Share E-Book

AI Governance in Practice Build responsible, audit-ready programs with ISOIEC 42001, NIST AI RMF, and lifecycle controls (Hemang Doshi)(Z-Library)

Author

Rating No ratings yet

Log in to rate

AI
Language English

Build an audit-ready AI governance program with practical assessments, lifecycle controls, and guidance aligned with ISO/IEC 42001, NIST AI RMF, OECD AI Principles, and the EU AI Act Turn AI governance principles, standards, and regulatory requirements into a practical program that operates across the AI lifecycle. - This book shows you how to build responsible AI governance around ISO/IEC 42001, the NIST AI RMF, OECD AI Principles, the EU AI Act, and other frameworks. You’ll conduct AI risk and impact assessments, define governance roles and decision rights, establish policies and lifecycle controls, and create documentation for transparency, accountability, and AI compliance. - You’ll apply governance through development, deployment, monitoring, and retirement; address AI security and safety; prepare for AI incidents; and use AI audits and monitoring findings to strengthen controls. Practical scenarios, templates, checklists, and step-by-step guidance turn frameworks into repeatable organizational practices. - Written by Hemang Doshi, who has more than 20 years of experience in system audit, IT risk and compliance, internal audit, risk management, information security audit, third-party risk management, and operational risk management, this book connects governance frameworks with practical implementation. By the end, you’ll be able to build an accountable, audit-ready AI governance program and integrate AI risk management with existing compliance, security, privacy, and risk processes. - What you will learn • Explain responsible AI principles and governance lifecycle risks • Compare ISO/IEC 42001, NIST AI RMF, OECD, and the EU AI Act • Conduct structured AI impact and risk assessments • Define accountable governance roles and decision rights • Create policies and lifecycle controls for responsible AI • Document AI systems for transparency and auditability • Prepare for AI incidents with structured response processes • Perform AI audits and improve governance fr

Format PDF
Size 19.9 MB
10
Views
(First 20 pages)

Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Page 1
(This page has no text content)
Page 2
AI Governance in Practice Build responsible, audit-ready programs with ISO/IEC 42001, NIST AI RMF, and lifecycle controls Hemang Doshi
Page 3
AI Governance in Practice Copyright © 2026 Packt Publishing All rights reserved. No part of this book may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written permission of the publisher, except in the case of brief quotations embedded in critical articles or reviews. Every effort has been made in the preparation of this book to ensure the accuracy of the information presented. However, the information contained in this book is sold without warranty, either express or implied. Neither the author, nor Packt Publishing or its dealers and distributors, will be held liable for any damages caused or alleged to have been caused directly or indirectly by this book. Packt Publishing has endeavored to provide trademark information about all of the companies and products mentioned in this book by the appropriate use of capitals. However, Packt Publishing cannot guarantee the accuracy of this information. Portfolio Director: Vijin Boricha Portfolio Manager: Anindya Sil Program Manager: Ankita Thakur Content Engineer: Tazeen Shaikh Technical Editor: Nithik Cheruvakodan Copy Editor: Tazeen Shaikh Indexer: Rekha Nair Proofreader: Tazeen Shaikh Production Designer: Aparna Bhagat Growth Lead: Ankita Thakur First published: September 2026 Production reference: 1250926 Published by Packt Publishing Ltd. Grosvenor House 11 St Paul's Square Birmingham B3 1RB, UK. ISBN 978-1-80730-081-4 www.packtpub.com
Page 4
To my mother, Jyoti Doshi, and to the memory of my father, Hasmukh Doshi, for their sacrifices and for exemplifying the power of determination. To my wife, Namrata Doshi, for being my loving partner throughout our life journey together, and to my kids, Jia and Neev, for giving me the time and space to write this book. To my sister, Pooja Shah, my brother-in-law, Hiren Shah, and my nephew, Phenil Shah, for their love, support, and inspiration. To my in-laws, Chandrakant Shah, Bharti Shah, and Ravish Shah, for their love and motivation. To my mentor and guide, Dipak Mazumder, for showing me how talent and creativity evolve. – Hemang Doshi
Page 5
Contributors About the author Hemang Doshi has more than 20 years of experience in system auditing, IT risk and compliance, internal audit, risk management, information security auditing, third-party risk management, AI GRC, and operational risk management. He has authored several books on certifications such as CISA, CRISC, CISM, Certified in Cybersecurity, DISA, and CEH, as well as enterprise risk management. His books and lectures are available in more than 175 countries and in more than 35 languages.
Page 6
About the reviewers Mani Keerthi Nagothu is a cybersecurity professional with global work experience. She is a well-known public speaker at various cybersecurity conferences, webinars, and podcasts. Her focus areas include cybersecurity strategy, incident response, and risk management. She is passionate about teaching cybersecurity, and four of her courses, Insider Threat Risk Management, Cyber Supply Chain Risk Management, Designing Tabletop Exercises, and Designing Cybersecurity Controls, are published on LinkedIn Learning. Javen Khoo Ai Wee, CMIIA, CIA, CISA, AAIA, CFE, ISC² CC is an internal audit and governance, risk, and compliance (GRC) professional with more than two decades of cross-functional experience across oil and gas, real estate, financial services and corporate advisory. With more than 10 years in internal audit, risk, and assurance-related roles, Javen currently serves as an independent GRC and internal audit advisor, supporting organizations in strengthening governance effectiveness, enhancing risk culture, and improving control discipline. Javen previously held leadership roles in PETRONAS Group Internal Audit and KLCC Group, where she directed high-impact audit engagements across PETRONAS' downstream and gas value chains, corporate functions and KLCC Group's diversified businesses. Beyond leading assurance portfolios, Javen is an active contributor to the internal audit and governance profession. She is a former member of the Research and Technical Advisory Committee of The Institute of Internal Auditors Malaysia (IIA Malaysia) and is currently a technical writer for IIA Malaysia, where she has published thought-leadership articles on cybersecurity, data integrity, fraud, and the evolving value of internal auditing. She also engages with academic institutions, including University of Malaya and Tunku Abdul Rahman University of Management and Technology, as a resource person for PhD research studies on AI in internal auditing and ESG assurance, thereby bridging academic rigor with practitioner experience.
Page 7
(This page has no text content)
Page 8
Table of Contents Preface xvii Chapter 1: Understanding Artificial Intelligence 1 Understanding AI ...................................................................................................................... 2 Differentiating normal system vis-à-vis AI-based system • 2 AI system • 4 Elements of AI ........................................................................................................................... 5 Data • 6 Algorithm • 6 Model • 6 Types of algorithms .................................................................................................................. 7 Supervised learning algorithms • 7 Unsupervised learning algorithms • 7 Semi-supervised learning algorithms • 8 Reinforcement learning algorithms • 9 Machine learning ...................................................................................................................... 9 Neural network • 10 Deep learning • 10 Types of AI models ................................................................................................................... 11 Decision tree model • 11 Recognition AI model • 12 Personalization model • 12 Natural language processing (NLP) model • 12 Robotic model • 12 Multimodal AI model • 12 Large language models (LLMs) • 12 AI deployment options ............................................................................................................. 13 Cloud deployment • 13 On-premises deployment • 14 Edge deployment • 14
