Know what governs it.
An inventory tells you what AI you have. Governance is the answer to the next question: who is accountable for it, what could it do to whom, which controls it actually requires, and how you would prove any of that if asked.
Not a policy document. An operating system for AI decisions.
Accountability
A named owner for every AI use, and a decision path when something changes — so ownership doesn't evaporate the moment the pilot ends.
Impact & risk
What each use could do, and to whom. Impact assessment aligned to ISO/IEC 42005, sized to the exposure rather than applied uniformly.
Controls
The controls your risks actually require — not a catalogue copied from a framework. Each one traceable to the risk it answers.
Evidence
Logging and records that reconstruct what happened, designed to satisfy a board question or an auditor without a scramble.
Operating processes
The routines that keep the register true: intake for new AI uses, review cadence, and change control.
Provenance
Every rule labelled at its source — a requirement, guidance, a certification constraint, or a method choice — so you always know why you're being asked for something.
The bridge between visibility and certification.
Governance builds directly on the AI Use Inventory and produces the management-system substance that ISO/IEC 42001 certification then examines. You can run it as a standalone program, or as the middle step of the full progression.
Led directly by Ramon J. Matos — CISSP, ISO/IEC 42001 Lead Implementer.
Discuss an AI Governance program.
We'll tell you whether it needs an inventory first, a full program, or executive ownership — and we'll say so if it's the last one.