AI governance becomes real when someone has to decide whether a system should actually be used.
What is it for? Who could be affected? What can go wrong? What controls are needed? What evidence is good enough? And who has the authority to say yes or no?
Governing AI is a practical guide to answering those questions.
Written for senior managers, AI governance, risk, compliance, assurance, Responsible AI, technology and data professionals, it turns a complex landscape of regulation, standards, risk and ethical considerations into a workable organisational discipline.
At its heart is the AI Governance Control Cycle:
Discover → Classify → Assess → Control → Assure → Authorise → Monitor → Improve
Rather than treating AI governance as a collection of policies or abstract principles, the book shows how governance works across the AI lifecycle, from identifying and classifying AI use cases, through risk and impact assessment, control design and assurance, to formal authorisation, monitoring and continual improvement.
Drawing on ISO/IEC 42001, ISO/IEC 23894, ISO/IEC 42005, ISO 31000, ISO/IEC 38507, NIST AI RMF, the EU AI Act and other authoritative sources, the book explains not simply what these frameworks say, but how they fit together in real organisational decision-making.
You will learn how to:
- build an AI governance operating model that works in practice;
- determine how much governance different AI systems require;
- distinguish risk, impact, controls, assurance, authorisation, compliance and ethics;
- assess AI risk and potential impacts on people and organisations;
- design proportionate controls and meaningful human oversight;
- decide what evidence is needed before AI is approved, scaled or relied upon;
- establish clear accountability and decision rights;
- monitor AI after deployment and recognise when reassessment is required;
- navigate the practical implications of the EU AI Act and the growing AI standards landscape.
The book also includes practitioner appendices and working tools designed to help readers apply the approach to real AI systems and governance decisions.
Good AI governance is not primarily about slowing AI down. It creates the conditions in which useful AI can be adopted, scaled and trusted because purpose, risk, impact, controls, accountability and evidence are understood.
Governing AI is designed not simply to be read, but to be used, as a practical reference when someone in your organisation asks:
"Can we use this AI system, and what would we need to know before we say yes?"