AI Governance Controls
Choose a control domain to see what your team needs to implement. Each control includes regulatory mappings, maturity levels, and implementation guidance.
See how controls form an AI governance framework. You can also compare tools organized by the same control domains.
Answer three questions to get a compliance action plan for your organization.
What applies to me?Human Oversight
Review gates, approval workflows, and override mechanisms for AI decisions.
7 controls
AGTAgentic AI
Goal constraints, action boundaries, and escalation paths for autonomous AI agents.
28 controls
SECSecurity
Defenses against crafted inputs that trick AI into misbehaving, including prompt injection, plus controls on who can use each model.
6 controls
ALCAudit & Logging
Tamper-proof records of AI decisions, inputs, outputs, and which model version produced them.
5 controls
CHMChange Management
Model release governance, version rollback, and change approval workflows.
5 controls
DGCData Governance
Training data provenance, privacy controls, and data retention policies.
6 controls
MONMonitoring & Drift
Catching AI accuracy that slips over time (drift), alerts on unusual behavior, and operational dashboards.
6 controls
SAFSafety & Reliability
Safe fallbacks when AI fails, output checks, and reliable behavior when someone tries to trick the system.
6 controls
IRCIncident Response
Containment, investigation, and remediation procedures for AI system failures.
6 controls
PRCProcurement
Third-party AI vendor due diligence, contractual obligations, and offboarding.
17 controls
CMPRegulatory Compliance
Multi-jurisdiction regulatory mapping, standards monitoring, and compliance architecture for AI systems.
10 controls
BRDBoard & Executive Governance
Board education, committee charters, executive reporting, risk appetite, and enterprise-wide AI governance program design.
11 controls
MGVModel & Program Governance
Model lifecycle policy, intake and approval workflows, evaluation frameworks, and program-level AI governance maturity.
10 controls
SCTSector-Specific & Emerging
Healthcare, insurance, critical infrastructure, national security, and emerging-use-case controls not covered by domain-general frameworks.
9 controls
132 controls across 13 domains (select a domain above to filter)
Human Oversight
7 controlsAI System Risk Classification
Assign every AI system a risk tier that determines the oversight requirements, review frequency, and documentation standards applied to it.
Human Approval Gate for Consequential AI Decisions
Require a qualified human to review and approve AI-generated recommendations before they produce irreversible or high-stakes outcomes.
AI Output Review Workflow
Define a structured, documented process for reviewing AI outputs before they are acted upon or distributed.
Automation Bias Prevention
Implement measures to detect and counteract the tendency for human reviewers to defer to AI recommendations without adequate critical evaluation.
Reviewer Competency Requirements
Define minimum competency requirements for humans who review, approve, or override AI-generated outputs in high-risk contexts.
Override and Escalation Procedures
Document the procedures, authority levels, and logging requirements when humans reject, modify, or escalate AI-generated decisions.
Board AI Risk Reporting and Escalation Thresholds
Report material AI risks to the board and audit committee on a schedule. Set thresholds requiring immediate notification between reports.
Agentic AI
28 controlsAgent Permission Boundaries
Define and enforce the tools, APIs, data sources, and actions each agent may use, granting only the minimum needed (least privilege).
Agent Prompt Injection Defense
Protect AI agents from prompt injection attacks, hidden instructions planted in outside content that take over agent behavior.
Agent Memory and Context Governance
Set rules for agent memory and information kept between sessions. Define permitted content, retention periods, access rights, and deletion conditions.
Multi-Agent Trust Hierarchy
Define explicit rules for which AI agents can instruct, call on, or delegate authority to other agents in multi-agent systems.
Human Approval Gate for Irreversible Agent Actions
Require explicit human approval before hard-to-reverse AI agent actions. Examples include communications, record changes, transactions, and data deletion.
Agent Action Audit Trail
Log every AI agent tool call, decision step, memory read or write, and external interaction. Records must allow reconstruction of the full action sequence.
Agent Scope and Task Boundaries
Set and enforce each agent’s permitted activity. Prevent actions beyond its intended purpose.
Agent Environment Isolation
Run AI agents in isolated environments. Limit system, network, and data access to what their tasks require.
