Skip to content

11 AI Governance, Controls and Responsible AI for GRC Professionals

Organizations are rapidly introducing Artificial Intelligence into:

  • customer services
  • cybersecurity
  • software development
  • HR
  • finance
  • marketing
  • legal operations
  • risk management
  • compliance
  • business analytics
  • enterprise decision-making

This creates tremendous opportunity.

It also creates new governance questions.

Which AI Systems
Are We Using?
Who Owns Them?
What Data
Do They Use?
What Decisions
Do They Influence?
What Risks
Do They Create?
What Controls
Are Required?
How Do We
Monitor Them?
Who Is
Accountable?

This is where GRC professionals become critical.

AI governance connects:

Business
+
Technology
+
Risk
+
Compliance
+
Security
+
Privacy
+
Responsible AI

The objective is not to prevent AI adoption.

The objective is to ensure AI is:

Authorized
Risk-Assessed
Controlled
Secure
Transparent
Monitored
Accountable

throughout its lifecycle.

By the end of this lesson, you will understand how to:

  • understand enterprise AI governance.

  • define AI governance principles.

  • establish an AI governance operating model.

  • create AI policies and standards.

  • build an enterprise AI system inventory.

  • classify AI systems and use cases.

  • perform AI risk assessments.

  • understand AI-specific risks.

  • establish AI control objectives.

  • build an AI control library.

  • govern AI models and data.

  • establish human oversight.

  • manage generative AI risks.

  • govern AI agents.

  • assess third-party AI providers.

  • manage AI incidents.

  • monitor AI systems continuously.

  • establish AI change management.

  • collect AI governance evidence.

  • perform AI assurance.

  • support AI audits.

  • understand responsible AI principles.

  • map AI governance to major frameworks.

  • understand NIST AI RMF.

  • understand ISO/IEC 42001.

  • understand ISO/IEC 23894.

  • integrate AI governance with enterprise GRC.

AI Governance is the system of:

Policies
Roles
Responsibilities
Processes
Controls
Standards
Oversight
Monitoring

used to ensure AI systems are developed and used responsibly.

A simplified model is:

AI Use Case
Business Purpose
Risk Assessment
Governance Requirements
Controls
Deployment
Monitoring
Human Oversight

2 — Why AI Governance Is a GRC Responsibility

Section titled “2 — Why AI Governance Is a GRC Responsibility”

AI creates risks across traditional organizational boundaries.

An AI system may simultaneously create:

Cybersecurity Risk
Privacy Risk
Operational Risk
Legal Risk
Compliance Risk
Third-Party Risk
Model Risk
Reputational Risk
Strategic Risk

No single technical team can govern all of these areas alone.

GRC provides the coordination layer.

3 — AI Governance Is Enterprise Governance

Section titled “3 — AI Governance Is Enterprise Governance”

AI governance should not exist as an isolated technology program.

It should connect with:

Enterprise Risk Management
Cybersecurity
Privacy
Compliance
Legal
Internal Audit
Third-Party Risk
Data Governance
Change Management
Incident Management

Organizations should establish approved principles for AI.

Common principles may include:

Accountability
Transparency
Security
Privacy
Fairness
Reliability
Safety
Human Oversight
Traceability

These principles must eventually become:

Principle
Policy
Control
Evidence

Otherwise they remain aspirational statements.

A mature operating model may involve:

Board / Executive Oversight
AI Governance Committee
GRC / Risk / Legal
AI System Owners
Technology Teams
Control Owners

Organizations may establish an:

AI Governance Committee

with representatives from:

Business
Technology
Security
Risk
Compliance
Legal
Privacy
Data
Internal Audit

Its responsibilities may include:

  • approving governance standards.

  • reviewing high-risk AI use cases.

  • resolving risk escalations.

  • reviewing exceptions.

  • monitoring material AI risks.

  • reviewing AI incidents.

  • overseeing responsible AI.

