Govern

Know what governs it.

An inventory tells you what AI you have. Governance is the answer to the next question: who is accountable for it, what could it do to whom, which controls it actually requires, and how you would prove any of that if asked.

What governance means here

Not a policy document. An operating system for AI decisions.

Accountability

A named owner for every AI use, and a decision path when something changes — so ownership doesn't evaporate the moment the pilot ends.

Impact & risk

What each use could do, and to whom. Impact assessment aligned to ISO/IEC 42005, sized to the exposure rather than applied uniformly.

Controls

The controls your risks actually require — not a catalogue copied from a framework. Each one traceable to the risk it answers.

Evidence

Logging and records that reconstruct what happened, designed to satisfy a board question or an auditor without a scramble.

Operating processes

The routines that keep the register true: intake for new AI uses, review cadence, and change control.

Provenance

Every rule labelled at its source — a requirement, guidance, a certification constraint, or a method choice — so you always know why you're being asked for something.

Where it sits

The bridge between visibility and certification.

Governance builds directly on the AI Use Inventory and produces the management-system substance that ISO/IEC 42001 certification then examines. You can run it as a standalone program, or as the middle step of the full progression.

Led directly by Ramon J. Matos — CISSP, ISO/IEC 42001 Lead Implementer.

Govern what you've discovered

Discuss an AI Governance program.

We'll tell you whether it needs an inventory first, a full program, or executive ownership — and we'll say so if it's the last one.