Agent and Non-Human Identity Management
Give each agent a distinct identity with narrowly limited credentials, access controls, and a defined lifecycle. Avoid shared service accounts and user identities.
Agent Knowledge Source Integrity
Check documents, databases, and external sources retrieved by agents. Verify that nobody has tampered with, poisoned, or substituted the content.
Agent Behavior Monitoring and Anomaly Detection
Monitor deployed AI agents for behavioral drift, unusual use of connected tools, unexpected resource use, and actions outside their permitted scope.
Agent Kill Switch and Emergency Stop
Maintain an immediate stop for any agent session, workflow, or type of agent. It must work without agent cooperation and support recovery to a known-safe state.
Kill-Switch Propagation Testing
Test emergency stops across subagents and agents running in parallel. Verify that all agent activity stops within a defined time window.
Multi-Agent Delegation Chain Logging
Log every action in systems where AI agents work together. Preserve enough detail to identify its originating instruction, authorized agent, and responsible person.
Agent OAuth Scope Drift Detection
Monitor AI agents’ OAuth permissions (scopes). Alert when permissions exceed the authorized set or arrive outside the formal approval process.
Agentic AI Deployment Readiness Assessment
Assess tool-using AI agents before deployment. Verify governance controls and evaluate potential effects on connected systems before launch.
Agentic Autonomy Expansion Criteria
Define criteria for expanding agent autonomy after deployment. Require supporting evidence and approval through the same governance process used for initial deployment.
Agent Data Modification Blast-Radius Containment
Limit which data each agent can change. Cap the damage from malfunctions, misuse, or prompt injection, and make affected data recoverable.
AI Tool and Plugin Supply Chain Risk Assessment
Assess supply-chain risks from agents’ third-party tools, plugins, and extensions. Include AI-generated code added to production software. Apply software supply-chain controls to these outside components.
RAG Retrieval Boundary Controls for Regulated Data
Set retrieval boundaries in RAG (AI document lookup) pipelines. Keep regulated, classified, and out-of-scope data out of what AI agents see to prevent unauthorized disclosure or sensitive-data mixing.
Human Oversight Classification Rationale Log
Document why each AI agent action requires human-in-the-loop (approval first) or human-on-the-loop (monitoring) oversight. Retain an auditable record of the reasoning behind those choices.
Agentic AI Governance Tooling Attestation
Obtain vendor attestations before using platform tools as primary agent oversight controls. Verify that monitoring data (telemetry) is complete, tamper-evident, and adequate for governance.
Agentic AI Security Assessment, CBRN and Cyber Espionage
Assess AI agent deployments for high-consequence misuse, including chemical, biological, radiological, and nuclear facilitation or AI-orchestrated cyber espionage. Implement mitigations proportionate to identified risks.
AI Permission Escalation Tabletop Exercise Program
Run recurring tabletop exercises on AI agents gaining and spreading unauthorized permissions. Test containment controls, incident detection, response effectiveness, and governance procedures.
Agent Ownership and Accountability Register
Keep a register that names an accountable person for every deployed AI agent. Record who owns its outcomes, who sponsors it at executive level, and what happens when either person leaves.
Agent External System Access Boundaries
Limit which outside websites, services, and government systems each agent may contact. Stop agents that keep retrying after being blocked, and alert on any contact outside the approved list.
User-Built Agent Go-Live Review
Require a proportionate review before any agent built by an employee on a self-service platform goes live. Match the depth of review to what the agent can reach and do.
MCP Server Inventory and Configuration Baseline
Keep an inventory of every MCP server (the connectors that let AI agents use tools and data) in the organization. Hold each one to a baseline for authentication, permissions, logging, and data-loss coverage.
Security
6 controlsPrompt Injection Prevention
Detect and block inputs designed to override instructions, extract sensitive information, or cause unintended AI behavior.
AI System Access Controls
Apply authentication, authorization, and role-based access controls to AI systems, their APIs (software connections), and the sensitive data they process.
Sensitive Data Handling in AI Pipelines
Prevent personally identifiable information, credentials, health data, and other sensitive content from entering AI models, prompts, or logs inappropriately.
