VIII · Govern itoverview
Part VIII · Govern it
Frameworks are not interchangeable, and treating them as one pile is why AI governance work stalls. Part VIII separates them by altitude - risk process, control set, management system, law - shows which question each one answers, and then cross-maps the regimes you are most likely to be asked about.
The last chapter is the practical one. VIII.6 · The advisor’s playbook is how to run this as an engagement rather than a reading list, and One system, end to end walks a single system from idea to production through everything in the book.
The frameworks
VIII.1 Frameworks & standards - four altitudes Threat taxonomies, control frameworks, governance systems, and certifiable standards - and how to cross-walk one control across all of them. govern · 11 min read VIII.2 Google SAIF - the controls layer Google's Secure AI Framework in depth: the six core elements, four components, fifteen risks, six control categories, the Risk Map, the Risk Assessment tool, SAIF 2.0 for agents, and CoSAI - and how to actually apply it. govern · 14 min read VIII.3 NIST AI RMF - the risk process The NIST AI Risk Management Framework in depth: the four functions (Govern, Map, Measure, Manage), the seven trustworthiness characteristics, and the Generative AI Profile - and how to run it as a process. govern · 10 min read VIII.4 ISO/IEC 42001, verification & maturity AISVS, AIVSS, and AIMA - the standards, scoring, and maturity models that turn a red-team into a verified, benchmarked posture. govern · 12 min readThe obligations
VIII.5 Jurisdictions - Singapore, the EU, the US & UK Singapore's secure-by-design, risk-based regime and the EU AI Act - the local instruments an accredited tester assesses against, mapped outward. govern · 9 min readThe engagement
VIII.6 The advisor's playbook Turning the playbook into a method - assess, explain, recommend - plus running an AI risk assessment and standing up a governance program. govern · 10 min read