Page 9
Summary ................................................................................................................................ 14 Chapter 2: Introduction to AI Governance 15 Understanding governance ...................................................................................................... 15 Elements of governance • 16 Governance versus management versus operations ................................................................. 17 Governance and regulations .................................................................................................... 18 Policies, procedures, and guidelines ........................................................................................ 18 Differentiating AI governance and IT governance ................................................................... 19 Why AI needs stronger governance than traditional systems .................................................. 20 Governing AI-based systems .................................................................................................... 21 AI governance – roles and responsibilities ................................................................................ 21 AI governance – policies .......................................................................................................... 22 AI governance – KPIs ............................................................................................................... 23 Summary ................................................................................................................................ 25 Chapter 3: Principles of Responsible AI 27 Who defines Responsible AI principles .................................................................................... 28 Responsible AI principles ........................................................................................................ 29 Accountability • 29 Accountability under EU AI Act • 30 Accountability – practical implementation • 32 Fairness and non-discrimination • 33 Fairness – practical implementation • 34 Transparency • 34 Transparency – practical implementation • 35 Explainability • 35 Explainability – practical implementation • 36 Privacy and data protection • 36 Security and resilience • 37 Security and resilience – practical implementation • 38 Safety and reliability • 39 Safety and reliability – practical implementation • 39 Human oversight • 40 Human oversight – practical implementation • 40 Table of Contents viii
Page 10
Risk-based approach • 41 Risk-based approach – practical implementation • 41 Ethical use • 41 Ethical use – practical implementation • 42 Continuous monitoring and improvement • 42 Continuous monitoring and improvement – practical implementation • 43 Compliance with laws and standards • 44 Compliance with laws and standards – practical implementation • 44 Summary ................................................................................................................................ 45 Chapter 4: Overview of Global AI Governance Frameworks – ISO/ IEC 42001 and EU AI Act 47 Understanding the difference between regulations, standards, and frameworks ................... 47 EU AI Act ................................................................................................................................. 49 General data protection regulation (GDPR) ............................................................................. 51 US executive order on safe, secure, and trustworthy AI ........................................................... 52 ISO/IEC 42001 – artificial intelligence management systems .................................................. 53 NIST AI risk management framework (AI RMF) ...................................................................... 54 OECD AI principles .................................................................................................................. 54 IEEE 7000 series ..................................................................................................................... 55 World economic forum AI governance playbooks ................................................................... 56 Common themes across the globe for AI governance .............................................................. 56 Summary ................................................................................................................................ 59 Chapter 5: AI Governance Framework – ISO/IEC 42001 61 ISO and IEC – international standards bodies ......................................................................... 61 What is a standard? • 62 How international standards are developed • 62 Structure of AIMS under ISO/IEC 42001 .................................................................................. 63 Ten clauses (clauses 1 to 10) • 63 Four annexes (annexes A, B, C, and D) • 64 Annex A • 65 Statement of Applicability (SoA) • 66 Implementation steps for ISO/IEC 42001 ................................................................................ 66 Sample case study – implementing ISO/IEC 42001 in a financial services company • 67 ix Table of Contents
Page 11
1. Create an AI governance policy • 67 2. Perform gap analysis • 67 3. Prepare the SoA • 68 4. Implement and maintain controls • 68 5. Certification audit • 68 Common pitfalls when implementing ISO/IEC 42001 ............................................................ 68 Certification audit process ...................................................................................................... 69 Importance of ISO/IEC 42001 certification ............................................................................. 72 Leveraging an existing ISO/IEC 27001 certificate to implement ISO/IEC 42001 ...................... 72 1. Review the scope • 73 2. Align the risk management processes • 73 3. Align the governance process • 73 4. Align the management review process • 74 5. Align the internal audit processes • 74 Summary ................................................................................................................................ 75 Chapter 6: AI Governance Framework – NIST AI RMF 77 What is NIST? .......................................................................................................................... 77 What is NIST AI RMF? ............................................................................................................. 78 Components of NIST AI RMF ................................................................................................... 78 Govern • 80 Developing policies and processes • 81 Establishing accountability and responsibility • 81 Ensuring diversity, equity, inclusion, and accessibility • 82 Establishing AI risk culture • 82 Engaging the stakeholders • 82 Managing third-party and supply chain risks • 83 Map • 83 Establishing and understanding context • 83 Categorizing the AI system • 84 Understanding AI capabilities, benefits, and costs • 84 Mapping risks and benefits across the AI system • 84 Assessing AI impacts • 84 Measure • 85 Applying AI risk metrics • 85 Table of Contents x
