AI Governance Institute

AI Governance Controls

Choose a control domain to see what your team needs to implement. Each control includes regulatory mappings, maturity levels, and implementation guidance.

See how controls form an AI governance framework. You can also compare tools organized by the same control domains.

Answer three questions to get a compliance action plan for your organization.

What applies to me?
HOC

Human Oversight

Review gates, approval workflows, and override mechanisms for AI decisions.

7 controls

AGT

Agentic AI

Goal constraints, action boundaries, and escalation paths for autonomous AI agents.

28 controls

SEC

Security

Defenses against crafted inputs that trick AI into misbehaving, including prompt injection, plus controls on who can use each model.

6 controls

ALC

Audit & Logging

Tamper-proof records of AI decisions, inputs, outputs, and which model version produced them.

5 controls

CHM

Change Management

Model release governance, version rollback, and change approval workflows.

5 controls

DGC

Data Governance

Training data provenance, privacy controls, and data retention policies.

6 controls

MON

Monitoring & Drift

Catching AI accuracy that slips over time (drift), alerts on unusual behavior, and operational dashboards.

6 controls

SAF

Safety & Reliability

Safe fallbacks when AI fails, output checks, and reliable behavior when someone tries to trick the system.

6 controls

IRC

Incident Response

Containment, investigation, and remediation procedures for AI system failures.

6 controls

PRC

Procurement

Third-party AI vendor due diligence, contractual obligations, and offboarding.

17 controls

CMP

Regulatory Compliance

Multi-jurisdiction regulatory mapping, standards monitoring, and compliance architecture for AI systems.

10 controls

BRD

Board & Executive Governance

Board education, committee charters, executive reporting, risk appetite, and enterprise-wide AI governance program design.

11 controls

MGV

Model & Program Governance

Model lifecycle policy, intake and approval workflows, evaluation frameworks, and program-level AI governance maturity.

10 controls

SCT

Sector-Specific & Emerging

Healthcare, insurance, critical infrastructure, national security, and emerging-use-case controls not covered by domain-general frameworks.

9 controls

132 controls across 13 domains (select a domain above to filter)

HOC

Human Oversight

7 controls
AGT

Agentic AI

28 controls
AGT-001
Agenthigh

Agent Permission Boundaries

Define and enforce the tools, APIs, data sources, and actions each agent may use, granting only the minimum needed (least privilege).

AGT-002
Agentmedium

Agent Prompt Injection Defense

Protect AI agents from prompt injection attacks, hidden instructions planted in outside content that take over agent behavior.

AGT-003
Agentmedium

Agent Memory and Context Governance

Set rules for agent memory and information kept between sessions. Define permitted content, retention periods, access rights, and deletion conditions.

AGT-004
Agenthigh

Multi-Agent Trust Hierarchy

Define explicit rules for which AI agents can instruct, call on, or delegate authority to other agents in multi-agent systems.

AGT-005
Agentmedium

Human Approval Gate for Irreversible Agent Actions

Require explicit human approval before hard-to-reverse AI agent actions. Examples include communications, record changes, transactions, and data deletion.

AGT-006
Agentmedium

Agent Action Audit Trail

Log every AI agent tool call, decision step, memory read or write, and external interaction. Records must allow reconstruction of the full action sequence.

AGT-007
Agentmedium

Agent Scope and Task Boundaries

Set and enforce each agent’s permitted activity. Prevent actions beyond its intended purpose.

AGT-008
Agenthigh

Agent Environment Isolation

Run AI agents in isolated environments. Limit system, network, and data access to what their tasks require.

AGT-009
Agenthigh

Agent and Non-Human Identity Management

Give each agent a distinct identity with narrowly limited credentials, access controls, and a defined lifecycle. Avoid shared service accounts and user identities.

AGT-010
Agentmedium

Agent Knowledge Source Integrity

Check documents, databases, and external sources retrieved by agents. Verify that nobody has tampered with, poisoned, or substituted the content.

AGT-011
Agenthigh

Agent Behavior Monitoring and Anomaly Detection

Monitor deployed AI agents for behavioral drift, unusual use of connected tools, unexpected resource use, and actions outside their permitted scope.

