AI Governance Framework
Outcomes against which the governing body holds management to account for the use of AI.
The AI governance framework is the set of outcomes against which the governing body holds management to account for the organisation's use of AI. It does not redefine governance. It states how the four outcomes are tested in operation.
The framework does not replace law, standards or internal policy. Those instruments are mapped onto the Control Objectives for AI Systems (AICOB) process model and, where used, applied through the AI governance platform. The governing body's work is to evaluate, direct and monitor. Management's work is to align, plan, build, run and assure. Every material AI outcome should have both a governing-body role and a management owner.
How the four outcomes are tested
Ethical culture. Tested by whether responsible-AI policy is approved, known and used; whether incentives and escalation routes support that policy; and whether exceptions, incidents and misuse are handled in line with stated values rather than only after the fact.
Sustainable performance and value creation. Tested by whether AI use is tied to organisational purpose and strategic objectives; whether the portfolio of AI uses is known and prioritised; and whether expected value is recorded and compared with realised value, including the cost of risk, change and recovery.
Adequate and effective control of AI resources and risks. Tested by whether the governing body can see the estate of AI uses; whether risk is assessed against law, frameworks and internal policy and treated inside the organisation's overall business-risk profile; whether third-party and embedded AI sit in the same control system as internal systems; and whether controls operate at runtime, not only as documents.
Trust, reputation and legitimacy. Tested by whether decisions, assessments, tests, approvals and remediations leave named work products; whether accountability remains visible across organisational and legal-entity boundaries; and whether one set of processes can be shown to satisfy multiple obligations - for example an EU AI Act article, ISO/IEC 42001-aligned requirements and internal policy - without a parallel paper framework.
The framework is applied through AICOB's forty AI control objectives and five process families, tailored by design factors so depth follows risk and value. Software may automate inventory, policy, runtime guardrails, monitoring and evidence. It does not replace the governing body's duty to evaluate, direct and monitor.
How the four outcomes are developed
Start with outcomes, not tools. The governing body first agrees what "good" looks like for AI: how people should behave, what value AI is for, what must remain under control, and what would keep the organisation trusted if an AI use failed. The process model and the platform come after that agreement.
Translate each outcome into direction. For each outcome the governing body evaluates context and risk, directs policy, appetite and roles, and monitors evidence. Management then executes through the AICOB process families described on the AICOB process model page. An outcome is developed only when that loop is closed: policy, assigned owner, work product and review.
Ethical culture
Developed from the top, then embedded in work. The governing body sets AI purpose, values and acceptable use, and governs ethics so that culture is the result, not a poster. Management turns that into codes, training, incentives, staff communication channels and exception handling. Culture is developed when people can refuse or escalate an AI use that drifts from intended purpose, and when those cases are treated as governance events. Direction and oversight sit with the governing body; policy, people and organisation sit with management. The platform holds the policy and the acceptable-use guardrails that make the culture visible at runtime.
Sustainable performance and value creation
Developed by tying every AI use to organisational purpose and strategy, then measuring value in both directions. The governing body approves strategic objectives for AI and the risk it will accept to pursue them. Management builds a portfolio: intended purpose, expected benefit, cost, and the point at which a use should be changed or retired. Value is developed when expected and realised outcomes are compared, including the drag from incidents, drift and rework. Strategy, architecture and portfolio planning sit in the Align, Plan and Organise family; performance review sits in Monitor, Evaluate and Assess. Inventory and value-tracking on the platform are how the board sees the estate rather than a few showcase models.
Adequate and effective control of AI resources and risks
Developed by putting AI inside the organisation's existing control system, then extending that system to models, agents, software-as-a-service and multi-party components. The governing body defines appetite, delegations and what must return for approval. Management identifies the estate, classifies risk against law and policy, assigns owners, and operates controls through build and run. Control is developed when a change to intended purpose, a new third-party model, or a component owned by another legal entity cannot go live without a named decision. Build and run sit in Build, Acquire and Implement and in Deliver, Service and Support; residual risk is watched through Evaluate, Direct and Monitor. The platform is the control surface: register the use, attach policy, enforce guardrails, watch drift, keep the trail.
Trust, reputation and legitimacy
Developed by making accountability and evidence inspectable, including across entities. The governing body requires that stakeholders can see why AI is used, who answers for it, and what happens when it fails. Management produces named work products: assessments, tests, approvals, remediations, and mappings to the EU AI Act, the UK GDPR / EU GDPR, ISO/IEC 42001-aligned requirements and internal policy. Legitimacy is developed when one process file can be sampled by audit or a regulator, and when responsibility does not vanish because the model, the data and the application sit in different companies. Assurance sits in Monitor, Evaluate and Assess, fed by every family. The platform's evidence pack and audit trail are the operational form of that claim.
Mature the four outcomes together, at different depth. They are developed in parallel, not in a waterfall. Culture without control is a statement. Control without value is bureaucracy. Value without legitimacy is a risk to the licence to operate. Design factors in AICOB set how deep each process goes: a low-risk internal copilot does not need the same build-and-run intensity as a high-risk agent that changes a customer outcome. The outcomes stay the same; the practices scale.
Proof that an outcome has been developed
An outcome is developed when the governing body can answer the matching question from AICOB artefacts and, if used, the platform:
- Culture - What behaviour do we require, and what happened the last time it was breached?
- Performance - Which AI uses serve which objective, and did they create the value we claimed?
- Control - What is in production, who owns it, and which controls ran?
- Legitimacy - What evidence would we hand a regulator, and who is accountable if several entities own the stack?
Until those answers exist, the outcome is declared, not developed.