AI API Credential Management
Securely manage, regularly replace, and audit API keys and credentials used to access AI services and model providers.
Adversarial Robustness Testing
Systematically test AI systems against hostile inputs, unusual cases, and known attack techniques before deployment and on a recurring basis.
Deepfake Impersonation Defense for Approvals and Payments
Require a check through a separate, trusted channel before acting on voice, video, or message requests to move money, change payment details, or grant access. Do not accept a familiar voice or face as proof of identity.
Audit & Logging
5 controlsAI Decision Logging
Log inputs, outputs, model versions, confidence scores, and context for every AI decision affecting people or business outcomes.
High-Risk AI Audit Trail
Keep tamper-evident audit trails for AI in regulated domains. Cover the lifecycle from input through decision to outcome.
AI Log Retention Policy
Set retention periods and formats for decision logs, audit trails, and system logs. Document eventual deletion procedures.
AI Explainability Documentation
Document how AI systems reach decisions in sufficient detail that affected individuals, reviewers, and regulators can understand and challenge outcomes.
Regulatory Audit Readiness
Keep AI documentation, logs, and governance records ready for efficient retrieval during regulatory inquiries or audits.
Change Management
5 controlsAI Model Version Control
Track model versions, configurations, prompts, and deployment history so that any past live setup can be recreated and compared.
Model Deployment Gate Process
Require formal approval before new model versions, prompt changes, or configuration updates go live in AI systems.
Model Rollback and Emergency Shutdown
Test procedures for rapidly reverting or disabling AI systems after failures or safety events.
AI Model Change Documentation
Record what changed between model versions, why the change was made, what testing was performed, and who approved the deployment.
Model Deprecation Procedure
Define the process for retiring AI models from production, including notification, data handling, audit trail preservation, and transition planning.
Data Governance
6 controlsTraining Data Provenance
Track and document the origin, composition, licensing, and preparation history of data used to train or fine-tune AI models.
PII Handling in AI Systems
Establish controls governing how personally identifiable information is handled when it flows through AI inputs, outputs, training data, and logs.
Data Minimization for AI Systems
Limit AI processing to data needed for its defined purpose. Avoid unnecessary collection, retention, or use of personal information.
AI Output Retention and Deletion
Define and enforce retention schedules and deletion procedures for AI-generated content, decisions, and the personal data contained within them.
Cross-Border Data Transfer Controls for AI
Govern international personal-data transfers through AI systems. Include transfers to AI service providers, model training systems, and cloud infrastructure in other jurisdictions.
AI-Generated Code and Open-Source License Compliance
Identify open-source license obligations and supply-chain risks in AI-generated code. Address them before adding the code to production systems.
Monitoring & Drift
6 controlsAI Performance Baseline
Establish documented, quantified performance baselines for live AI systems against which ongoing performance can be compared.
Model Drift Detection
Monitor live AI systems for data drift, concept drift, and shifts in outputs that signal degraded or changed model behavior.
AI Bias and Fairness Monitoring
Continuously monitor AI system outputs for discriminatory patterns across protected demographic attributes in live use.
AI Output Anomaly Detection
Automatically detect unusual, unexpected, or potentially harmful AI outputs in live use for investigation and response.
Continuous Model Evaluation
Run ongoing automated tests on reserved test data and deliberately tricky inputs to continuously measure live model performance.
Behavioral Anomaly Detection for Agentic Systems
Monitor AI agents for unexpected action sequences, data or system access, and behavior inconsistent with assigned tasks.
Safety & Reliability
6 controlsHallucination Detection and Mitigation
Implement controls to detect, reduce, and manage AI-generated factual errors and fabrications before they reach end users or inform decisions.
AI Output Validation
Check AI outputs against quality, safety, and format criteria before users or other systems receive them.
AI Graceful Degradation
Define and implement fallback behavior for AI systems when they are unavailable, underperforming, or producing outputs below acceptable quality thresholds.
AI Reliability Testing
Systematically test AI systems for consistency, repeatability, handling of unusual inputs, and behavior under heavy use before deployment and on a recurring basis.
Harmful Content Filtering
Apply input and output filtering to prevent AI systems from generating or acting on harmful, toxic, illegal, or policy-violating content.
