AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

← News
Research2026-08-17

Keyrus 2026 Guide Sets a Baseline Operating Model for AI Governance Programs

What happened

Keyrus published AI in 2026: How to Build Trustworthy, Safe and Governed AI Systems, a practitioner guide designed to help enterprise compliance and risk teams build or mature their AI governance programs. The guide identifies four structural pillars: an AI system inventory, a risk prioritization framework, cross-functional governance ownership, and third-party oversight for vendor-supplied models. It recommends pairing governance workflows with runtime monitoring, documentation standards, and continuous feedback loops. The guidance is global in scope and is not tied to a specific regulatory jurisdiction, though its operating model maps closely to requirements emerging under frameworks such as ISO/IEC 42001:2023 and the EU AI Act. The guide arrives as a growing body of practitioner research, including the KPMG-UTS case study, is converging on the same foundational gaps in enterprise AI governance.

Why it matters

  • ·An AI inventory is increasingly a regulatory prerequisite, not a best practice. Regulators under the EU AI Act, several US state laws, and ISO/IEC 42001:2023 expect organizations to demonstrate they know what AI systems they operate and at what risk level, making a complete inventory the first control auditors will probe.
  • ·Third-party and vendor-supplied model risk remains one of the least-governed areas in enterprise AI programs. The Keyrus guide calls for structured vendor oversight as a core program element, a gap also identified in incidents such as the KPMG model risk framing, where vendor models sitting inside existing workflows often escape the scrutiny applied to internally developed systems.
  • ·Cross-functional governance structures are becoming an audit expectation, not an organizational preference. Without a defined committee with documented decision rights and membership, compliance teams cannot demonstrate consistent accountability when an AI incident occurs or a regulator requests evidence of oversight.

Governance controls affected

What to do now

  • Conduct a gap assessment against the four pillars in the Keyrus guide: inventory completeness, risk prioritization methodology, governance team structure, and vendor model oversight coverage.
  • Verify that your AI system inventory includes vendor-supplied and embedded models, not only internally developed systems, and confirm each entry has an assigned risk classification.
  • Review your cross-functional governance committee charter against the guide's cross-functional ownership model to confirm it defines decision rights, escalation paths, and accountability for AI incidents.
  • Map your current runtime monitoring controls to the guide's continuous feedback loop requirement and identify systems that have no post-deployment performance or drift monitoring in place.
  • Update third-party AI risk assessments to require vendor disclosure of model updates, safety commitments, and incident notification timelines as a contract condition.

What to watch next

Compliance teams should monitor whether upcoming enforcement actions under the EU AI Act begin to cite incomplete inventories or absent cross-functional governance bodies as deficiencies, as this would convert the Keyrus guide's recommendations into de facto regulatory expectations. Certification activity under ISO/IEC 42001:2023 is also worth tracking, since auditors are beginning to develop consistent interpretations of what a conforming governance operating model looks like in practice. As more practitioner frameworks converge on the same baseline elements, organizations that cannot document a structured program will face growing pressure from both regulators and counterparties in procurement and audit contexts.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-08-10

Bluewave's 90-Day Blueprint Gives Compliance Teams a Phased Governance Starter Model

Bluewave Technology Group has published a phased implementation guide outlining how organizations can stand up a foundational AI governance program within 90 days. The blueprint sequences controls across three phases, beginning with scope definition, a working group, an acceptable use policy, and an AI inventory, then adds ownership structures, approval tollgates, observability, and vendor and privacy review questions. It is designed as a practical starter model for compliance teams that have not yet formalized AI governance.

Research2026-08-17

KPMG Frames AI Governance as a Model Risk Problem, Not a Separate Silo

KPMG has published a guide positioning AI oversight as an extension of existing model risk management structures rather than a standalone governance program. The guide organizes AI oversight around four pillars: governance, development, validation, and monitoring. Compliance teams are advised to integrate AI controls into familiar model risk frameworks rather than build parallel processes.

Research2026-08-14

KPMG-UTS Case Study Sets a Practitioner Benchmark for AI Governance Operating Models

The University of Technology Sydney and KPMG published a joint case study documenting KPMG's practical experience building an enterprise AI governance program. The paper, part of UTS's Lighthouse series, details how governance controls, accountability structures, and operating arrangements were developed and implemented. It represents one of the few publicly available, practitioner-led implementation accounts from a major professional services firm.