Build an audit-ready AI governance program with practical assessments, lifecycle controls, and guidance aligned with ISO/IEC 42001, NIST AI RMF, OECD AI Principles, and the EU AI Act
Turn AI governance principles, standards, and regulatory requirements into a practical program that operates across the AI lifecycle.
-
This book shows you how to build responsible AI governance around ISO/IEC 42001, the NIST AI RMF, OECD AI Principles, the EU AI Act, and other frameworks. You’ll conduct AI risk and impact assessments, define governance roles and decision rights, establish policies and lifecycle controls, and create documentation for transparency, accountability, and AI compliance.
-
You’ll apply governance through development, deployment, monitoring, and retirement; address AI security and safety; prepare for AI incidents; and use AI audits and monitoring findings to strengthen controls. Practical scenarios, templates, checklists, and step-by-step guidance turn frameworks into repeatable organizational practices.
-
Written by Hemang Doshi, who has more than 20 years of experience in system audit, IT risk and compliance, internal audit, risk management, information security audit, third-party risk management, and operational risk management, this book connects governance frameworks with practical implementation. By the end, you’ll be able to build an accountable, audit-ready AI governance program and integrate AI risk management with existing compliance, security, privacy, and risk processes.
-
What you will learn
• Explain responsible AI principles and governance lifecycle risks
• Compare ISO/IEC 42001, NIST AI RMF, OECD, and the EU AI Act
• Conduct structured AI impact and risk assessments
• Define accountable governance roles and decision rights
• Create policies and lifecycle controls for responsible AI
• Document AI systems for transparency and auditability
• Prepare for AI incidents with structured response processes
• Perform AI audits and improve governance fr
AI Reading Assistant
Whole-book reading guide from stratified index samples; jump to passages in the text
Tip the Site
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat Pay
Alipay
Open WeChat or Alipay and scan. No login required.
AI guide
【One-Line Pitch】
A practical field guide for turning AI governance principles and regulatory frameworks into an audit-ready program that runs across the entire AI lifecycle. Best for GRC professionals, auditors, risk and compliance officers, and technology leaders who must show, not just claim, responsible AI.
【Book Arc】
- **Opening (~0%–15%)**: Sets the stakes with a cautionary scenario about an opaque, unchallengeable AI credit score, then argues why AI's ability to learn and adapt creates risks that traditional IT governance never had to handle.
- **Early (~15%–35%)**: Builds the technical foundation — data, algorithms, models, machine learning, deep learning, and deployment options (on-premises, edge) — so readers understand where risk actually originates before governing it.
- **Early–Middle (~30%–45%)**: Distinguishes governance from regulation, then lays out roles and responsibilities (business owners, data science, risk, legal, security/privacy, internal audit) and the policies that translate intent into control.
- **Middle (~40%–60%)**: Walks through responsible AI principles one by one — accountability, fairness, transparency, explainability, privacy, security, safety, human oversight — each paired with concrete implementation practices.
- **Middle–Late (~55%–80%)**: Compares the major frameworks (ISO/IEC 42001, NIST AI RMF, OECD AI Principles, EU AI Act), maps them to each other, and helps you choose the right one for your organization.
- **Late–Ending (~75%–100%)**: Moves into operating mechanics — governance structures and RACI matrices, the document hierarchy (policy, inventory, impact/risk assessments, registers, incident and change records), AI audits, incident response, and continuous improvement.
【Key Takeaways】
- **Governance is not regulation** (Early): Regulations are external obligations; governance is the internal machinery — policies, roles, controls, monitoring — that turns those obligations into something auditable.
- **AI risk differs from traditional IT risk** (Early): Because models learn, drift, and change behavior over time, governance must be continuous rather than a one-time approval gate.
- **Responsible AI principles need implementation detail to matter** (Middle): Each principle (fairness, explainability, human oversight, etc.) is paired with practical steps, so "we value fairness" becomes testable controls.
- **Transparency and explainability are distinct** (Middle): You can disclose that AI is used and still fail to explain a specific decision — both are needed for trust and appeals.
- **Frameworks are complementary, not competing** (Middle–Late): The book maps OECD and NIST AI RMF onto ISO/IEC 42001 and positions the EU AI Act as a regulatory overlay, helping you select rather than stack blindly.
- **Accountability requires named roles and decision rights** (Early–Middle): A RACI matrix and a governance committee convert vague ownership into enforceable responsibility.
- **Audit-readiness lives in documentation** (Late): A defined document hierarchy — inventory, impact and risk assessments, risk register, vendor assessments, monitoring and incident records — is what auditors actually examine.
- **Incidents and audits feed improvement** (Ending): Structured incident response and audit findings are treated as inputs to strengthen controls, not as one-off events.
【Reading Tips】
- Skim the AI fundamentals chapters if you already work in data science; deep-read them if you come from audit, risk, or compliance and need the vocabulary.
- Treat the principles chapter as a checklist: for each principle, note the "practical implementation" bullets and ask whether your organization can evidence them.
- Use the framework comparison and mapping sections as a decision aid — pick your primary framework first, then layer the others rather than adopting all at once.
- Keep the document hierarchy chapter open as a template while drafting your own governance artifacts.
- The excerpts do not cover the later audit and incident chapters in depth, so plan to read those sections directly rather than relying on summaries.
【Coverage Limits】
This guide is synthesized from stratified excerpts covering roughly the first half of the book (fundamentals, governance, principles, and framework comparison); the later chapters on audits, incidents, and lifecycle controls are described from the table of contents and blurb rather than detailed excerpt content.
Excerpt 1
s • Define accountable governance roles and decision rights • Create policies and lifecycle controls for responsible AI • Document AI systems for transparenc...
so silently control lives. This book is designed to help AI GRC professionals, business leaders, governance professionals, auditors, risk managers, complianc...
overnance also helps organizations manage regulatory change. As AI regulations evolve, governance structures such as committees, compliance functions, and re...
ty and reliability principle is critical in Responsible AI. Safety means ensuring that AI systems do not cause unintended harm to people, organizations, or s...
with issuing guidance, developing technical standards, and integrating AI risk management into existing regulatory frameworks. This approach reflects the US...
AI inventory, responsible AI, AI incidents, and compliance. Where necessary, AI system owners, data scientists, legal specialists, or other AI subject-matter...
the Current and Target Profiles to identify gaps in AI risk management, determine areas requiring improvement, prioritize actions based on risk and Chapter 7...
rticle 14): Appropriate human oversight measures must be in place to monitor the AI system, intervene when necessary, and prevent or minimize risks to indivi...
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.
Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat PayAlipay
Open WeChat or Alipay and scan. No login required.
Add Tag
Enter tag name (max 50 characters)
Share E-Book
AI Governance in Practice Build responsible, audit-ready programs with ISOIEC 42001, NIST AI RMF, and lifecycle controls (Hemang Doshi)(Z-Library)
Scan QR code with your phone to access
Copy the link or scan the QR code to access this e-book on your phone
Share E-Book via Email
Please enter email address
Donation Statistics
¥.00
Total Donations
0
Donation Count
AI Governance in Practice Build responsible, audit-ready programs with ISOIEC 42001, NIST AI RMF, and lifecycle controls (Hemang Doshi)(Z-Library)
Find Your Favorite Books
Only registered users can comment after logging in. Comments need to be reviewed by administrators before being displayed
Loading comments...
Reply to Comment
Edit Comment