or use AI. If you sell or use AI in Europe, review the EU AI Act closely. Its bans on certain practices have applied since February 2, 2025. Breaking those bans can bring fines of up to EUR 35 million or 7% of worldwide annual turnover, whichever is higher.

An amendment known as the AI Omnibus, Regulation (EU) 2026/1744, took effect on July 27, 2026. As a result, rules for the high-risk uses listed in Annex III, such as employment and education, now apply from December 2, 2027. Rules for AI built into regulated products, such as machinery, lifts or toys, apply from August 2, 2028. Most transparency duties, such as telling people when they are interacting with AI, have applied since August 2, 2026. The European Commission publishes the current timeline and updates it when dates change.

A few AI governance best practices make the rollout smoother. Keep each policy to a single page. Put review gates inside tools teams already use, such as ticketing systems or release checklists. Report progress to leadership with simple numbers: systems listed, systems reviewed and incidents still open. An AI governance maturity model also helps, because it shows which stage each business unit has reached.

Why is AI governance hard to set up?

AI governance is hard because AI spreads faster than rules, ownership is split across teams, and models change after launch. Fortunately, each of these problems has a practical fix that works inside your existing processes.

  • Shadow AI: employees sign up for AI tools without any review. Make approved tools easy to request, then survey each team to find the rest. Our guide to AI automation tools lists the security questions to ask each vendor.
  • No single owner: legal, IT, data and product teams each control one piece of the process. Give every system one accountable owner, and use one group for approvals.
  • Vendor blind spots: many AI features arrive inside software you already pay for. Add AI questions to your standard vendor review so they are caught early.
  • Systems that change after launch: a model update or a new prompt can change results overnight. Treat every change as a release, with a test and a record. Separate guides explain how to ship an AI agent to production and measure a live AI system.
  • Rules that keep moving: deadlines shift, as the 2026 change to EU AI Act dates shows. Tie your controls to a framework map rather than to a single law.
  • Evidence gathered by hand: screenshots and spreadsheets break down once you have more than a few systems. Collect evidence automatically from the tools where the work happens. Verko, Infoloop’s governance platform, pulls it from connected tools such as AWS, GitHub and Okta.

What is the difference between AI governance and data governance?

Data governance controls the data itself, while AI governance controls what systems do with that data and the decisions they support. Every company using AI needs both, and the two share a lot of ground.

Data governanceAI governance
Main questionIs our data accurate, secure and used lawfully?Is this AI system safe, fair and working as tested?
CoversQuality, access, privacy, retention, lineageRisk tiers, testing, human review, output checks
Typical ownerChief data officer or data teamAn executive AI owner and an approval group
Key recordsData catalog, access logsAI inventory, risk tiers, test results, incident log
Main risksBreaches, bad data, misuseWrong or unfair decisions, drift, misuse

The overlap covers training data, privacy and access control. That is why the two programs should share definitions. It is usually easier to extend your existing data governance program than to build AI governance from scratch. Keep one owner for data rules and one for AI rules. Agree in writing where each set of rules stops.

How Infoloop helps

Verko, Infoloop’s AI governance platform for compliance and AI teams, covers 15+ frameworks from the EU AI Act to SOC 2. It maps one set of controls to each framework you select, so the evidence behind the checklist above is reused.

Infoloop also builds custom AI systems, including an AI support assistant that cut manual support work by 72%. It brought first responses under two minutes, and its first version went live in five weeks. Software from Infoloop’s 50+ projects is live in 6 countries, and the company is rated 4.8 on average across Trustpilot, Google, Clutch and GoodFirms.

Infoloop works with clients worldwide from offices in Surat, India, and Dover, Delaware. Book a Verko demo to see your own frameworks mapped during the call.

Frequently asked questions

  • What is an AI governance framework?

    An AI governance framework is the set of rules, roles and checks that controls how a company builds, buys and uses AI. It names an owner for each system and sorts systems by risk. It also keeps records that show the controls work. Most teams start with a short policy and an inventory.

  • What are the pillars of AI governance?

    Most frameworks share five pillars: accountability, risk management, transparency, data protection and monitoring. Accountability names who decides. Risk management sorts systems by the harm they could cause. Transparency records what each system does and where it is used. Data protection covers privacy and security. Monitoring checks that systems still work as tested.

  • How is AI governance different from data governance?

    Data governance controls the data itself, while AI governance controls what systems do with that data. Data governance covers quality, access, privacy and retention. AI governance adds risk tiers, testing, human review and checks on outputs. The two overlap on training data, so it is usually easier to extend your data rules than to start over.

  • Who is responsible for AI governance in a company?

    One senior executive should own AI governance, with a small group from legal, security, data and the business. Each AI system also needs its own named owner. That person answers for its risk tier, its testing and how well it works day to day. Shared ownership with no single name usually means nobody acts.

  • What is an AI governance maturity model?

    An AI governance maturity model shows how far along your controls are, usually in four stages. At stage one, work is ad hoc, with no inventory or owner. Stage two adds written policies. Stage three adds reviews and evidence for every system. Stage four adds constant monitoring and uses what it finds to improve controls.

  • When do the EU AI Act's high-risk rules apply?

    Rules for the high-risk uses listed in Annex III of the EU AI Act, such as hiring and education, apply from December 2, 2027. Rules for AI built into regulated products, such as machinery, apply from August 2, 2028. The AI Omnibus amendment set these dates when it took effect on July 27, 2026. Bans on certain practices have applied since February 2, 2025.

Nimit Kaneria

Co-founder and CEO

Nimit leads Infoloop's custom software and AI work, for companies whose processes don't fit packaged software.

Further reading

More articles on this topic from the Infoloop team.