Page 12
Evaluating AI trustworthiness • 85 Tracking AI risks over time • 86 Assessing measurement effectiveness • 86 Manage • 87 Managing AI risks • 87 Maximizing benefits and minimizing impacts • 87 Managing third-party AI risks • 88 Monitoring, improving, and responding • 88 Implementing NIST AI RMF ................................................................................................... 88 Other implementation support ............................................................................................... 89 1. AI RMF profiles • 89 2. AI RMF playbook • 91 3. AI RMF crosswalks • 92 Summary ................................................................................................................................ 92 Chapter 7: AI Governance Framework – OECD AI Principles 93 What is OECD? ........................................................................................................................ 94 Background and evolution of the OECD AI Principles ............................................................. 94 Scope and applicability of the OECD AI Principles .................................................................. 95 The five OECD AI Principles .................................................................................................... 95 Practical application of OECD AI Principles in organizations .................................................. 97 Principle 1: Inclusive growth, sustainable development, and well-being • 97 Principle 2: Respect for the rule of law, human rights, and democratic values, including fairness and privacy • 98 Principle 3: Transparency and explainability • 98 Principle 4: Robustness, security, and safety • 99 Principle 5: Accountability • 99 Mapping OECD AI Principles to AI governance frameworks ................................................. 100 Summary .............................................................................................................................. 102 Chapter 8: European Union AI Act 103 Global impact of the EU AI Act .............................................................................................. 103 Applicability of the EU AI Act • 104 AI system ............................................................................................................................... 104 Classification of AI systems ................................................................................................... 104 xi Table of Contents
Page 13
Prohibited AI • 106 High risk AI systems • 106 Limited risk AI • 108 Minimal risk AI • 108 Determining the classification of an AI system ...................................................................... 109 Obligations by role .................................................................................................................. 111 Complaint and redress mechanism ........................................................................................ 112 Penalties, fines, and enforcement ........................................................................................... 112 Practical implementation roadmap ....................................................................................... 114 Summary ............................................................................................................................... 116 Chapter 9: AI Impact Assessment 117 AI impact assessment requirements under different frameworks, standards and regulations ..... 117 Benefits of AI impact assessment ........................................................................................... 118 Key areas of AI impact ............................................................................................................ 118 Steps to conduct effective AI impact assessment .................................................................... 121 Summary ............................................................................................................................... 123 Chapter 10: AI Risk Assessment 125 Types of AI risks .................................................................................................................... 126 AI risk assessment requirements under different frameworks, standards, and regulations ... 127 AI risk assessment steps ........................................................................................................ 128 Risk identification • 129 Risk analysis • 131 Likelihood and impact • 131 Risk evaluation • 133 Risk mitigation/treatment • 133 Risk management policy ........................................................................................................ 134 Risk register ........................................................................................................................... 135 Summary ............................................................................................................................... 135 Chapter 11: Comparative Analysis of AI Frameworks – ISO/IEC 42001 and EU AI Act 137 Overview of major AI governance frameworks ....................................................................... 137 Table of Contents xii
Page 14