AGT-012
Agentmedium

Agent Kill Switch and Emergency Stop

Maintain an immediate stop for any agent session, workflow, or type of agent. It must work without agent cooperation and support recovery to a known-safe state.

AGT-013
Agentmedium

Kill-Switch Propagation Testing

Test emergency stops across subagents and agents running in parallel. Verify that all agent activity stops within a defined time window.

AGT-014
Agentmedium

Multi-Agent Delegation Chain Logging

Log every action in systems where AI agents work together. Preserve enough detail to identify its originating instruction, authorized agent, and responsible person.

AGT-015
Agentmedium

Agent OAuth Scope Drift Detection

Monitor AI agents’ OAuth permissions (scopes). Alert when permissions exceed the authorized set or arrive outside the formal approval process.

AGT-016
Agentmedium

Agentic AI Deployment Readiness Assessment

Assess tool-using AI agents before deployment. Verify governance controls and evaluate potential effects on connected systems before launch.

AGT-017
Agentmedium

Agentic Autonomy Expansion Criteria

Define criteria for expanding agent autonomy after deployment. Require supporting evidence and approval through the same governance process used for initial deployment.

AGT-018
Agentmedium

Agent Data Modification Blast-Radius Containment

Limit which data each agent can change. Cap the damage from malfunctions, misuse, or prompt injection, and make affected data recoverable.

AGT-019
Agentmedium

AI Tool and Plugin Supply Chain Risk Assessment

Assess supply-chain risks from agents’ third-party tools, plugins, and extensions. Include AI-generated code added to production software. Apply software supply-chain controls to these outside components.

AGT-020
Agentmedium

RAG Retrieval Boundary Controls for Regulated Data

Set retrieval boundaries in RAG (AI document lookup) pipelines. Keep regulated, classified, and out-of-scope data out of what AI agents see to prevent unauthorized disclosure or sensitive-data mixing.

AGT-021
Agentlow

Human Oversight Classification Rationale Log

Document why each AI agent action requires human-in-the-loop (approval first) or human-on-the-loop (monitoring) oversight. Retain an auditable record of the reasoning behind those choices.

AGT-022
Agentmedium

Agentic AI Governance Tooling Attestation

Obtain vendor attestations before using platform tools as primary agent oversight controls. Verify that monitoring data (telemetry) is complete, tamper-evident, and adequate for governance.

AGT-023
Agenthigh

Agentic AI Security Assessment, CBRN and Cyber Espionage

Assess AI agent deployments for high-consequence misuse, including chemical, biological, radiological, and nuclear facilitation or AI-orchestrated cyber espionage. Implement mitigations proportionate to identified risks.

AGT-024
Agentmedium

AI Permission Escalation Tabletop Exercise Program

Run recurring tabletop exercises on AI agents gaining and spreading unauthorized permissions. Test containment controls, incident detection, response effectiveness, and governance procedures.

AGT-027
Agentlow

Agent Ownership and Accountability Register

Keep a register that names an accountable person for every deployed AI agent. Record who owns its outcomes, who sponsors it at executive level, and what happens when either person leaves.

AGT-028
Agentmedium

Agent External System Access Boundaries

Limit which outside websites, services, and government systems each agent may contact. Stop agents that keep retrying after being blocked, and alert on any contact outside the approved list.

AGT-029
Agentmedium

User-Built Agent Go-Live Review

Require a proportionate review before any agent built by an employee on a self-service platform goes live. Match the depth of review to what the agent can reach and do.

AGT-030
Agentmedium

MCP Server Inventory and Configuration Baseline

Keep an inventory of every MCP server (the connectors that let AI agents use tools and data) in the organization. Hold each one to a baseline for authentication, permissions, logging, and data-loss coverage.

SEC

Security

6 controls
ALC

Audit & Logging

5 controls
CHM

Change Management

5 controls
DGC

Data Governance

6 controls
MON

Monitoring & Drift

6 controls
SAF

Safety & Reliability

6 controls
IRC

Incident Response

6 controls
PRC

Procurement

17 controls
PRC-001
medium

AI Vendor Due Diligence

Assess AI vendors against security, governance, and compliance criteria before procurement and at defined intervals during the vendor relationship.

PRC-002
medium

AI Contractual Requirements

Set minimum AI vendor contract terms for data handling, transparency, audit rights, and incident notification.

