Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Hemang Doshi

Rating No ratings yet

Build an audit-ready AI governance program with practical assessments, lifecycle controls, and guidance aligned with ISO/IEC 42001, NIST AI RMF, OECD AI Principles, and the EU AI Act Turn AI governance principles, standards, and regulatory requirements into a practical program that operates across the AI lifecycle. - This book shows you how to build responsible AI governance around ISO/IEC 42001, the NIST AI RMF, OECD AI Principles, the EU AI Act, and other frameworks. You’ll conduct AI risk and impact assessments, define governance roles and decision rights, establish policies and lifecycle controls, and create documentation for transparency, accountability, and AI compliance. - You’ll apply governance through development, deployment, monitoring, and retirement; address AI security and safety; prepare for AI incidents; and use AI audits and monitoring findings to strengthen controls. Practical scenarios, templates, checklists, and step-by-step guidance turn frameworks into repeatable organizational practices. - Written by Hemang Doshi, who has more than 20 years of experience in system audit, IT risk and compliance, internal audit, risk management, information security audit, third-party risk management, and operational risk management, this book connects governance frameworks with practical implementation. By the end, you’ll be able to build an accountable, audit-ready AI governance program and integrate AI risk management with existing compliance, security, privacy, and risk processes. - What you will learn • Explain responsible AI principles and governance lifecycle risks • Compare ISO/IEC 42001, NIST AI RMF, OECD, and the EU AI Act • Conduct structured AI impact and risk assessments • Define accountable governance roles and decision rights • Create policies and lifecycle controls for responsible AI • Document AI systems for transparency and auditability • Prepare for AI incidents with structured response processes • Perform AI audits and improve governance fr

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A practical field guide for turning AI governance principles and regulatory frameworks into an audit-ready program that runs across the entire AI lifecycle. Best for GRC professionals, auditors, risk and compliance officers, and technology leaders who must show, not just claim, responsible AI. 【Book Arc】 - **Opening (~0%–15%)**: Sets the stakes with a cautionary scenario about an opaque, unchallengeable AI credit score, then argues why AI's ability to learn and adapt creates risks that traditional IT governance never had to handle. - **Early (~15%–35%)**: Builds the technical foundation — data, algorithms, models, machine learning, deep learning, and deployment options (on-premises, edge) — so readers understand where risk actually originates before governing it. - **Early–Middle (~30%–45%)**: Distinguishes governance from regulation, then lays out roles and responsibilities (business owners, data science, risk, legal, security/privacy, internal audit) and the policies that translate intent into control. - **Middle (~40%–60%)**: Walks through responsible AI principles one by one — accountability, fairness, transparency, explainability, privacy, security, safety, human oversight — each paired with concrete implementation practices. - **Middle–Late (~55%–80%)**: Compares the major frameworks (ISO/IEC 42001, NIST AI RMF, OECD AI Principles, EU AI Act), maps them to each other, and helps you choose the right one for your organization. - **Late–Ending (~75%–100%)**: Moves into operating mechanics — governance structures and RACI matrices, the document hierarchy (policy, inventory, impact/risk assessments, registers, incident and change records), AI audits, incident response, and continuous improvement. 【Key Takeaways】 - **Governance is not regulation** (Early): Regulations are external obligations; governance is the internal machinery — policies, roles, controls, monitoring — that turns those obligations into something auditable. - **AI risk differs from traditional IT risk** (Early): Because models learn, drift, and change behavior over time, governance must be continuous rather than a one-time approval gate. - **Responsible AI principles need implementation detail to matter** (Middle): Each principle (fairness, explainability, human oversight, etc.) is paired with practical steps, so "we value fairness" becomes testable controls. - **Transparency and explainability are distinct** (Middle): You can disclose that AI is used and still fail to explain a specific decision — both are needed for trust and appeals. - **Frameworks are complementary, not competing** (Middle–Late): The book maps OECD and NIST AI RMF onto ISO/IEC 42001 and positions the EU AI Act as a regulatory overlay, helping you select rather than stack blindly. - **Accountability requires named roles and decision rights** (Early–Middle): A RACI matrix and a governance committee convert vague ownership into enforceable responsibility. - **Audit-readiness lives in documentation** (Late): A defined document hierarchy — inventory, impact and risk assessments, risk register, vendor assessments, monitoring and incident records — is what auditors actually examine. - **Incidents and audits feed improvement** (Ending): Structured incident response and audit findings are treated as inputs to strengthen controls, not as one-off events. 【Reading Tips】 - Skim the AI fundamentals chapters if you already work in data science; deep-read them if you come from audit, risk, or compliance and need the vocabulary. - Treat the principles chapter as a checklist: for each principle, note the "practical implementation" bullets and ask whether your organization can evidence them. - Use the framework comparison and mapping sections as a decision aid — pick your primary framework first, then layer the others rather than adopting all at once. - Keep the document hierarchy chapter open as a template while drafting your own governance artifacts. - The excerpts do not cover the later audit and incident chapters in depth, so plan to read those sections directly rather than relying on summaries. 【Coverage Limits】 This guide is synthesized from stratified excerpts covering roughly the first half of the book (fundamentals, governance, principles, and framework comparison); the later chapters on audits, incidents, and lifecycle controls are described from the table of contents and blurb rather than detailed excerpt content.
Excerpt 1
s • Define accountable governance roles and decision rights • Create policies and lifecycle controls for responsible AI • Document AI systems for transparenc...
View in text
Excerpt 2
so silently control lives. This book is designed to help AI GRC professionals, business leaders, governance professionals, auditors, risk managers, complianc...
View in text
Excerpt 3
overnance also helps organizations manage regulatory change. As AI regulations evolve, governance structures such as committees, compliance functions, and re...
View in text
Excerpt 4
ty and reliability principle is critical in Responsible AI. Safety means ensuring that AI systems do not cause unintended harm to people, organizations, or s...
View in text
Excerpt 5
with issuing guidance, developing technical standards, and integrating AI risk management into existing regulatory frameworks. This approach reflects the US...
View in text
Excerpt 6
AI inventory, responsible AI, AI incidents, and compliance. Where necessary, AI system owners, data scientists, legal specialists, or other AI subject-matter...
View in text
Excerpt 7
the Current and Target Profiles to identify gaps in AI risk management, determine areas requiring improvement, prioritize actions based on risk and Chapter 7...
View in text
Excerpt 8
rticle 14): Appropriate human oversight measures must be in place to monitor the AI system, intervene when necessary, and prevent or minimize risks to indivi...
View in text
Tags
AI categories
Artificial IntelligenceCybersecurityTechnology
ISBN: 1807300811
Publisher: Packt Publishing
Publish Year: 2026
Language: English
Pages: 250
File Format: PDF
File Size: 19.9 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…