Important roles may include:

AI System Owner
Business Owner
Model Owner
Data Owner
Risk Owner
Control Owner
Security Owner
Privacy Owner
Compliance Owner

One person may perform multiple roles depending on the organization.

Organizations can define:

Responsible
Accountable
Consulted
Informed

for activities such as:

AI Approval
Risk Assessment
Model Deployment
Data Approval
Security Testing
Monitoring
Incident Response
Retirement

An enterprise AI policy establishes:

What AI
May Be Used
How AI
May Be Used
Who May
Use It
What Controls
Are Required

A policy may contain:

Purpose
Scope
Definitions
Approved AI Usage
Prohibited Usage
Risk Classification
Data Requirements
Security Requirements
Human Oversight
Third-Party Requirements
Incident Reporting
Monitoring
Exceptions
Enforcement

Organizations should define acceptable uses.

Examples might include:

Document Summarization
Code Assistance
Research Support
Data Analysis
Customer Support
Security Analysis

subject to approved controls.

Organizations may prohibit:

Uploading Restricted Data
to Unapproved AI Services
Unapproved Automated
High-Impact Decisions
Disabling Human Oversight
Circumventing Security Controls
Using Unapproved Models
for Sensitive Workloads

One major enterprise risk is:

Shadow AI

This occurs when employees use AI systems without:

Approval
Risk Assessment
Security Review
Privacy Review
Governance

Shadow AI is similar to:

Shadow IT

but can introduce additional data and decision risks.

You cannot govern what you do not know exists.

Organizations therefore need an:

Enterprise
AI Inventory

A useful inventory may contain:

AI System ID
System Name
Business Purpose
Business Owner
Technical Owner
Model
Provider
Data Used
Users
Deployment Environment
Risk Classification
Approval Status
Review Date
Lifecycle Status
AI-001
System:
Customer Support Assistant
Business Owner:
Customer Operations
Provider:
External AI Provider
Data:
Customer Support Records
Risk Tier:
High
Status:
Approved with Controls

Sometimes one AI platform supports multiple use cases.

Example:

Enterprise LLM Platform
Marketing Assistant
Security Assistant
HR Assistant
Developer Assistant

Each use case may have:

Different Data
Different Users
Different Risks
Different Controls

Therefore:

AI Platform Inventory
AI Use-Case Inventory

AI systems may be identified through:

Procurement
Vendor Management
Cloud Discovery
SaaS Discovery
Application Inventory
Employee Surveys
Security Monitoring
Expense Records

Not every AI use case creates the same level of risk.

Organizations can classify AI systems based on:

Business Impact
Decision Impact
Data Sensitivity
User Population
Autonomy
External Exposure
Regulatory Impact
Security Impact
Tier 1
Low Risk
Tier 2
Moderate Risk
Tier 3
High Risk
Tier 4
Critical / Restricted

The exact methodology should be organization-specific.

AI Used to
Summarize Public
Marketing Material

may present relatively limited risk.

AI Used to
Recommend Employee
Hiring Decisions

may require significantly greater governance.

Data Sensitivity
+
Decision Impact
+
Autonomy
+
External Exposure
AI Risk Tier

Before deployment, organizations should ask:

What Can
Go Wrong?
Why?
What Would
the Impact Be?
What Controls
Exist?
What Residual
Risk Remains?

An AI risk taxonomy may include:

Security Risk
Privacy Risk
Data Risk
Model Risk
Bias Risk
Accuracy Risk
Reliability Risk
Legal Risk
Compliance Risk
Third-Party Risk
Operational Risk
Reputational Risk

Generative AI may produce:

Confident
but
Incorrect Output

This is particularly important where AI supports:

Legal
Compliance
Security
Financial
Operational

decisions.

AI systems may produce outcomes that create:

Unfair
Inconsistent
Discriminatory
Unintended

effects.

GRC should ensure the organization has processes to:

Identify
Assess
Test
Monitor
Escalate

potential bias risks.