PRC-003
high

Third-Party AI Model Evaluation

Evaluate third-party AI models against defined performance, safety, and bias criteria before deploying them in enterprise workflows.

PRC-004
low

Vendor AI Incident Notification Requirements

Require AI vendors to notify the organization of incidents affecting their AI systems within defined timeframes and with specified information.

PRC-005
medium

AI Procurement Risk Assessment

Assess technical, legal, privacy, and operational risks before approving an AI system or service purchase. Document the findings.

PRC-006
medium

Vendor Safety Commitment Verification

Check whether vendors honor published safety commitments, voluntary pledges, and contractual duties throughout the relationship.

PRC-007
low

Vendor Governance Change Monitoring

Monitor vendor changes to governance structures, safety leadership, and policies. Assess their effects on deployed system risks.

PRC-008
medium

Vendor Model Update Disclosure and Re-Assessment Protocol

Require disclosure of material vendor model updates, including capability changes, safety results, and revised model cards (vendors' published model fact sheets). Trigger internal reassessment when updates affect prior due diligence.

PRC-009
medium

AI Vendor Concentration Risk Assessment

Assess dependence on a small number of AI vendors or underlying model providers. Document supplier alternatives supporting continuity if a primary provider fails, suspends access, or becomes unavailable.

PRC-010
low

AI Vendor Financial Stability Assessment

Assess vendors’ financial stability and organizational viability during selection and recurring reviews. Consider market consolidation, regulatory costs, and dependence on further investor funding.

PRC-011
medium

Federal AI Procurement Submission and Review Process

Set a process for federal AI procurement submissions. Track voluntary pre-deployment evaluation commitments becoming mandatory and update procurement workflows accordingly.

PRC-012
low

AI Safety Index and Benchmark Monitoring

Track external safety indices, benchmarks, and independent evaluations for your AI vendors and models. Include material findings in initial and recurring vendor risk assessments.

PRC-013
low

AI Platform Conflict-of-Interest Assessment

Assess conflicts when an AI vendor also supplies oversight, monitoring, or safety evaluations for its own models. Ensure governance decisions can be made without depending entirely on vendor-controlled evidence.

PRC-014
medium

Shadow AI and Third-Party Widget Inventory and Classification

Discover and classify AI built into cloud software (SaaS), browser extensions, and code running in web pages. Apply appropriate processing and vendor-risk controls to these shadow AI sources.

PRC-015
medium

Procurement-Stage AI Governance Conditions

Set governance conditions that must be met before AI procurement finishes. Include contractual standards, whistleblowing policies, and internal approval triggers.

PRC-016
Agentmedium

AI Developer Tool Data Boundary Controls

Define which coding assistants and AI developer tools the enterprise permits, including what data they may transmit. Evaluate data boundaries before deployment and whenever vendor policies change.

PRC-017
low

AI Evaluator and Auditor Independence Assessment

Before relying on an outside AI evaluation, audit, or safety assessment, check that the assessor is qualified and independent of the vendor. Discount findings that fail the check.

CMP

Regulatory Compliance

10 controls
CMP-001
high

Multi-Jurisdiction AI Regulatory Compliance Mapping

Map AI obligations across operating jurisdictions. Identify differing requirements, conflicts, and duties requiring simultaneous compliance.

CMP-002
medium

International AI Standards Monitoring Workflow

Track AI standards updates from ISO, NIST, OECD, ITU, and other bodies. Review internal obligations when changes are material.

CMP-003
medium

Voluntary AI Framework Obligation Mapping

Compare industry pledges, government agreements, and regulatory sandbox commitments with sector requirements. Identify resulting compliance risks and additional obligations.

CMP-004
medium

Non-Legislative AI Obligation Tracker

Track AI governance duties arising through procurement rules, bilateral agreements, regulatory sandbox exit conditions, and regulatory guidance letters.

CMP-005
medium

Regulatory Engagement Process for AI Standards Development

Define participation in regulatory consultations, comment periods, and public-private working groups developing AI rules and standards.

CMP-006
medium

AI Content Watermarking and Labeling Compliance

Keep a checklist of jurisdiction-specific AI content labeling, watermarking, and provenance (content origin) requirements. Implement the necessary technical controls and procedures.