Selecting the right framework for your organization ............................................................ 138 When to use the OECD AI Principles • 138 When to use the NIST AI RMF • 139 When to use ISO/IEC 42001 • 139 EU AI act • 140 The ISO advantage ................................................................................................................ 140 OECD principles mapped to ISO/IEC 42001 standard • 141 NIST AI RMF mapped to ISO/IEC 42001 standard • 143 Summary .............................................................................................................................. 144 Chapter 12: AI Governance Structure 147 Objectives of an AI governance structure ............................................................................... 147 Governance model ................................................................................................................ 148 RACI matrix for AI governance .............................................................................................. 150 Implementing AI governance structures ................................................................................ 152 Common pitfalls in implementing AI governance .................................................................. 154 Summary ............................................................................................................................... 155 Chapter 13: AI Governance Documents 157 Importance of documented AI policies and procedures ......................................................... 158 Document hierarchy .............................................................................................................. 159 Important AI governance documents ..................................................................................... 161 AI governance policy • 161 AI use case assessment and approval form • 162 AI system inventory • 162 AI impact assessment • 162 AI risk assessment • 163 AI risk register • 163 AI vendor and third-party assessment • 163 AI model and system documentation • 164 AI monitoring and review records • 164 AI incident management procedure and records • 164 AI change management records • 165 AI governance committee records • 165 Training and awareness records • 165 xiii Table of Contents
Page 15
AI governance review and audit records • 165 Key contents of AI governance policy .................................................................................... 166 Documentation and record keeping requirements under different regulations and frameworks. 170 EU AI Act • 170 ISO/IEC 42001 artificial intelligence management systems • 170 NIST AI Risk Management Framework (AI RMF) • 171 OECD AI Principles • 171 Stepwise procedure for creating AI documents ...................................................................... 171 Summary ............................................................................................................................... 173 Chapter 14: AI Lifecycle Governance 175 AI lifecycle stages – a governance perspective ........................................................................ 176 Ideation and use-case definition • 177 Data collection and preparation • 178 Model design and development • 178 Testing and validation • 179 Deployment and integration • 180 Monitoring and ongoing management • 180 Retirement and decommissioning • 181 Third-party and vendor AI lifecycle governance • 182 Summary .............................................................................................................................. 182 Chapter 15: Security of AI Systems 183 Understanding the unique security risks of AI systems ......................................................... 183 Protecting data, models, and infrastructure .......................................................................... 185 Protecting AI data • 185 Protecting AI models • 187 Protecting AI infrastructure • 188 Role of the AI GRC professional in the security of AI systems ................................................ 189 Summary .............................................................................................................................. 190 Chapter 16: AI Incident Management 191 Incident criteria ..................................................................................................................... 193 AI incident management framework ...................................................................................... 195 Table of Contents xiv
Page 16
Role of the AI GRC professional in AI incident management .................................................. 197 Incident register .................................................................................................................... 198 Common pitfalls in AI incident management ....................................................................... 200 AI incident management checklist ........................................................................................ 201 Summary .............................................................................................................................. 202 Chapter 17: AI System Audits 203 Responsibility of audit .......................................................................................................... 204 Role of AI GRC professional in AI system audits ..................................................................... 205 Key audit areas in AI systems ................................................................................................. 206 AI governance and oversight • 206 Data quality and integrity • 207 Bias and fairness • 207 Transparency and explainability • 207 Security risks in AI systems • 207 Privacy and regulatory compliance • 207 Model performance and reliability • 207 Human oversight and accountability • 207 AI incident management • 208 Types of AI audits ................................................................................................................. 208 Summary .............................................................................................................................. 209 Chapter 18: Unlock Access to the Code Bundle and the PDF Version 211 Unlock this book's free benefits in three easy steps ................................................................ 212 Other Books You May Enjoy 216 Index 219 xv Table of Contents
Page 17
(This page has no text content)
Page 18
