Most organisations discover their AI footprint accidentally — a customer asks, a regulator asks, or an incident asks. The answer is rarely one system. It is a customer support assistant someone shipped last quarter, a scoring model in the finance team, three teams using the same API with different prompts, and a vendor feature that turned on by default.
The register comes first
Before any framework helps, you need a list. For each system: what it does, what data it uses, who owns it, whether it makes or informs a decision about a person, which model and vendor sit behind it, and what happens if it is wrong. That last column is what turns an inventory into a risk-tiering exercise.
NIST AI RMF as the operating model
The framework organises the work into four functions — Govern, Map, Measure and Manage — and its value is that it is voluntary, technology-neutral and outcome-oriented. Govern establishes accountability. Map builds the context you need to judge risk. Measure defines how you evaluate systems for robustness, bias, privacy and security. Manage allocates resources to the risks that matter. It maps cleanly onto the ISMS habits a security team already has.
The EU AI Act adds obligations, not just advice
- Prohibited practices — a short list that is genuinely off the table.
- High-risk systems — the heavy tier: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness requirements.
- Transparency obligations — telling people they are interacting with a system, and labelling synthetic content.
- General-purpose model duties — falling largely on providers, but flowing to deployers through contracts.
Classification is the decision that determines cost. Most enterprise systems are not high-risk, but the ones that touch employment, credit, education, essential services or biometrics often are — and those are exactly the systems business teams build without telling anyone.
What good looks like after six months
A maintained inventory. A risk tier for every system, with the reasoning recorded. Model cards or system documentation for anything customer-facing. An acceptable-use policy people have actually read. A review gate before a new AI feature ships, owned by a named person. That is a governance program — the policy pack is the artefact, not the outcome.
If your AI inventory and your vendor register have never been compared, start there. The overlap is usually where the surprises live.
Go deeper
AI Security & Governance: NIST AI RMF and EU AI Act
Someone in your organisation has to answer for the AI systems now in production — what they do, what they were trained on, and who signed off. This course builds that governance program on NIST AI RMF and EU AI Act foundations.

Leave a Reply