AI systems may process:

Personal Data
Sensitive Data
Employee Data
Customer Data
Behavioral Data

Privacy governance should consider:

Purpose
Lawful Processing
Minimization
Retention
Access
Disclosure
Data Subject Impact

AI systems introduce security concerns including:

Prompt Injection
Data Leakage
Unauthorized Access
Model Abuse
Insecure Integrations
Supply Chain Risk
Credential Exposure

AI models may behave differently due to:

Model Updates
Prompt Changes
Data Changes
Configuration Changes
Provider Changes
Context Changes

Therefore model behavior must be monitored.

AI depends heavily on data.

Poor data may create:

Incorrect Outputs
Bias
Privacy Exposure
Incomplete Decisions
Unreliable Analytics

The principle remains:

Poor Input
Poor Output

Some AI decisions may be difficult to explain.

This becomes especially important when AI affects:

Individuals
Customers
Employees
Financial Decisions
Regulated Processes

AI systems increasingly move from:

Recommendation

toward:

Action

An AI agent may:

Send Email
Modify Records
Execute Code
Call APIs
Create Tickets
Change Infrastructure

Autonomy increases governance requirements.

AI System
Business Purpose
Owner
Users
Data
Model
Provider
Decision Impact
Autonomy
Security Risk
Privacy Risk
Compliance Risk
Operational Risk
Third-Party Risk
Existing Controls
Residual Risk
Approval

Example:

There is a risk that
the customer-support
AI assistant generates
incorrect guidance
because model output
is not consistently
validated, resulting in
customer harm or
service disruption.

AI risks should integrate with:

Enterprise
Risk Management

rather than remain isolated in technical documentation.

Once risks are identified:

AI Risk
Control Objective
Control
Evidence

An enterprise AI control library may include:

AI Governance
AI Inventory
Risk Assessment
Data Governance
Security
Privacy
Model Governance
Human Oversight
Testing
Third-Party AI
Monitoring
Incident Management
Change Management
Documentation
Control ID:
AI-GOV-001
Control:
All production AI
systems must be
registered in the
enterprise AI inventory.
Owner:
AI Governance
Frequency:
Continuous
Evidence:
Approved AI inventory
Control ID:
AI-RISK-002
Control:
High-risk AI use cases
must complete an
AI risk assessment
before production
deployment.
Control ID:
AI-HUM-001
High-impact AI
decisions must include
defined human
oversight mechanisms.
AI
Generates
Recommendation
Human
Reviews
Human
Decides

This is commonly called:

Human-in-the-Loop

Some systems operate automatically while humans:

Monitor
Intervene
Override

when required.

This is often described as:

Human-on-the-Loop

A human clicking:

Approve

without reviewing the AI output is not meaningful oversight.

Oversight requires:

Information
Authority
Competence
Time
Ability to Override

Humans may over-trust AI because:

The System
Sounds Confident

This creates:

Automation Bias

Training and controls should address this risk.

Organizations should understand:

What Data
Enters AI?
Where Does
It Go?
How Long
Is It Retained?
Who Can
Access It?
Is It Used
for Training?

Before sending information to AI:

Data
Classification
Permitted AI Use

Example:

Public
Approved
Internal
Approved with Controls
Restricted
Prohibited or
Special Approval

AI systems should receive:

Only the Data
Necessary

for the approved purpose.

Employees may accidentally paste:

Passwords
API Keys
Customer Data
Source Code
Contracts
Security Findings

into unapproved AI systems.

Controls may include:

Policy
Training
DLP
Access Restrictions
Approved AI Platforms
Monitoring

Organizations should maintain information about:

Model
Version
Provider
Purpose
Configuration
Limitations
Testing
Approval
Model v1
Testing
Approved
Model v2
Reassessment

A model update can create:

New Risk

even when the application has not changed.

Material changes may include:

New Model
New Provider
New Training Data
New System Prompt
New Tools
New Data Sources
Changed Autonomy

These may require reassessment.