Post-Deployment Adversarial Testing Cadence
Schedule recurring red-teaming (simulated attacks) of live systems by risk tier. Continue this testing after pre-deployment assessments.
Incident Response
6 controlsAI Incident Classification
Classify AI incidents by type and severity. Use the categories to set response urgency and notification requirements.
AI Incident Response Playbook
Document step-by-step procedures for identifying, containing, investigating, and resolving AI system incidents, including role assignments and escalation paths.
AI Harm Notification Procedures
Define procedures for notifying regulators, affected individuals, and other required parties when an AI system causes or contributes to harm.
AI Post-Incident Review
Conduct a structured review after every significant AI incident to identify root causes, contributing factors, and systemic improvements.
AI Incident Log and Tracking
Maintain a centralized, structured log of all AI incidents, near-misses, and governance concerns, accessible to the AI governance function.
Cross-Jurisdictional Incident Reporting Tracker
Track AI incident notification deadlines across operating jurisdictions. Map each deadline to the incident categories triggering it.
Procurement
17 controlsAI Vendor Due Diligence
Assess AI vendors against security, governance, and compliance criteria before procurement and at defined intervals during the vendor relationship.
AI Contractual Requirements
Set minimum AI vendor contract terms for data handling, transparency, audit rights, and incident notification.
Third-Party AI Model Evaluation
Evaluate third-party AI models against defined performance, safety, and bias criteria before deploying them in enterprise workflows.
Vendor AI Incident Notification Requirements
Require AI vendors to notify the organization of incidents affecting their AI systems within defined timeframes and with specified information.
AI Procurement Risk Assessment
Assess technical, legal, privacy, and operational risks before approving an AI system or service purchase. Document the findings.
Vendor Safety Commitment Verification
Check whether vendors honor published safety commitments, voluntary pledges, and contractual duties throughout the relationship.
Vendor Governance Change Monitoring
Monitor vendor changes to governance structures, safety leadership, and policies. Assess their effects on deployed system risks.
Vendor Model Update Disclosure and Re-Assessment Protocol
Require disclosure of material vendor model updates, including capability changes, safety results, and revised model cards (vendors' published model fact sheets). Trigger internal reassessment when updates affect prior due diligence.
AI Vendor Concentration Risk Assessment
Assess dependence on a small number of AI vendors or underlying model providers. Document supplier alternatives supporting continuity if a primary provider fails, suspends access, or becomes unavailable.
AI Vendor Financial Stability Assessment
Assess vendors’ financial stability and organizational viability during selection and recurring reviews. Consider market consolidation, regulatory costs, and dependence on further investor funding.
Federal AI Procurement Submission and Review Process
Set a process for federal AI procurement submissions. Track voluntary pre-deployment evaluation commitments becoming mandatory and update procurement workflows accordingly.
AI Safety Index and Benchmark Monitoring
Track external safety indices, benchmarks, and independent evaluations for your AI vendors and models. Include material findings in initial and recurring vendor risk assessments.
AI Platform Conflict-of-Interest Assessment
Assess conflicts when an AI vendor also supplies oversight, monitoring, or safety evaluations for its own models. Ensure governance decisions can be made without depending entirely on vendor-controlled evidence.
Shadow AI and Third-Party Widget Inventory and Classification
Discover and classify AI built into cloud software (SaaS), browser extensions, and code running in web pages. Apply appropriate processing and vendor-risk controls to these shadow AI sources.
Procurement-Stage AI Governance Conditions
Set governance conditions that must be met before AI procurement finishes. Include contractual standards, whistleblowing policies, and internal approval triggers.
AI Developer Tool Data Boundary Controls
Define which coding assistants and AI developer tools the enterprise permits, including what data they may transmit. Evaluate data boundaries before deployment and whenever vendor policies change.
AI Evaluator and Auditor Independence Assessment
Before relying on an outside AI evaluation, audit, or safety assessment, check that the assessor is qualified and independent of the vendor. Discount findings that fail the check.
Regulatory Compliance
10 controlsMulti-Jurisdiction AI Regulatory Compliance Mapping
Map AI obligations across operating jurisdictions. Identify differing requirements, conflicts, and duties requiring simultaneous compliance.
