technical report

AI governance and risk management

Your organisation already uses artificial intelligence. The question is not whether to use it, but whether to govern it. This 17-page report organises the risk assessment, the applicable regulatory framework and the governance model ISO/IEC 42001 requires.

Pages
18
Format
PDF
Language
English
Cost
Free

What it covers

  • The three layers of AI usage that show up in every inventory, including the one nobody declared.
  • The full regulatory framework: ISO standards, NIST, the European Regulation with its application calendar, the regional picture and current Uruguayan law.
  • ISO/IEC 42001 governance model: principles, three-lines roles and the components of the management system.
  • Seven families of risk, from data leakage to the fragility of LLM-based automation.
  • What to verify before enabling a corporate assistant: the three modes, data oversharing and the supply chain.
  • A risk matrix with fifteen risks and thirteen controls mapped to Annex A.
  • A roadmap across three horizons, from immediate containment to certification.

Who it is for

  • Boards that need to decide on AI with judgement rather than headlines.
  • Information security and IT leads who have already seen Shadow AI appear.
  • Compliance and legal teams that must anticipate the regulation coming their way.