Proposed Change
Impact Assessment
Testing
Risk Review
Approval
Deployment
Monitoring

Testing may include:

Accuracy Testing
Security Testing
Bias Testing
Privacy Testing
Safety Testing
Performance Testing
Adversarial Testing
Human Oversight Testing

Maintain evidence such as:

Test Plan
Test Dataset
Results
Failures
Exceptions
Remediation
Approval

Generative AI introduces specific risks including:

Hallucination
Prompt Injection
Sensitive Data Leakage
Unsafe Output
Copyright Risk
Over-Reliance
Untrusted Content

Possible controls include:

Approved Models
Input Restrictions
Output Validation
Content Filtering
Access Controls
Logging
Human Review
Prompt Security
Data Classification

Prompts can become part of:

Application Logic

for AI systems.

Critical prompts may therefore require:

Version Control
Testing
Approval
Change Management

Changing:

System Prompt

may materially change:

AI Behavior

Therefore significant prompt changes may require governance review.

AI agents introduce a major shift.

Traditional AI:

Input
Output

AI agent:

Goal
Reasoning
Tool Selection
Action
Environment Change

Agents may be able to:

Read Files
Send Messages
Execute Commands
Modify Systems
Create Accounts
Call APIs
Access Databases

This increases:

Operational
and
Security Risk

Follow:

Least Privilege

An agent should receive only the permissions necessary for its approved purpose.

AI Agent
Approved Tools
Restricted Permissions
Action Guardrails
Human Approval
Logging

Actions such as:

Deleting Data
Changing Infrastructure
Sending Payments
Creating Accounts
Changing Permissions
Deploying Code

may require explicit human authorization.

Many organizations do not build their own AI.

They consume:

AI SaaS
Cloud AI Services
Foundation Models
AI APIs
Embedded AI

This creates third-party risk.

Assess:

Security
Privacy
Data Use
Retention
Training Practices
Model Governance
Incident Response
Availability
Subprocessors
Compliance
Contractual Protections

Ask:

Does the Provider
Use Our Data
to Train Models?

The answer may materially affect:

Privacy
Confidentiality
Intellectual Property
Security

risk.

Organization
AI Application
AI Platform
Foundation Model
Cloud Provider
Data / Tools

Multiple dependencies may exist.

Your AI provider may rely on:

Another Model Provider
Another Cloud Provider
External Data Sources

creating:

Fourth-Party
Dependencies

Assessment should not end at onboarding.

Monitor:

Model Changes
Terms Changes
Privacy Changes
Incidents
Security Changes
Subprocessor Changes
Compliance Changes

AI incidents may include:

Sensitive Data Disclosure
Unsafe Output
Unauthorized Action
Model Failure
Prompt Injection
Bias Event
Incorrect High-Impact Decision
Third-Party AI Failure
AI Event
Detection
Triage
Containment
Impact Assessment
Investigation
Remediation
Lessons Learned

Organizations should define:

What Constitutes
an AI Incident?

Otherwise events may not reach the correct governance teams.

Fields may include:

Incident ID
AI System
Date
Event
Impact
Affected Data
Affected Users
Root Cause
Containment
Remediation
Owner
Status

AI systems should be monitored for:

Performance
Accuracy
Security Events
Policy Violations
Data Drift
Model Drift
User Complaints
Control Failures
Incidents

Model behavior may change over time because:

Environment Changes
Data Changes
User Behavior Changes
Model Changes

This is commonly described as:

Model Drift

Input data may change compared with the data expected by the system.

Expected Data
Environment Changes
New Data Pattern
Performance Changes
AI System
Telemetry
Control Signals
Risk Monitoring
GRC Dashboard
Human Review

Potential AI KRIs may include:

AI Systems
Without Owners
High-Risk AI
Without Assessment
AI Incidents
Unapproved AI Usage
Failed Model Tests
Overdue AI Reviews
High-Risk Vendor Findings

Potential AI governance KPIs may include:

Percentage of AI Systems
Registered
Percentage of High-Risk AI
Assessed Before Deployment
AI Reviews
Completed on Time
AI Findings
Remediated on Time

GRC should maintain evidence including:

AI Inventory
Risk Assessments
Approvals
Policies
Control Tests
Model Documentation
Data Assessments
Vendor Assessments
Monitoring Reports
Incident Records
Training Records
AI Requirement
Control
Implementation
Evidence
Testing
Assurance

AI assurance asks:

Are the
Governance Controls
Designed Appropriately?
Are They
Operating?
Is Evidence
Available?
Are Risks
Being Managed?