CMP-007
high

EU AI Act Conformity Assessment and FRIA Process

Implement applicable EU AI Act assessment requirements for high-risk systems. Prepare technical documentation, engage notified bodies where required, and address fundamental rights impact assessments.

CMP-008
medium

Federal AI Regulatory Monitoring and Pre-Deployment Vetting

Monitor federal executive orders, agency guidance, and rules for the most advanced AI models. Maintain pre-deployment checks reflecting current US expectations.

CMP-009
high

AI Hardware Provenance and Export Control Compliance

Document the origin and supply chain of AI hardware, including GPUs (graphics processing units) and specialized chips. Screen infrastructure purchases against applicable export controls.

CMP-010
high

AI Use in Regulatory Reporting and Risk Modeling

Map AI uses in regulatory reporting, stress testing, and risk modeling to supervisory expectations. Document validation of outputs before regulatory submission.

BRD

Board & Executive Governance

11 controls
BRD-001
medium

Director AI Literacy and Competency Assessment

Assess directors’ AI knowledge against defined standards. Address gaps through targeted education so the board can carry out its oversight duties.

BRD-002
medium

AI Governance Committee Charter and Decision Rights

Charter an AI governance committee with members from relevant functions. Define its mandate, membership, decision rights, quorum, escalation paths, and board reporting duties.

BRD-003
medium

Board-Level AI Safety Committee Charter

Establish a board committee responsible for AI safety oversight and high-consequence risk decisions. Keep its fiduciary responsibilities distinct from the operational governance committee.

BRD-004
medium

AI Governance ESG and Investor Disclosure

Set a process for reporting AI governance maturity, risk management, and safety practices to shareholders, institutional investors, and ESG agencies.

BRD-005
medium

AI Governance Maturity Assessment

Assess the governance program against defined maturity frameworks and external benchmarks. Use the findings to prioritize improvements.

BRD-006
medium

AI Risk Tolerance and Appetite Documentation

Document and approve AI risk tolerance across relevant risk categories. Obtain board sign-off and schedule periodic reviews.

BRD-007
high

Federated AI Governance Design

Define accountability across distributed AI deployments. Allocate central and business-unit responsibilities, and set escalation routes when local governance is insufficient.

BRD-008
medium

Voluntary AI Governance Adequacy Standard

Define an internal governance standard where binding AI mandates are absent. Document how it meets stakeholder expectations and anticipated regulatory requirements.

BRD-009
high

Unified Multi-Framework AI Risk Register

Consolidate the NIST AI Risk Management Framework (RMF), ISO 42001, EU AI Act, and sector obligations in one risk register. Remove duplication and identify controls satisfying several requirements.

BRD-010
low

AI Governance Committee Operating Cadence and Membership Lifecycle

Document committee meeting schedules, standing agendas, quorum enforcement, and chair responsibilities. Define member onboarding and offboarding so oversight continues consistently.

BRD-011
medium

AI Governance Training Program and Completion Tracking

Maintain AI training tailored to staff roles, with documented curricula and annual completion targets. Keep auditable completion records and review content periodically. Cover staff responsible for design, deployment, review, and oversight.

MGV

Model & Program Governance

10 controls
MGV-001
Agentmedium

AI Model Preview and Staged Release Policy

Distinguish preview and experimental access from approved production use. Require documented governance approval at each release stage before wider deployment.

MGV-002
Agentmedium

AI System Intake and Approval Workflow

Use a standard intake process before new AI systems enter the organization. Record use case, data classification, risk tier, and ownership. Route approvals across relevant functions and retain governance, risk, and compliance (GRC) records.

MGV-003
Agentmedium

AI Governance Program Milestone Framework

Set governance milestones throughout deployment. Require completion before a system advances to its next lifecycle stage.

MGV-004
Agenthigh

Continuous AI Assurance Function Design

Operate an ongoing assurance function that produces regular evidence of control effectiveness. Give boards, regulators, and enterprise customers current records of the governance program’s performance.

MGV-005
Agentmedium

Generative AI Input Data Classification

Classify data entering generative AI through prompts, background material, retrieved documents, results from connected tools, and conversation history. Address privacy, confidentiality, and regulatory risks absent from general data classification rules.

