← All domains

Governance & ComplianceView domain

APRF-29

Organizational Governance

AI policy, ownership, risk acceptance, and continual improvement—ISO 42001-style management system.

Purpose

Establish organizational AI policy, clear ownership/RACI, risk-acceptance authority, and continual improvement so technical pillars have accountable stewards.

Engineering philosophy

Technical controls without organizational governance drift. A production-ready AI program names owners, accepts residual risk explicitly, and improves from incidents and audits.

Why it matters

Enterprises fail AI readiness when no one owns a pillar, exceptions are informal, and leadership cannot see residual risk.

Common failures

  • AI features ship with no named owner for safety or eval gates
  • Exceptions granted in chat with no expiry
  • No AI policy covering acceptable use and prohibited applications
  • Compliance theater without leadership review of risk

Mandatory checks

Gate controls. Each check is pass/fail via artifact + pass condition. Expected from the annotated capability level when the system meets the minimum criticality tier.

  • ORG-M1L3 · DefinedTier 2 · Productionmanual

    Documented AI policy covering acceptable use and prohibited applications shall exist

    Artifact
    Approved AI acceptable-use / prohibited-applications policy
    Pass condition
    Policy has version, owner, and review date ≤ 12 months; includes both acceptable-use and prohibited-application sections
  • ORG-M2L3 · DefinedTier 2 · Productionhybrid

    Each production AI system shall have named owners for critical APRF domains

    Artifact
    System inventory with owner fields for critical domains
    Pass condition
    0 production systems missing required domain owners in inventory query
  • ORG-M3L4 · Quantitatively ManagedTier 3 · Mission Criticalhybrid

    Risk acceptance for known control gaps shall be recorded with owner and expiry

    Artifact
    Risk-acceptance register samples
    Pass condition
    100% of open control-gap waivers have owner + expiry date; 0 expired waivers without escalation record
  • ORG-M4L5 · OptimizingTier 3 · Mission Criticalmanual

    Internal audit or independent assessment shall sample APRF evidence on a defined cadence

    Artifact
    Independent assessment or internal-audit sampling report against APRF evidence
    Pass condition
    PASS if the last sampling report is ≤12 months old and lists sampled check IDs and findings

Evidence required

  • AI policy document
  • Ownership/RACI for production AI systems
  • Risk-acceptance register samples

Severity & risk

Severity
high
Impact if violated
Risk level
medium
Typical residual risk (impact × likelihood)

Engineering best practices

  • Map APRF domains to teams; avoid orphan pillars
  • Time-box exceptions; auto-escalate expired waivers
  • Tie promotions and funding to measurable maturity for high-criticality systems

Automatic validations

  • Inventory systems missing owners
  • Alerts on expired risk acceptances

Manual validations

  • Annual policy review
  • Leadership tabletop on AI risk acceptance

Examples

  • A risk register entry accepts a missing multi-provider fallback until Q3 with CTO sign-off
  • Each agent product lists owners for Security, Safety, Evaluation, and Reliability

References

Crosswalks

  • GOVERN Govern

    NIST AI Risk Management Framework · supports

  • Accountable Accountable and Transparent

    NIST AI Risk Management Framework · supports

  • §4 Context of the organization

    ISO/IEC 42001 · aligns-with

  • §5 Leadership

    ISO/IEC 42001 · supports

  • §6 Planning

    ISO/IEC 42001 · partial

  • §10 Improvement

    ISO/IEC 42001 · aligns-with

  • CC1 Control Environment

    SOC 2 Trust Services Criteria · evidence-for

  • CC3 Risk Assessment

    SOC 2 Trust Services Criteria · evidence-for

  • Operational Excellence Operational Excellence

    AWS Well-Architected Framework · aligns-with

Future evolution

Machine-readable organizational control catalogs mapped to APRF domains and ISO 42001 clauses.