Skip to main content
Skip to content
Regurai
AI governance framework

An AI governance framework only works once it runs.

A framework is the structure that decides which AI may operate, on what basis, under whose accountability, and with what evidence behind it. This page sets out what such a framework contains, how the main standards relate to it, and how Regurai operates one.

Definition

What an AI governance framework is.

A defined set of roles, decisions, controls and records that governs how artificial intelligence is introduced, approved, monitored and evidenced across an organisation. It is not a single policy document, and it is not a compliance certificate.

Components

Seven components every framework needs.

Each component produces something the next one depends on. Missing one breaks the chain.

01

Scope and inventory

A defined record of the models, agents and AI-enabled applications in use, each with a purpose, an intended use and a named owner. Without an inventory, every later step is an estimate.

02

Roles and accountability

Who proposes, who reviews, who approves and who remains accountable once the system is live, with separation between the people who build and the people who authorise.

03

Risk assessment

A repeatable method for classifying each AI system by its use, the data it depends on and the people it affects, rather than a one-off questionnaire held apart from the system itself.

04

Controls and obligations

The controls expected of each risk class, mapped to the regulatory and internal obligations they are intended to satisfy.

05

Approval and conditions

A recorded decision on whether a system may operate, under what conditions, and when that decision must be revisited.

06

Monitoring and change

Detection of change in data, dependencies or control state that invalidates an earlier decision, so approvals do not silently age.

07

Evidence and audit trail

A durable, tamper-evident record behind every decision, assembled as work happens rather than reconstructed before an audit.

Standards

How the main standards fit together.

These frameworks answer different questions. Most organisations use them in combination rather than choosing between them. Referencing a framework does not imply endorsement by, or affiliation with, the issuing body.

NIST AI RMF 1.0

AI Risk Management Framework

A voluntary risk framework organised around govern, map, measure and manage. Widely used as the structural backbone of an internal AI governance framework.

Official source

ISO/IEC 42001:2023

Artificial intelligence management system

A certifiable management-system standard. It defines how the governance framework itself is planned, operated, reviewed and improved.

Official source

EU AI Act (2024/1689)

Harmonised rules on artificial intelligence

Binding law in the European Union. It sets risk categories and specific obligations, so it determines the requirements a framework must be able to evidence.

Official source

ISO/IEC 27001:2022

Information security management systems

The security control base most AI governance frameworks build on, since AI systems inherit the security posture of the data and platforms beneath them.

Official source
Operating model

Six stages, in the order the work happens.

This is how Regurai runs an AI governance framework day to day, rather than describing one on paper.

01

Register

What AI exists here?

Record models, agents and AI-enabled applications with owners, purpose and intended use.

02

Connect

What does it depend on and affect?

Link each AI system to its data, applications, processes, controls and obligations.

03

Assess

What risk does it carry?

Score risk from real dependencies and control coverage rather than a standalone questionnaire.

04

Approve

Should it run, and under what conditions?

Decide with separation of duties, recorded conditions and named accountability.

05

Monitor

Has anything changed?

Detect changes in data, dependencies or control state that invalidate an earlier decision.

06

Prove

Can we evidence it?

Assemble the audit trail behind any AI decision without re-collecting evidence by hand.

From framework to owner

A framework is only useful once it reaches a named person.

  1. Framework
  2. Requirement
  3. Control
  4. Evidence
  5. Gap
  6. Action
  7. Owner
  8. Assurance

Regurai supports alignment with these frameworks, maps requirements to controls and assembles the supporting evidence. It does not determine compliance, and it does not confer certification. Those judgements remain with your organisation and its assessors.

Common failures

Where frameworks break down.

A policy with no inventory behind it

A written framework that cannot name the AI systems in use cannot be operated or evidenced.

Risk assessed in isolation

Scoring an AI system without its data, process and control dependencies produces a rating that does not survive scrutiny.

Approvals that never expire

A decision taken against one version of a model becomes misleading once the model, its data or its controls change.

Evidence collected only for audits

Reconstructing an audit trail after the fact is slow, incomplete and hard to defend.

Related: AI Governance and framework coverage methodology.

See. Understand. Govern. Act.

See how Regurai connects AI, data, architecture, risk, regulation and value into one enterprise intelligence layer.