AI Governance Institute
← News
Research2026-08-17

Keyrus 2026 Guide Sets a Baseline Operating Model for AI Governance Programs

What happened

Keyrus published AI in 2026: How to Build Trustworthy, Safe and Governed AI Systems, a practitioner guide designed to help enterprise compliance and risk teams build or mature their AI governance programs. The guide identifies four structural pillars: an AI system inventory, a risk prioritization framework, cross-functional governance ownership, and third-party oversight for vendor-supplied models. It recommends pairing governance workflows with runtime monitoring, documentation standards, and continuous feedback loops. The guidance is global in scope and is not tied to a specific regulatory jurisdiction, though its operating model maps closely to requirements emerging under frameworks such as ISO/IEC 42001:2023 and the EU AI Act. The guide arrives as a growing body of practitioner research, including the KPMG-UTS case study, is converging on the same foundational gaps in enterprise AI governance.

Why it matters

  • ·An AI inventory is increasingly a regulatory prerequisite, not a best practice. Regulators under the EU AI Act, several US state laws, and ISO/IEC 42001:2023 expect organizations to demonstrate they know what AI systems they operate and at what risk level, making a complete inventory the first control auditors will probe.
  • ·Third-party and vendor-supplied model risk remains one of the least-governed areas in enterprise AI programs. The Keyrus guide calls for structured vendor oversight as a core program element, a gap also identified in incidents such as the KPMG model risk framing, where vendor models sitting inside existing workflows often escape the scrutiny applied to internally developed systems.
  • ·Cross-functional governance structures are becoming an audit expectation, not an organizational preference. Without a defined committee with documented decision rights and membership, compliance teams cannot demonstrate consistent accountability when an AI incident occurs or a regulator requests evidence of oversight.

Governance controls affected

What to do now

  • ☐Conduct a gap assessment against the four pillars in the Keyrus guide: inventory completeness, risk prioritization methodology, governance team structure, and vendor model oversight coverage.
  • ☐Verify that your AI system inventory includes vendor-supplied and embedded models, not only internally developed systems, and confirm each entry has an assigned risk classification.
  • ☐Review your cross-functional governance committee charter against the guide's cross-functional ownership model to confirm it defines decision rights, escalation paths, and accountability for AI incidents.
  • ☐Map your current runtime monitoring controls to the guide's continuous feedback loop requirement and identify systems that have no post-deployment performance or drift monitoring in place.
  • ☐Update third-party AI risk assessments to require vendor disclosure of model updates, safety commitments, and incident notification timelines as a contract condition.

What to watch next

Compliance teams should monitor whether upcoming enforcement actions under the EU AI Act begin to cite incomplete inventories or absent cross-functional governance bodies as deficiencies, as this would convert the Keyrus guide's recommendations into de facto regulatory expectations. Certification activity under ISO/IEC 42001:2023 is also worth tracking, since auditors are beginning to develop consistent interpretations of what a conforming governance operating model looks like in practice. As more practitioner frameworks converge on the same baseline elements, organizations that cannot document a structured program will face growing pressure from both regulators and counterparties in procurement and audit contexts.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Enforcement2026-09-22

NY Comptroller Audit Finds SUNY Lacked AI Definition, Inventory, or Approval Workflows

New York State Comptroller Thomas DiNapoli released an audit finding that SUNY Administration had no effective AI governance framework, no standard definition of AI, and no documented policies or approval workflows for AI development and use. The audit identified specific weaknesses in inventory management, policy controls, and internal accountability. The findings create a public-sector governance benchmark that compliance teams in both government and regulated industries should treat as a checklist.

Research2026-09-26

BIS Warns AI Strains Core Bank Supervisory Expectations on Model Governance

The Bank for International Settlements (BIS) published a speech on September 18, 2026, signaling that advanced AI and large language models (LLMs) are outpacing existing supervisory expectations for banks. The speech identifies governance, model validation, independent review, and explainability as the primary stress points. Banks and their enterprise counterparts in financial services should treat this as a forward signal that supervisors will raise the bar on AI model oversight.

Research2026-09-19

ISA Puts Agentic AI in Critical Infrastructure on Policymakers' Agenda

The Internet Security Alliance has briefed policymakers on the risks of deploying agentic AI in critical infrastructure. The briefing calls for regulatory action on autonomous system containment, third-party AI risk, and resilience planning. Critical infrastructure operators should treat this as a leading indicator of forthcoming binding guidance.