What Is AI Governance: 3 Critical Frameworks Every GRC Analyst Must Know
The definition of AI governance, why it differs from general cybersecurity governance, and the three frameworks every GRC analyst needs to know. Start here.
Seven posts covering AI governance from concept to program build. The cluster moves from what AI governance is, through the frameworks that define it, to the operational gaps GRC programs need to close before regulators and auditors do it for them.
The definition of AI governance, why it differs from general cybersecurity governance, and the three frameworks every GRC analyst needs to know. Start here.
The three distinctions that separate governing AI systems from complying with AI regulations, and why confusing them produces programs that satisfy auditors but fail to control AI.
The five steps for building an AI governance program from asset inventory to evidence trail, designed for GRC professionals without a dedicated AI team.
The five governance gaps created by agentic AI systems that decide and act without human approval at each step, and what GRC programs need to close before auditors find them.
A breakdown of the EU AI Act's four risk tiers, compliance obligations by tier, and what US organizations with EU exposure need to know before deploying AI systems.
The six key requirements of ISO 42001:2023, how the standard differs from ISO 27001:2022, and what implementation involves for GRC analysts.
The ten risks in the OWASP AI Top 10 explained for GRC programs, with guidance on mapping each risk to controls your organization already owns.