technical report
AI governance and risk management
Your organisation already uses artificial intelligence. The question is not whether to use it, but whether to govern it. This 17-page report organises the risk assessment, the applicable regulatory framework and the governance model ISO/IEC 42001 requires.
- Pages
- 18
- Format
- Language
- English
- Cost
- Free
What it covers
- The three layers of AI usage that show up in every inventory, including the one nobody declared.
- The full regulatory framework: ISO standards, NIST, the European Regulation with its application calendar, the regional picture and current Uruguayan law.
- ISO/IEC 42001 governance model: principles, three-lines roles and the components of the management system.
- Seven families of risk, from data leakage to the fragility of LLM-based automation.
- What to verify before enabling a corporate assistant: the three modes, data oversharing and the supply chain.
- A risk matrix with fifteen risks and thirteen controls mapped to Annex A.
- A roadmap across three horizons, from immediate containment to certification.
Who it is for
- Boards that need to decide on AI with judgement rather than headlines.
- Information security and IT leads who have already seen Shadow AI appear.
- Compliance and legal teams that must anticipate the regulation coming their way.