International AI Standards Monitoring Workflow
Track AI standards updates from ISO, NIST, OECD, ITU, and other bodies. Review internal obligations when changes are material.
Voluntary AI Framework Obligation Mapping
Compare industry pledges, government agreements, and regulatory sandbox commitments with sector requirements. Identify resulting compliance risks and additional obligations.
Non-Legislative AI Obligation Tracker
Track AI governance duties arising through procurement rules, bilateral agreements, regulatory sandbox exit conditions, and regulatory guidance letters.
Regulatory Engagement Process for AI Standards Development
Define participation in regulatory consultations, comment periods, and public-private working groups developing AI rules and standards.
AI Content Watermarking and Labeling Compliance
Keep a checklist of jurisdiction-specific AI content labeling, watermarking, and provenance (content origin) requirements. Implement the necessary technical controls and procedures.
EU AI Act Conformity Assessment and FRIA Process
Implement applicable EU AI Act assessment requirements for high-risk systems. Prepare technical documentation, engage notified bodies where required, and address fundamental rights impact assessments.
Federal AI Regulatory Monitoring and Pre-Deployment Vetting
Monitor federal executive orders, agency guidance, and rules for the most advanced AI models. Maintain pre-deployment checks reflecting current US expectations.
AI Hardware Provenance and Export Control Compliance
Document the origin and supply chain of AI hardware, including GPUs (graphics processing units) and specialized chips. Screen infrastructure purchases against applicable export controls.
AI Use in Regulatory Reporting and Risk Modeling
Map AI uses in regulatory reporting, stress testing, and risk modeling to supervisory expectations. Document validation of outputs before regulatory submission.
Board & Executive Governance
11 controlsDirector AI Literacy and Competency Assessment
Assess directors’ AI knowledge against defined standards. Address gaps through targeted education so the board can carry out its oversight duties.
AI Governance Committee Charter and Decision Rights
Charter an AI governance committee with members from relevant functions. Define its mandate, membership, decision rights, quorum, escalation paths, and board reporting duties.
Board-Level AI Safety Committee Charter
Establish a board committee responsible for AI safety oversight and high-consequence risk decisions. Keep its fiduciary responsibilities distinct from the operational governance committee.
AI Governance ESG and Investor Disclosure
Set a process for reporting AI governance maturity, risk management, and safety practices to shareholders, institutional investors, and ESG agencies.
AI Governance Maturity Assessment
Assess the governance program against defined maturity frameworks and external benchmarks. Use the findings to prioritize improvements.
AI Risk Tolerance and Appetite Documentation
Document and approve AI risk tolerance across relevant risk categories. Obtain board sign-off and schedule periodic reviews.
Federated AI Governance Design
Define accountability across distributed AI deployments. Allocate central and business-unit responsibilities, and set escalation routes when local governance is insufficient.
Voluntary AI Governance Adequacy Standard
Define an internal governance standard where binding AI mandates are absent. Document how it meets stakeholder expectations and anticipated regulatory requirements.
Unified Multi-Framework AI Risk Register
Consolidate the NIST AI Risk Management Framework (RMF), ISO 42001, EU AI Act, and sector obligations in one risk register. Remove duplication and identify controls satisfying several requirements.
AI Governance Committee Operating Cadence and Membership Lifecycle
Document committee meeting schedules, standing agendas, quorum enforcement, and chair responsibilities. Define member onboarding and offboarding so oversight continues consistently.
AI Governance Training Program and Completion Tracking
Maintain AI training tailored to staff roles, with documented curricula and annual completion targets. Keep auditable completion records and review content periodically. Cover staff responsible for design, deployment, review, and oversight.
Model & Program Governance
10 controlsAI Model Preview and Staged Release Policy
Distinguish preview and experimental access from approved production use. Require documented governance approval at each release stage before wider deployment.
AI System Intake and Approval Workflow
Use a standard intake process before new AI systems enter the organization. Record use case, data classification, risk tier, and ownership. Route approvals across relevant functions and retain governance, risk, and compliance (GRC) records.
AI Governance Program Milestone Framework
Set governance milestones throughout deployment. Require completion before a system advances to its next lifecycle stage.
