● AI Governance Section

AI Governance

What it actually is, the vocabulary it runs on, and how organizations put it into practice — three ways into the same body of knowledge, for three different starting points.

Every page in this section is grounded in the IAPP AIGP Body of Knowledge (v2.1, effective February 2026) — nothing here is invented or paraphrased loosely from memory.

4Domains covered
281Glossary terms
4Major frameworks
1Law with real fines (EU AI Act)
Start with the definition

What is AI governance?

AI governance is the set of principles, roles, policies and controls an organization puts in place so that its AI systems are built and used responsibly — fair, transparent, safe, accountable to a real person, and compliant with the laws that already apply, plus the newer laws written specifically for AI. It sits at the intersection of law, risk management and engineering practice, which is why it's usually its own discipline rather than something bolted onto an existing legal or IT function.

"Effective AI governance is distributed but accountable. Typical roles include executive sponsorship, an AI governance committee, legal/privacy, security, data science/engineering, risk and compliance, procurement, HR, and business-unit owners — plus, increasingly, a dedicated AI governance lead. The goal is to avoid both extremes: a single overwhelmed owner, and diffuse responsibility where 'everyone' owns AI and therefore no one does." — IAPP AIGP Body of Knowledge, Domain I

The field is organized around four domains — think of them as the map this whole section follows, from "what is this and why does it need rules" through to "how do you actually keep a live system safe once it's deployed."

Domain I

Foundations of AI governance

What AI governance is, the shared vocabulary, why AI carries novel risk, and how an organization stands up a program with clear roles, policies and lifecycle controls.

16–20 exam items · 3 competencies
Domain II

Laws, standards & frameworks

Existing law that already binds AI — privacy, IP, non-discrimination — plus AI-specific law and frameworks: above all the EU AI Act, alongside OECD, NIST and ISO.

19–23 exam items · 4 competencies
Domain III

Governing AI development

The build half of the lifecycle — scoping a use case, assessing impact, governing the data, training and testing rigorously, then releasing and monitoring responsibly.

21–25 exam items · 3 competencies
Domain IV

Governing AI deployment & use

The deploy half — choosing and assessing a system (built or bought), contracting with vendors, then operating, monitoring and eventually retiring it.

21–25 exam items · 3 competencies
Three ways in

Explore this section

Pick the page that matches where you're starting from — they all draw on the same source material, just at different altitudes.

Referenced throughout this section

The four frameworks that keep coming up

Every page in this section refers back to the same four frameworks. They are not interchangeable — one is a voluntary pledge, one is a certification, one is a risk checklist, and one is an actual law with fines attached.

OECD AI Principles
A shared values pledge governments agreed on. No penalties for breaking it.
NIST AI RMF
A voluntary US risk-management framework. Recommended, not mandatory.
ISO/IEC 42001
An earnable certification proving an organization runs AI responsibly. Optional.
EU AI Act
An actual law with real fines, sorting AI uses into risk tiers. The one with teeth.
How to use this section

Who each page is built for

New to the topic?Start with AI Governance for Non-Technical People — it assumes nothing and builds up from "what is AI" to "is there actually a law about this."
Need a definition fast?Go straight to the Vocabulary page and search — every term links back to plain-language phrasing, not just a one-line dictionary entry.
Running a program?The Management Training Guide is built for a live session — an agenda, exercises and facilitator notes, not just reading material.
kashifz.com