AI Governance

Govern AI before it governs you.

For most organizations, governance is the fix-first pillar. A staffer can paste a confidential brief into a consumer tool today, and no policy says they cannot.

Done well, governance flips from a brake into an advantage: the firms that can prove control win the regulated, enterprise, and high-trust work everyone else is locked out of.

The governance climb

From hope, to a proven advantage.

The Governance & Risk pillar climbs the same six tiers, from no policy and nothing but hope, to an enforced system clients buy.

6

Autonomous

Governance is a proven advantage clients buy, audited and continuously hardened.

5

Integrated

Enterprise tooling with retention controls segments sensitive data across every team.

4

Operational

A written policy is read and followed, with real controls on confidential data.

3

Adopting

A policy is being drafted and one team discloses AI use, but coverage is partial.

2

Reactive

An informal understanding exists, but nothing is written, consistent, or enforced.

1

Legacy

No AI policy exists, and nothing but hope keeps confidential briefs out of consumer tools.

The frameworks

The standards everyone is converging on.

FrameworkScopeWhat it asks of you
NIST AI RMFUS, voluntaryStand up an AI risk function (Govern, Map, Measure, Manage), inventory AI use, and measure and manage model risk continuously.
EU AI ActEU, regulationClassify AI systems by risk tier, meet transparency and documentation duties, and avoid prohibited uses.
ISO/IEC 42001International, certifiableOperate a governed AI management system with policy, named roles, lifecycle controls, and continual improvement.
SOC 2AttestationProve security and confidentiality controls over the data and systems your AI touches before clients trust it.

Illustrative summaries for planning, not legal or compliance advice; validate against current regulation with qualified counsel.

By sector

Your regulatory reality, mapped.

Every sector carries its own regimes onto the governance pillar. Open your industry for the full crosswalk.

Agencies
4 regimes mapped

Client confidentiality and NDAs · IP and work-for-hire terms · FTC guidance on AI claims and endorsements · Copyright and training-data rights

See the crosswalk →
Healthcare
4 regimes mapped

HIPAA Privacy and Security Rules · HITECH Act · FDA oversight of clinical AI (SaMD and clinical decision support) · ONC information-blocking rule (21st Century Cures Act)

See the crosswalk →
Financial Services
4 regimes mapped

Model-Risk Governance (SR 11-7 / OCC 2011-12) · Fair Lending (ECOA / Reg B, FCRA) · GLBA Safeguards Rule · SEC / FINRA (Reg S-P, Rule 17a-4, marketing rules)

See the crosswalk →
Government
4 regimes mapped

FedRAMP / StateRAMP · FISMA (NIST SP 800-53) · NIST AI RMF (AI 100-1) · OMB AI memos (M-24-10 / M-24-18)

See the crosswalk →
Education
4 regimes mapped

FERPA · COPPA · State student-data-privacy laws (e.g. SOPIPA, NY Ed Law 2-d) · IDEA / Section 504

See the crosswalk →
Manufacturing
4 regimes mapped

IEC 62443 (OT/ICS security) · NIST AI RMF · ISO 9001 (Quality Management) · Export Controls (ITAR / EAR)

See the crosswalk →
Legal
4 regimes mapped

ABA Model Rule 1.1 (Competence), Comment 8 · ABA Model Rule 1.6 (Confidentiality of Information) · ABA Model Rule 5.3 (Responsibilities Regarding Nonlawyer Assistance) · Attorney-Client Privilege and Work-Product Doctrine

See the crosswalk →
Professional Services
4 regimes mapped

Client confidentiality and engagement letters · SOC 2 (Trust Services Criteria) · AICPA Code of Professional Conduct and quality management standards · GDPR and US state privacy laws (CCPA/CPRA)

See the crosswalk →
Retail
4 regimes mapped

PCI-DSS v4.0 · CCPA / CPRA (California) · CAN-SPAM Act · TCPA

See the crosswalk →
Nonprofit
4 regimes mapped

Donor data privacy (state privacy laws, PCI DSS for online gifts, CRM data handling) · Grant compliance and funder reporting requirements (2 CFR 200 Uniform Guidance, OMB cost principles) · 501(c)(3) charitable purpose and nonpartisanship constraints (IRS Form 990, lobbying and political-activity limits) · Ethical use of beneficiary data (informed consent, HIPAA where health services apply, FERPA where education applies)

See the crosswalk →

Make governance your edge.

Score your readiness and start with the pillar that matters most.

See where you stand