Continuous AI Assurance Function Design
Operate an ongoing assurance function that produces regular evidence of control effectiveness. Give boards, regulators, and enterprise customers current records of the governance program’s performance.
Generative AI Input Data Classification
Classify data entering generative AI through prompts, background material, retrieved documents, results from connected tools, and conversation history. Address privacy, confidentiality, and regulatory risks absent from general data classification rules.
RAI Benchmark-Aligned Evaluation Framework
Map AI system evaluations to published benchmarks such as HELM Safety, AIR-Bench, and FACTS. Produce evidence regulators, auditors, and enterprise customers can compare against independent standards.
Emerging AI Modality Classification and Governance Extension
Detect new AI capabilities entering the organization, including ambient AI, agents that handle images and audio, brain-computer interfaces, and always-on assistants. Extend governance coverage before widespread deployment.
AI-Generated Deliverable Disclosure and Citation Standards
Set AI disclosure standards for client-facing, regulatory, and published work. Verify AI-generated citations and factual claims before external distribution. Professional services teams should disclose AI involvement before closing engagements.
AI Capability Claim Substantiation Standard
Set documentation standards for AI capability claims. Cover marketing, product documentation, sales discussions, regulatory submissions, and procurement responses. Retain supporting evidence that meets Federal Trade Commission (FTC) disclosure expectations and enterprise due diligence requirements.
AI Output Pre-Publication Verification for High-Stakes Claims
Require human checks of AI-generated numbers, legal citations, regulatory references, and other high-stakes claims before external publication or regulatory submission. Keep verification checklists and auditable approval records.
Sector-Specific & Emerging
9 controlsAnthropomorphic and Companion AI Safeguards
Set design requirements and reviews for AI that simulates personality, emotional connection, or companionship. Address psychological influence, protections for minors, and disclosure duties for ongoing interpersonal interaction.
Clinical AI Governance Committee Charter
Create a healthcare AI committee with clinical and technical expertise. Define quorum, decision rights, and escalation authority over clinical support and patient-care systems. Schedule reviews around applicable FDA Software as a Medical Device (SaMD) guidance and state clinical standards.
Critical Infrastructure AI Risk Assessment and Containment
Assess AI risks in energy, water, transport, and financial market infrastructure. Cover limiting AI's reach into operational technology, consequences of failure, and dependencies across sectors. Address these alongside standard enterprise AI risks.
Insurance Sector AI Documentation Standards
Set documentation standards for AI in underwriting, claims, pricing, and fraud detection. Meet applicable state insurance examination expectations, National Association of Insurance Commissioners (NAIC) model bulletin requirements, and algorithmic accountability duties.
National Security and Dual-Use AI Risk Assessment
Assess AI systems and research with both commercial and national security or weapons applications. Address export controls from the US Commerce Department's Bureau of Industry and Security (BIS), defense-related ITAR arms export duties, dual-use research protocols, and monitoring for foreign adversarial misuse.
Self-Hosted Open-Weight AI Model Governance
Set intake rules for AI model files (weights) downloaded from public repositories and hosted internally. Check integrity, licensing, and safety before deployment. Manage ongoing updates separately from vendor-hosted AI procurement.
Consumer and External AI Tool Acceptable Use Policy
Set acceptable-use rules for employees and contractors using consumer or externally hosted AI. Cover public assistants, browser tools, and AI features in cloud software. Define permitted uses, data restrictions, access controls, and onboarding attestations to manage shadow AI (unsanctioned AI use).
AI-Specific External Complaints and Redress Mechanism
Provide a formal complaints process for customers, employees, affected individuals, and the public. Give timely responses and human review of AI-assisted decisions on request. Provide meaningful redress when decisions are incorrect or unfair.
AI System Algorithm Register
Maintain a register of internal and public-facing AI systems. Record purpose, decision scope, risk classification, data inputs, and accountability contacts. Address applicable requirements under the EU AI Act, NYC Local Law 144, Amsterdam-model registers, and equivalent frameworks.
New controls, every week
We publish new governance controls, maturity updates, and implementation guidance as regulations shift. Get them Thursday mornings, before your compliance team needs them.