Example:

Control:
All high-risk AI
systems require
risk assessment.

Testing:

Population:
20 High-Risk Systems
Sample:
5 Systems
Expected:
Approved Risk Assessment
Observed:
4 Available
1 Missing

Result:

Potential
Control Exception

Internal Audit may evaluate:

Governance
Inventory Completeness
Risk Assessments
Control Design
Control Operation
Human Oversight
Vendor Governance
Monitoring
Incident Management

For important AI actions, preserve:

User
AI System
Input
Relevant Context
Output
Action
Approval
Timestamp

subject to privacy and retention requirements.

Organizations may need to explain:

What AI
Was Used?
Why?
What Data?
What Output?
How Was
the Decision Made?
What Human
Oversight Existed?

Responsible AI is the practice of designing, deploying and using AI in ways aligned with organizational values and governance expectations.

Common themes include:

Fairness
Transparency
Accountability
Privacy
Security
Reliability
Safety
Human Oversight

89 — Responsible AI Must Become Controls

Section titled “89 — Responsible AI Must Become Controls”

Weak approach:

We Value
Transparency

Stronger approach:

Principle:
Transparency
Policy Requirement
AI Documentation Control
Evidence

Every production AI system should have:

Named
Accountability

Avoid:

The AI
Made the Decision

The organization remains accountable for how AI is used.

The NIST AI Risk Management Framework provides a structured approach to managing AI risks.

Its core functions are:

GOVERN
MAP
MEASURE
MANAGE

GOVERN establishes:

Policies
Roles
Responsibilities
Culture
Risk Processes
Accountability

MAP helps organizations understand:

Context
Purpose
Users
Impacts
Dependencies
Potential Risks

MEASURE focuses on:

Testing
Assessment
Metrics
Risk Analysis
Performance Evaluation

MANAGE focuses on:

Prioritizing Risk
Risk Treatment
Monitoring
Response
Improvement
GOVERN
MAP
MEASURE
MANAGE

Governance operates across the lifecycle.

ISO/IEC 42001 provides requirements for an:

Artificial Intelligence
Management System

or:

AIMS

It helps organizations establish systematic governance around AI.

Conceptually:

AI Policy
Objectives
Risk Management
Controls
Operation
Monitoring
Improvement

This is similar to other management-system approaches:

Plan
Do
Check
Act

ISO/IEC 23894 provides guidance related to:

AI
Risk Management

It can help organizations integrate AI-specific risk considerations with broader risk management practices.

Organizations do not necessarily need separate governance programs for every framework.

Instead:

Enterprise AI
Governance Program
Common Controls
NIST AI RMF
ISO/IEC 42001
ISO/IEC 23894
Internal Policies
Applicable Regulations

Example:

AI-INV-001
AI Inventory

may support multiple:

Frameworks
Policies
Regulatory Requirements
External Requirement
AI Requirement
Common AI Control
Evidence

This reduces duplicate compliance work.

AI regulations may introduce requirements concerning:

Risk Management
Transparency
Documentation
Human Oversight
Data Governance
Monitoring
Incident Reporting

GRC teams should incorporate these into the regulatory change process.

Maintain:

Jurisdiction
Regulation
Requirement
Applicability
Affected AI Systems
Control Mapping
Owner
Effective Date
Status
Business
Proposes AI
AI Inventory
Risk Classification
Risk Assessment
Security Review
Privacy Review
Compliance Review
Approval
Deployment
Monitoring

Not every use case requires every review.

Risk determines governance depth.

Avoid treating:

AI Summarizing
Public Documents

exactly the same as:

AI Making
High-Impact Decisions

Governance should be:

Proportionate
to Risk

Sometimes a system cannot fully meet a control.

