02Program

AI governance services: ISO/IEC 42001 readiness, NIST AI RMF alignment and AI risk management

Governance for organizations adopting and building AI: an inventory of the AI systems in use, a usage policy people can follow, a risk assessment method for each system, and the controls and records that ISO/IEC 42001, the NIST AI Risk Management Framework and the EU AI Act expect. Sized to the organization, and built with the teams that use AI.

Name
AI Governance
Line
02 · AI
Type
Outcome program, combines several practices

01The problem

AI is already in use, and governance is being asked for after the fact.

Employees use public assistants with company data, product teams add LLM features to applications, and vendors switch on AI inside tools you already license. Boards, customers and regulators now ask who approved each use, what data it touches, how its risks were assessed and who is accountable when it fails. Most organizations cannot answer from records.

The frameworks exist: ISO/IEC 42001 defines an AI management system, the NIST AI RMF structures risk work around Govern, Map, Measure and Manage, and the EU AI Act attaches obligations to specific system categories on a phased timetable. The work is to turn them into a program that fits how the organization already builds and buys technology.

02Scope

What the AI governance program covers.

  • AI system inventory

    A register of the AI systems built, bought and embedded in licensed tools, with owner, purpose, data, model and risk classification for each.

  • AI usage policy and approved tools

    Rules for who may use which tools, with which data, for which purposes, written so people follow them instead of working around them.

  • AI risk assessment method

    A repeatable assessment for each system covering data, model behavior, security, fairness, transparency and human oversight, proportionate to its impact.

  • ISO/IEC 42001 readiness

    Gap assessment against the AI management system standard, policy and process design, control implementation and internal audit ahead of certification by an accredited body.

  • NIST AI RMF alignment

    Mapping of governance roles, risk mapping, measurement and management activities to the four functions, with the evidence for each.

  • Regulatory mapping

    Which obligations apply under the EU AI Act, sector regulators and data protection law for each system, and what must be documented or disclosed.

  • Vendor and embedded AI review

    Due diligence for AI features inside SaaS and for third-party models, including data use, retention and the controls available to you.

  • Oversight and reporting

    Committee cadence, metrics and incident handling for AI, with reporting that gives leadership a current view.

03Approach

How an AI governance engagement runs.

ISO/IEC 42001:2023 for the management system, the NIST AI RMF 1.0 and its Generative AI Profile for risk work, and the OWASP Top 10 for LLM Applications and MITRE ATLAS for security threats. Research methods come from [AI security research](/security-labs/ai-security) in Security Labs, and discovery of AI in use informs the design of [ARGUS](/products/argus), our AI discovery product in development.

  1. Inventory

    Find the AI already in use across teams, products and vendors. Classify each system by purpose, data and impact. Governance that skips this step governs the wrong things.

  2. Set policy and roles

    Agree the usage policy, the approval path for new systems, and who owns AI risk. Keep it short enough to be read.

  3. Assess risk per system

    Apply the assessment method to the systems that matter most first. Security testing of LLM applications is delivered through AI security.

  4. Implement controls and records

    Data handling rules, access control, evaluation, monitoring, human oversight and documentation implemented with the teams that build and run each system.

  5. Audit and sustain

    Internal audit against ISO/IEC 42001 or the chosen framework, management review, and a cadence for re-assessing systems as models and uses change.

04Outcomes

What the AI governance program is built to achieve.

  • An AI system inventory with owners and risk classifications
  • A usage policy and approval path that people follow
  • A risk assessment method applied to the systems that matter most
  • Controls and records aligned to ISO/IEC 42001 or the NIST AI RMF
  • A regulatory obligation map per system
  • A defensible answer when boards, customers and regulators ask how AI is governed

When this work fits

  • Organizations whose staff already use AI assistants and whose leadership wants it governed rather than banned
  • Product teams shipping LLM features that customers and procurement ask questions about
  • Companies pursuing ISO/IEC 42001 or asked to show NIST AI RMF alignment
  • Regulated organizations mapping EU AI Act or sector obligations to specific systems

05Questions

AI governance: questions we are asked

ISO/IEC 42001:2023 is the international standard for an AI management system: the policies, roles, risk assessment, controls and continual improvement an organization uses to develop or use AI responsibly. It follows the same management system structure as ISO 27001, so organizations holding that certificate can extend what they have. Certification is issued by accredited bodies; we provide readiness and implementation support.

Governance decides which systems may exist, for which purposes, with which data and under whose accountability. Security tests and hardens those systems against misuse such as prompt injection and data leakage. One produces the inventory and the policy; the other produces the findings and fixes. Both are delivered here, through this program and AI security.

It applies to providers and deployers of AI systems placed on the EU market or whose output is used in the EU, with obligations graded by risk category and phased in over time. Whether a specific system is in scope depends on its purpose and use. We map each system in your inventory against the categories and document the result; legal interpretation stays with your counsel.

Embedded AI features in SaaS are added to the inventory like any other system, with the vendor’s data use, retention and opt-out controls recorded. The usage policy then says which features may be enabled for which data. Discovery of AI in use is also the problem our product ARGUS, in development, is designed to address.

Working with us

What every engagement rests on.

Non-disclosure agreements
Every engagement is governed by an NDA. Details of your environment, findings and deliverables stay within the engagement.
Least-privilege access
The minimum access the work requires, tied to named individuals and removed when the work ends.
Telemetry stays in your tenant
In security operations, our analysts work inside your SIEM, EDR or cloud console in preference to exporting logs to systems we run.
End of engagement
Access is handed back, and your information is returned or deleted as agreed with you.

Onion Information Security Solutions Private Limited · CIN U62099MH2025PTC443498 · Registered office in Mumbai, India