Governance risk
7 controls address this domain.
- directive
AI-CTRL-001
AI System Inventory and Classification
Maintain a complete, current, and classified inventory of all AI systems in development, deployment, and decommissioning to enable risk-based governance.
GovernanceISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +3v1.0.0 Reviewed 2026-05-01 - directive
AI-CTRL-005
AI Risk Assessment and Impact Assessment
Ensure that each AI system is subject to a documented risk assessment and AI System Impact Assessment (AIIA) aligned with ISO/IEC 23894 and ISO/IEC 42005, completed prior to production deployment and refreshed on material change or annually.
AI Risk ManagementISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +3v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-006
Human-in-the-Loop Design for High-Risk Decisions
Ensure that AI systems producing decisions with legal or similarly significant effects on individuals incorporate meaningful human oversight in the decision flow, with documented design, training, and audit trails.
Human OversightISO 42001 NIST AI RMF EU AI Act OWASP Agentic Top 10 +2v1.0.0 Reviewed 2026-05-01 - corrective
AI-CTRL-009
AI Incident Response Procedures
Maintain a tested AI-specific incident response capability that detects, triages, contains, and recovers from AI incidents (prompt injection, model misbehavior, data exfiltration, decision errors with material impact), with regulator notification per applicable rules.
Incident ManagementISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +3v1.0.0 Reviewed 2026-05-01 - directive
AI-CTRL-012
AI System Documentation and Model Cards
Maintain current, accessible technical documentation (model cards, datasheets, system cards) for every production AI system, sufficient to enable risk-based use, regulatory review, and downstream consumer understanding.
Transparency & ExplainabilityISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +1v1.0.0 Reviewed 2026-05-01 - directive
AI-CTRL-016
AI Acceptable Use Policy and User Training
Maintain a published, enforceable AI Acceptable Use Policy and deliver role-appropriate AI literacy training to employees, contractors, and other authorized users.
GovernanceISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +3v1.0.0 Reviewed 2026-05-01 - detective
AI-CTRL-020
Shadow AI Detection
Detect, triage, and remediate use of unsanctioned AI services and unauthorized AI tooling by employees, contractors, and other authorized users, with documented response and metrics.
GovernanceISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +4v1.0.0 Reviewed 2026-05-01