Use:

Exception Request
Risk Assessment
Compensating Controls
Approval
Expiration
Review

A common risk pattern is:

Temporary
Exception
Renewal
Renewal
Permanent Exposure

AI governance dashboards should identify repeated exceptions.

Governance should cover:

Idea
Design
Development
Testing
Approval
Deployment
Operation
Change
Retirement

Retirement should address:

Access Removal
Data Retention
Model Access
Vendor Termination
Evidence Preservation
Inventory Update

Leadership may monitor:

Total AI Systems
High-Risk AI Systems
Unapproved AI
Open AI Risks
AI Control Findings
AI Incidents
Vendor Issues
Overdue Reviews
Exceptions

Example:

AI Systems
Risk Tier
Owners
Assessments
Controls
Findings
Incidents
Monitoring

Potential metrics:

AI Inventory Coverage
Risk Assessment Coverage
Control Testing Coverage
Review Completion
Incident Trend
Exception Aging
Vendor Review Status
High-Risk AI Exposure

Executives should understand:

Where Are We
Using AI?
Where Is
Risk Highest?
Are Controls
Working?
What Is
Changing?
What Requires
Decision?

Board reporting may focus on:

AI Adoption
Material AI Risks
High-Risk Use Cases
Regulatory Exposure
Major AI Incidents
Management Response
Strategic Opportunities

A mature program may maintain:

AI Policy
AI Standard
AI Inventory
AI Risk Methodology
AI Control Library
AI Assessment Template
AI Vendor Questionnaire
AI Incident Procedure
AI Monitoring Standard
AI Exception Process

A simplified model:

First Line
Business / Technology
Own AI Risk
Second Line
Risk / GRC / Compliance
Provide Oversight
Third Line
Internal Audit
Provides Independent Assurance

Business and technology teams should:

Own AI Systems
Implement Controls
Manage Risks
Maintain Evidence
Monitor Performance

GRC and risk functions may:

Define Framework
Challenge Assessments
Monitor Risk
Review Exceptions
Provide Oversight

Internal Audit may independently assess:

Governance
Risk Management
Control Design
Control Operation
Evidence

122 — AI Governance Is Not Only a Technology Problem

Section titled “122 — AI Governance Is Not Only a Technology Problem”

A technically secure AI system can still create:

Privacy Risk
Legal Risk
Bias Risk
Operational Risk
Compliance Risk

Therefore:

Secure AI
Fully Governed AI

123 — AI Governance Is Not Only Compliance

Section titled “123 — AI Governance Is Not Only Compliance”

Similarly:

Compliant AI
Risk-Free AI

Governance should consider:

Risk
Security
Privacy
Reliability
Business Impact
Ethics
Compliance

GRC professionals may help:

Build AI Policies
Maintain AI Inventory
Assess AI Risk
Design Controls
Map Frameworks
Review Vendors
Monitor Compliance
Manage Exceptions
Support Assurance
Report to Leadership
Ad Hoc AI
Shadow AI
No Inventory
No Formal Governance
AI Policy
Approved Tools
Basic Inventory
Basic Reviews
AI Classification
Risk Assessments
AI Controls
Human Oversight
AI Risk
+
Enterprise Risk
+
Security
+
Privacy
+
Compliance
+
Vendor Risk
AI Inventory
Continuous Monitoring
Control Signals
Risk Intelligence
Human Governance

126 — Enterprise AI Governance Architecture

Section titled “126 — Enterprise AI Governance Architecture”
Board / Executives
AI Governance Committee
Enterprise AI Policy
AI Inventory
Risk Classification
AI Risk Assessment
Control Framework
Testing / Approval
Deployment
Continuous Monitoring
Assurance
AI Idea
Business Purpose
Inventory
Classification
Risk Assessment
Controls
Testing
Approval
Deployment
Monitoring
Change Management
Incident Management
Reassessment
Retirement

