Keyrus 2026 Guide Sets a Baseline Operating Model for AI Governance Programs
What happened
Keyrus published AI in 2026: How to Build Trustworthy, Safe and Governed AI Systems, a practitioner guide designed to help enterprise compliance and risk teams build or mature their AI governance programs. The guide identifies four structural pillars: an AI system inventory, a risk prioritization framework, cross-functional governance ownership, and third-party oversight for vendor-supplied models. It recommends pairing governance workflows with runtime monitoring, documentation standards, and continuous feedback loops. The guidance is global in scope and is not tied to a specific regulatory jurisdiction, though its operating model maps closely to requirements emerging under frameworks such as ISO/IEC 42001:2023 and the EU AI Act. The guide arrives as a growing body of practitioner research, including the KPMG-UTS case study, is converging on the same foundational gaps in enterprise AI governance.
Why it matters
- ·An AI inventory is increasingly a regulatory prerequisite, not a best practice. Regulators under the EU AI Act, several US state laws, and ISO/IEC 42001:2023 expect organizations to demonstrate they know what AI systems they operate and at what risk level, making a complete inventory the first control auditors will probe.
- ·Third-party and vendor-supplied model risk remains one of the least-governed areas in enterprise AI programs. The Keyrus guide calls for structured vendor oversight as a core program element, a gap also identified in incidents such as the KPMG model risk framing, where vendor models sitting inside existing workflows often escape the scrutiny applied to internally developed systems.
- ·Cross-functional governance structures are becoming an audit expectation, not an organizational preference. Without a defined committee with documented decision rights and membership, compliance teams cannot demonstrate consistent accountability when an AI incident occurs or a regulator requests evidence of oversight.
Governance controls affected
What to do now
- ☐Conduct a gap assessment against the four pillars in the Keyrus guide: inventory completeness, risk prioritization methodology, governance team structure, and vendor model oversight coverage.
- ☐Verify that your AI system inventory includes vendor-supplied and embedded models, not only internally developed systems, and confirm each entry has an assigned risk classification.
- ☐Review your cross-functional governance committee charter against the guide's cross-functional ownership model to confirm it defines decision rights, escalation paths, and accountability for AI incidents.
- ☐Map your current runtime monitoring controls to the guide's continuous feedback loop requirement and identify systems that have no post-deployment performance or drift monitoring in place.
- ☐Update third-party AI risk assessments to require vendor disclosure of model updates, safety commitments, and incident notification timelines as a contract condition.
What to watch next
Compliance teams should monitor whether upcoming enforcement actions under the EU AI Act begin to cite incomplete inventories or absent cross-functional governance bodies as deficiencies, as this would convert the Keyrus guide's recommendations into de facto regulatory expectations. Certification activity under ISO/IEC 42001:2023 is also worth tracking, since auditors are beginning to develop consistent interpretations of what a conforming governance operating model looks like in practice. As more practitioner frameworks converge on the same baseline elements, organizations that cannot document a structured program will face growing pressure from both regulators and counterparties in procurement and audit contexts.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
