Governance.
AI policy, accountable owner, inventory, framework alignment.
Why governance matters
Governance is the foundation of every AI security program. The Govern function in NIST AI RMF and clauses 4 through 6 of ISO 42001 both prioritize the same things: a written AI policy, a named accountable executive, an inventory of AI systems, and documented framework alignment. Without governance, every other dimension drifts. Engineering teams adopt AI tools faster than security can review them, vendors get onboarded without contracts, and shadow AI grows without discovery. The check opens on governance: where AI stands with leadership decides which questions follow, and every governance question cites its NIST AI RMF or ISO 42001 source.
What the check asks about governance
The check asks up to five questions in total, chosen by your earlier answers, so a path may meet one of these or none. Each carries a weight from 0 to 3 and cites its source.
| Question | Citation | Answers |
|---|---|---|
| Which of these best describes AI in your organization today?Where AI stands with leadership decides which questions matter next. | NIST AI RMF GOVERN-1.1, MAP-1.1 |
|
| Is anyone evaluating or piloting AI tools right now, even informally?Pilots without a policy are how unsanctioned use begins. | NIST AI RMF GOVERN-1.5 |
|
| Is there a named executive accountable for AI risk, even without a policy yet?Naming an owner matters even before a policy exists. | ISO 42001 clause 5.3 |
|
| Do you know which AI coding agents and assistants are running on staff machines, and what they can reach?Agents on developer machines can read files, sign in to applications and run commands. Knowing what is installed and what it can reach is the first control. | OWASP LLM06 Excessive Agency, NIST AI RMF MAP-1.1 |
|
| Do you know which AI coding agents and assistants run on staff machines, what they can reach, and how MCP servers and Skills are vetted before install?Agents on developer machines read files, sign in to applications and run commands, and their plug-ins ship as packages. Inventory and vetting are the controls that stop a quiet blast radius. | OWASP LLM06 Excessive Agency, NIST AI RMF MAP-1.1 |
|
Frameworks cited on this dimension
Every question above cites its source. These are the frameworks behind governance.
NIST AI RMF in Operation
The NIST AI Risk Management Framework (AI RMF 1.0, published January 2023) defines four core functions for AI risk: Govern, Map, Measure, Ma.
Read the guideISO 42001 in Practice
ISO/IEC 42001:2023 specifies requirements for establishing, implementing, maintaining, and continually improving an AI management system. It.
Read the guideExcessive Agency (LLM06)
An LLM-based agent has more permissions, more tool access, or more autonomy than its task requires. Compromise via prompt injection then use.
Read the guideSee where governance lands on your chart.
Five questions, about three minutes, and your dot lands on the Posture Quadrant. Your stage and the move that takes you forward arrive by email or in a live conversation with a CWS engineer.