Practical Exercise 1 — Build an AI Inventory

Section titled “Practical Exercise 1 — Build an AI Inventory”

Create a fictional enterprise with:

15 AI Systems

Include:

System
Purpose
Owner
Provider
Data
Users
Risk Tier
Approval Status

Identify systems missing:

Owner
Risk Assessment
Approval

Practical Exercise 2 — Classify AI Use Cases

Section titled “Practical Exercise 2 — Classify AI Use Cases”

Classify these examples:

Marketing
Content Assistant
Developer
Coding Assistant
Security
Investigation Assistant
Customer
Support Assistant
Employee
Recruitment AI

Using:

Data Sensitivity
Decision Impact
Autonomy
External Exposure

Assign candidate risk tiers.

Practical Exercise 3 — AI Risk Assessment

Section titled “Practical Exercise 3 — AI Risk Assessment”

Perform an AI risk assessment for:

Customer Support
AI Assistant

Identify:

Security Risk
Privacy Risk
Hallucination Risk
Operational Risk
Third-Party Risk
Controls
Residual Risk

Practical Exercise 4 — Build an AI Control Library

Section titled “Practical Exercise 4 — Build an AI Control Library”

Create controls across:

Governance
Inventory
Risk
Security
Privacy
Data
Human Oversight
Third Parties
Monitoring
Incident Management

Create at least:

20 AI Controls

Practical Exercise 5 — Generative AI Risk Assessment

Section titled “Practical Exercise 5 — Generative AI Risk Assessment”

Assess an enterprise GenAI assistant for:

Prompt Injection
Data Leakage
Hallucination
Unsafe Output
Unauthorized Access
Over-Reliance

Map controls to each risk.

Practical Exercise 6 — AI Agent Assessment

Section titled “Practical Exercise 6 — AI Agent Assessment”

Scenario:

AI Agent
Can Read Email,
Create Tickets
and Call APIs

Assess:

Permissions
Autonomy
Human Approval
Logging
Security
Failure Scenarios

Practical Exercise 7 — AI Vendor Assessment

Section titled “Practical Exercise 7 — AI Vendor Assessment”

Assess a fictional AI SaaS provider.

Evaluate:

Security
Privacy
Data Retention
Training Use
Subprocessors
Incident Management
Compliance
Contract Terms

Scenario:

Employee Uploads
Sensitive Customer Data
to an Unapproved
AI Platform

Create:

Incident Record
Impact Assessment
Containment Plan
Root Cause
Corrective Actions

Test:

AI-RISK-002
High-Risk AI
Must Complete
Risk Assessment
Before Deployment

Create:

Population
Sample
Evidence
Exceptions
Test Result

Practical Exercise 10 — NIST AI RMF Mapping

Section titled “Practical Exercise 10 — NIST AI RMF Mapping”

Take the AI governance controls created earlier and map them to:

GOVERN
MAP
MEASURE
MANAGE

Practical Exercise 11 — AI Governance Dashboard

Section titled “Practical Exercise 11 — AI Governance Dashboard”

Create a fictional dashboard containing:

40 AI Systems
8 High Risk
3 Unapproved
6 Open Risks
4 Open Findings
2 AI Incidents
5 Overdue Reviews

Prepare an executive summary.

Practical Exercise 12 — AI Governance Committee

Section titled “Practical Exercise 12 — AI Governance Committee”

Design an:

AI Governance Committee

Define:

Members
Responsibilities
Meeting Frequency
Escalation Criteria
Approval Authority
Reporting

Practical Exercise 13 — AI Governance Program

Section titled “Practical Exercise 13 — AI Governance Program”

Build an enterprise AI governance program containing:

AI Policy
AI Inventory
Risk Methodology
Control Library
Approval Workflow
Vendor Assessment
Incident Procedure
Monitoring
Assurance
Executive Reporting
  1. What is AI governance?