Preface Turn AI governance principles, standards, and regulatory requirements into a practical program that operates across the AI lifecycle. This book shows you how to build responsible AI governance around ISO/IEC 42001, the NIST AI RMF, OECD AI Principles, the EU AI Act and other frameworks. You'll conduct AI risk and impact assessments, define governance roles and decision rights, establish policies and lifecycle controls, and create documentation for transparency, accountability, and AI compliance. You'll apply governance through development, deployment, monitoring, and retirement; address AI security and safety; prepare for AI incidents; and use AI audits and monitoring findings to strengthen controls. Practical scenarios, templates, checklists, and step-by-step guidance turn frameworks into repeatable organizational practices. Written by Hemang Doshi, who has more than 20 years of experience in system audit, IT risk and compliance, internal audit, risk management, information security audit, third-party risk management, and operational risk management, this book connects governance frameworks with practical implementation. By the end, you'll be able to build an accountable, audit-ready AI governance program and integrate AI risk management with existing compliance, security, privacy, and risk processes. Who this book is for AI governance, compliance, and risk management professionals responsible for overseeing AI systems, evaluating AI risks, or implementing responsible AI practices, along with data scientists, ML engineers, internal auditors, privacy leaders, and technology executives. A foundational understanding of AI concepts, basic IT risk principles, and organizational policies or governance frameworks is recommended. This book also provides a strong foundation for AI GRC certifications such as AIGP, AAIA, AAIR, AAISM, AIMS and others. What this book covers Chapter 1, Understanding Artificial Intelligence, introduces the fundamentals of AI, its key concepts, types, applications, and lifecycle. It provides a foundation for understanding AI systems, risks, and governance.
Page 19
Chapter 2, Introduction to AI Governance, introduces the fundamentals of AI governance, its objectives, key principles, and the importance of establishing effective governance practices. Chapter 3, Principles of Responsible AI, introduces the key principles of responsible AI, including fairness, transparency, accountability, privacy, safety, and human oversight. Chapter 4, Overview of Global AI Governance Frameworks – ISO/IEC 42001 and EU AI Act, provides an overview of ISO/IEC 42001, NIST AI RMF, OECD AI Principles, and the EU AI Act. Chapter 5, AI Governance Framework – ISO/IEC 42001, introduces ISO/IEC 42001 and explains its key requirements for establishing and maintaining an AI management system. Chapter 6, AI Governance Framework – NIST AI RMF, introduces the NIST AI Risk Management Framework and its approach to managing AI-related risks and promoting trustworthy AI. Chapter 7, AI Governance Framework – OECD AI Principles, introduces the OECD AI Principles and their role in promoting innovative, trustworthy, and human-centered AI. Chapter 8, European Union AI Act, introduces the EU AI Act, its risk-based approach, key requirements, and obligations for AI systems. Chapter 9, AI Impact Assessment, explains the purpose and process of assessing the potential impacts of AI systems on individuals, organizations, and society. Chapter 10, AI Risk Assessment, explains how to identify, assess, prioritize, and manage risks associated with AI systems. Chapter 11, Comparative Analysis of AI Frameworks – ISO/IEC 42001 and EU AI Act, compares ISO/ IEC 42001 and the EU AI Act, highlighting their key similarities and differences. Chapter 12, AI Governance Structure, explains the roles, responsibilities, accountability, and organizational structure required for effective AI governance. Chapter 13, AI Governance Documents, introduces the key policies, procedures, records, and other documentation required to support AI governance. Chapter 14, AI Lifecycle Governance, explains how governance practices can be integrated throughout the AI system lifecycle, from planning and development to deployment and retirement. Chapter 15, Security of AI Systems, introduces key security risks and controls for protecting AI systems, data, models, infrastructure, and supporting services. Chapter 16, AI Incident Management, explains how organizations can identify, respond to, manage, and learn from AI-related incidents. Chapter 17, AI System Audits, introduces the principles and practices for auditing AI systems, governance processes, risks, controls, and compliance. Preface xviii
Page 20
To get the most out of this book You should have a basic understanding of IT, cybersecurity, risk management, and governance. No advanced AI knowledge is required. The book includes practical examples and templates to help you understand and apply AI governance concepts. You should also refer to the latest versions of relevant standards and regulations, as they may change over time. Download the example code files This book includes a complete downloadable code bundle containing all the example projects and files used throughout the chapters. We recommend downloading the bundle so you can follow along smoothly and experiment with the examples. Use the bundle as a practical starting point. Modify it, extend it, and apply what you learn by creating your own variations as you progress through the chapters. Get the code bundle If you bought the book directly from Packt: Go to packtpub.com Click your profile picture and select Your Orders Find this book and click Download Code If you bought this book from Amazon or any other channel partner: Go to packtpub.com/unlock or scan the following QR code Search for this book Sign up or log in to your free Packt account Upload your proof of purchase and download the code bundle locally Usage note: You're free to use and modify this code for personal learning and non-commercial projects. 1. 2. 3. 1. 2. 3. 4. xix Preface
The above is a preview of the first 20 pages. Register to read the complete e-book.

Recommended for You

Loading recommended books...
Failed to load, please try again later

Tip the Site

Scan the WeChat Pay or Alipay code to tip. No login required.

WeChat Pay
Alipay
← Back to List