An AI governance framework only works once it runs.
A framework is the structure that decides which AI may operate, on what basis, under whose accountability, and with what evidence behind it. This page sets out what such a framework contains, how the main standards relate to it, and how Regurai operates one.
What an AI governance framework is.
A defined set of roles, decisions, controls and records that governs how artificial intelligence is introduced, approved, monitored and evidenced across an organisation. It is not a single policy document, and it is not a compliance certificate.
Seven components every framework needs.
Each component produces something the next one depends on. Missing one breaks the chain.
Scope and inventory
A defined record of the models, agents and AI-enabled applications in use, each with a purpose, an intended use and a named owner. Without an inventory, every later step is an estimate.
Roles and accountability
Who proposes, who reviews, who approves and who remains accountable once the system is live, with separation between the people who build and the people who authorise.
Risk assessment
A repeatable method for classifying each AI system by its use, the data it depends on and the people it affects, rather than a one-off questionnaire held apart from the system itself.
Controls and obligations
The controls expected of each risk class, mapped to the regulatory and internal obligations they are intended to satisfy.
Approval and conditions
A recorded decision on whether a system may operate, under what conditions, and when that decision must be revisited.
Monitoring and change
Detection of change in data, dependencies or control state that invalidates an earlier decision, so approvals do not silently age.
Evidence and audit trail
A durable, tamper-evident record behind every decision, assembled as work happens rather than reconstructed before an audit.
How the main standards fit together.
These frameworks answer different questions. Most organisations use them in combination rather than choosing between them. Referencing a framework does not imply endorsement by, or affiliation with, the issuing body.
NIST AI RMF 1.0
A voluntary risk framework organised around govern, map, measure and manage. Widely used as the structural backbone of an internal AI governance framework.
Official sourceISO/IEC 42001:2023
A certifiable management-system standard. It defines how the governance framework itself is planned, operated, reviewed and improved.
Official sourceEU AI Act (2024/1689)
Binding law in the European Union. It sets risk categories and specific obligations, so it determines the requirements a framework must be able to evidence.
Official sourceISO/IEC 27001:2022
The security control base most AI governance frameworks build on, since AI systems inherit the security posture of the data and platforms beneath them.
Official sourceSix stages, in the order the work happens.
This is how Regurai runs an AI governance framework day to day, rather than describing one on paper.
Register
Record models, agents and AI-enabled applications with owners, purpose and intended use.
Connect
Link each AI system to its data, applications, processes, controls and obligations.
Assess
Score risk from real dependencies and control coverage rather than a standalone questionnaire.
Approve
Decide with separation of duties, recorded conditions and named accountability.
Monitor
Detect changes in data, dependencies or control state that invalidate an earlier decision.
Prove
Assemble the audit trail behind any AI decision without re-collecting evidence by hand.
A framework is only useful once it reaches a named person.
- Framework
- Requirement
- Control
- Evidence
- Gap
- Action
- Owner
- Assurance
Regurai supports alignment with these frameworks, maps requirements to controls and assembles the supporting evidence. It does not determine compliance, and it does not confer certification. Those judgements remain with your organisation and its assessors.
Where frameworks break down.
A policy with no inventory behind it
A written framework that cannot name the AI systems in use cannot be operated or evidenced.
Risk assessed in isolation
Scoring an AI system without its data, process and control dependencies produces a rating that does not survive scrutiny.
Approvals that never expire
A decision taken against one version of a model becomes misleading once the model, its data or its controls change.
Evidence collected only for audits
Reconstructing an audit trail after the fact is slow, incomplete and hard to defend.
Related: AI Governance and framework coverage methodology.