  2. Why is AI governance relevant to GRC?

  3. Why should AI governance integrate with enterprise risk management?

  4. What is an AI governance operating model?

  5. What is the purpose of an AI policy?

  6. What is Shadow AI?

  7. Why is an AI inventory necessary?

  8. Why should AI platforms and AI use cases sometimes be inventoried separately?

  9. What factors can be used to classify AI risk?

  10. What is an AI risk assessment?

  11. What are common AI risk categories?

  12. What is hallucination risk?

  13. What is automation bias?

  14. What is autonomy risk?

  15. Why is AI data governance important?

  16. Why should model versions be tracked?

  17. What AI changes may require reassessment?

  18. What is meaningful human oversight?

  19. What risks are introduced by generative AI?

  20. Why should critical prompts be governed?

  21. Why do AI agents require stronger governance?

  22. How does least privilege apply to AI agents?

  23. What should an AI vendor assessment cover?

  24. What is fourth-party AI risk?

  25. What constitutes an AI incident?

  26. What is model drift?

  27. What is data drift?

  28. What evidence supports AI governance?

  29. What is AI assurance?

  30. What is Responsible AI?

  31. What are the four NIST AI RMF functions?

  32. What is ISO/IEC 42001?

  33. What is ISO/IEC 23894?

  34. Why are common AI controls useful?

  35. How does risk-based AI governance work?

  36. What should happen when an AI system changes?

  37. Why must AI exceptions expire?

  38. What should AI retirement address?

  39. How do the Three Lines apply to AI governance?

  40. Who remains accountable for AI decisions?

AI governance connects:

AI
+
Business
+
Risk
+
Security
+
Privacy
+
Compliance
+
Human Oversight

The fundamental lifecycle is:

AI Use Case
Inventory
Classification
Risk Assessment
Controls
Testing
Approval
Deployment
Monitoring
Assurance

Remember:

AI Adoption
AI Governance

and:

AI Policy
AI Control

and:

AI Output
Human Decision

and:

Secure AI
Fully Governed AI

and:

Compliant AI
Risk-Free AI

A mature governance model establishes:

Principle
Policy
Risk
Control
Evidence
Monitoring
Assurance

The objective is not:

Stop AI

The objective is:

Govern AI
According to Risk

AI governance is becoming an important capability for:

GRC Analysts
AI Governance Analysts
Cyber Risk Analysts
Technology Risk Professionals
Privacy Professionals
Compliance Analysts
IT Auditors
Third-Party Risk Analysts
Security Assurance Professionals
GRC Managers
AI Risk Consultants

Traditional GRC professionals understand:

Risk
Controls
Compliance
Audit
Governance

AI governance professionals extend this knowledge into:

AI Systems
AI Models
AI Data
AI Agents
AI Vendors
AI-Specific Risks

This creates an increasingly important professional capability:

Traditional GRC
+
AI Understanding
AI Governance
Professional

➡️ Next: 12 — Building an Enterprise AI-Enabled GRC Operating Model

You have now learned how AI can support individual GRC activities and how organizations can govern AI itself.

The next step is to bring everything together.

In the next lesson, you will design an enterprise operating model connecting:

Policies
Risk
Controls
Compliance
Evidence
Audit
Third Parties
Regulatory Change
AI Governance
Executive Reporting

with:

People
+
Process
+
Technology
+
Data
+
AI

You will learn how to establish:

GRC Roles and Responsibilities
GRC Data Architecture
AI-Assisted Workflows
Human Approval Gates
GRC Knowledge Architecture
Control Ownership
Evidence Automation
GRC Integration Patterns
AI Governance Boundaries
Continuous Monitoring
GRC Metrics
Management Oversight
Three Lines Integration
Implementation Roadmap

The goal is to move from:

Individual
AI-Assisted
GRC Tasks

toward:

Enterprise
AI-Enabled
GRC

where AI supports the entire lifecycle:

Requirement
Policy
Risk
Control
Implementation
Evidence
Testing
Finding
Remediation
Reporting
Decision

while humans retain:

Judgment
Authority
Oversight
Accountability

➡️ Next: 12 — Building an Enterprise AI-Enabled GRC Operating Model