MGV-006
Agenthigh

RAI Benchmark-Aligned Evaluation Framework

Map AI system evaluations to published benchmarks such as HELM Safety, AIR-Bench, and FACTS. Produce evidence regulators, auditors, and enterprise customers can compare against independent standards.

MGV-007
Agentmedium

Emerging AI Modality Classification and Governance Extension

Detect new AI capabilities entering the organization, including ambient AI, agents that handle images and audio, brain-computer interfaces, and always-on assistants. Extend governance coverage before widespread deployment.

MGV-008
medium

AI-Generated Deliverable Disclosure and Citation Standards

Set AI disclosure standards for client-facing, regulatory, and published work. Verify AI-generated citations and factual claims before external distribution. Professional services teams should disclose AI involvement before closing engagements.

MGV-009
medium

AI Capability Claim Substantiation Standard

Set documentation standards for AI capability claims. Cover marketing, product documentation, sales discussions, regulatory submissions, and procurement responses. Retain supporting evidence that meets Federal Trade Commission (FTC) disclosure expectations and enterprise due diligence requirements.

MGV-010
medium

AI Output Pre-Publication Verification for High-Stakes Claims

Require human checks of AI-generated numbers, legal citations, regulatory references, and other high-stakes claims before external publication or regulatory submission. Keep verification checklists and auditable approval records.

SCT

Sector-Specific & Emerging

9 controls
SCT-001
Agentmedium

Anthropomorphic and Companion AI Safeguards

Set design requirements and reviews for AI that simulates personality, emotional connection, or companionship. Address psychological influence, protections for minors, and disclosure duties for ongoing interpersonal interaction.

SCT-002
Agenthigh

Clinical AI Governance Committee Charter

Create a healthcare AI committee with clinical and technical expertise. Define quorum, decision rights, and escalation authority over clinical support and patient-care systems. Schedule reviews around applicable FDA Software as a Medical Device (SaMD) guidance and state clinical standards.

SCT-003
Agenthigh

Critical Infrastructure AI Risk Assessment and Containment

Assess AI risks in energy, water, transport, and financial market infrastructure. Cover limiting AI's reach into operational technology, consequences of failure, and dependencies across sectors. Address these alongside standard enterprise AI risks.

SCT-004
medium

Insurance Sector AI Documentation Standards

Set documentation standards for AI in underwriting, claims, pricing, and fraud detection. Meet applicable state insurance examination expectations, National Association of Insurance Commissioners (NAIC) model bulletin requirements, and algorithmic accountability duties.

SCT-005
Agenthigh

National Security and Dual-Use AI Risk Assessment

Assess AI systems and research with both commercial and national security or weapons applications. Address export controls from the US Commerce Department's Bureau of Industry and Security (BIS), defense-related ITAR arms export duties, dual-use research protocols, and monitoring for foreign adversarial misuse.

SCT-006
Agentmedium

Self-Hosted Open-Weight AI Model Governance

Set intake rules for AI model files (weights) downloaded from public repositories and hosted internally. Check integrity, licensing, and safety before deployment. Manage ongoing updates separately from vendor-hosted AI procurement.

SCT-007
low

Consumer and External AI Tool Acceptable Use Policy

Set acceptable-use rules for employees and contractors using consumer or externally hosted AI. Cover public assistants, browser tools, and AI features in cloud software. Define permitted uses, data restrictions, access controls, and onboarding attestations to manage shadow AI (unsanctioned AI use).

SCT-008
Agentmedium

AI-Specific External Complaints and Redress Mechanism

Provide a formal complaints process for customers, employees, affected individuals, and the public. Give timely responses and human review of AI-assisted decisions on request. Provide meaningful redress when decisions are incorrect or unfair.

SCT-009
Agentmedium

AI System Algorithm Register

Maintain a register of internal and public-facing AI systems. Record purpose, decision scope, risk classification, data inputs, and accountability contacts. Address applicable requirements under the EU AI Act, NYC Local Law 144, Amsterdam-model registers, and equivalent frameworks.

New controls, every week

We publish new governance controls, maturity updates, and implementation guidance as regulations shift. Get them Thursday mornings, before your compliance team needs them.

Powered by Buttondown.