LTK Soft

AI Governance

AI Governance in 2026: A Practical Playbook Using NIST AI RMF, ISO/IEC 42001, and the EU AI Act

Customers, auditors, and regulators are all asking how you control your AI. Here is a practical way to answer them without burying your teams in paperwork.

LTK

LTK Soft Team

12 min read

Shield with a checkmark between two compliance checklists
Key takeaways
  • Start with an inventory. You cannot govern AI you don't know about — including AI built into the SaaS tools you already use.
  • Tier every use case by risk and scale the controls to the tier. Most internal use cases need light controls.
  • NIST AI RMF tells you what to think about, ISO/IEC 42001 tells you how to run it as a management system, and the EU AI Act tells you what is legally required.
  • Evidence matters as much as policy: keep evaluation results, decision logs, and approvals where an auditor can find them.

Two years ago, AI governance was a topic for large banks and big tech. Today it shows up in ordinary security questionnaires, enterprise contracts, cyber-insurance renewals, and board meetings. Buyers want to know which AI systems touch their data, how outputs are checked, and who is accountable when something goes wrong.

The good news is that governing AI well does not require a new department. It requires a clear inventory, sensible risk tiers, controls that match those tiers, and evidence that the controls work.

Why AI governance can’t wait

  • Regulation is arriving in stages. The EU AI Act entered into force in August 2024, with bans on prohibited practices from February 2025, obligations for general-purpose AI models from August 2025, and most high-risk requirements phasing in from 2026 onward. In the US, state laws such as Colorado’s AI Act and New York City’s rules on automated hiring tools add their own requirements.
  • Customers are asking. Enterprise buyers now include AI-specific questions in vendor reviews. Having clear answers shortens sales cycles.
  • Shadow AI is already here. Employees use public AI tools whether or not there is a policy. Governance is how you channel that into approved, safe tools.

The three frameworks, compared

FrameworkWhat it isBest used for
NIST AI RMFVoluntary US framework built around four functions — Govern, Map, Measure, Manage — with a companion profile for generative AI (NIST AI 600-1)Structuring how you identify and reduce AI risks
ISO/IEC 42001International, certifiable standard for an AI management system, published in 2023Running governance as a repeatable, auditable process — and proving it to customers
EU AI ActLaw that sorts AI systems into prohibited, high-risk, limited-risk (transparency), and minimal-risk categoriesKnowing what is legally required for systems used in the EU

These fit together rather than compete. A practical programme uses NIST AI RMF to think through risks, runs the process the way ISO/IEC 42001 describes, and checks each system against the EU AI Act and any US rules that apply. As an ISO 27001-certified company, we have found that organisations with an existing information security management system can reuse much of that structure.

The six-step playbook

  1. Inventory every AI use. Custom models, LLM integrations, vendor tools, and AI features inside existing SaaS products. Record the owner, purpose, data used, and who is affected.
  2. Tier each use case by risk. Consider who is affected, what decisions the system influences, what data it touches, and how easily a mistake can be caught and reversed.
  3. Publish an acceptable-use policy. Which tools are approved, what data may never be entered, and how to request a new use case. One or two pages is enough.
  4. Apply controls by tier. Data protection, human oversight, testing, logging, and vendor review — scaled to the risk, as shown below.
  5. Keep the evidence. Evaluation results, model and data documentation, approvals, incidents, and decision logs, stored where auditors can find them.
  6. Monitor and review. Re-test after model or prompt changes, review the inventory quarterly, and track incidents to closure.

Controls by risk tier

TierExamplesMinimum controls
LowDrafting internal emails, summarising public documents, code suggestionsApproved tools only, no confidential data in public tools, user training
MediumInternal knowledge assistants, document extraction with human review, support draftingPrivate deployment, access controls that mirror source permissions, logging, evaluation before release
HighDecisions about people — claims, credit, hiring, care — or actions taken without reviewDocumented risk assessment, bias and accuracy testing, human approval for adverse outcomes, explainability, full audit trail, regular independent review

Keeping governance lightweight

A one-page intake form beats a sixty-page policy

The governance programmes that work are the ones teams actually use. A short intake form for new AI use cases, a fast approval path for low-risk work, and deeper review only where the risk justifies it will do more than a long policy nobody reads.

Governance should also make building easier, not harder. When the approved patterns — a private LLM endpoint, a standard logging setup, a reusable evaluation harness — already exist, teams pick the safe path because it is the fastest one. Our guide to private AI and RAG describes one such pattern.

Find out where your AI governance gaps areInventory, data mapping, control assessment, and a prioritised remediation plan aligned to NIST AI RMF and your applicable frameworks.
See the governance audit

Frequently asked questions

Do we need ISO/IEC 42001 certification?

Not necessarily. Certification makes sense when customers or regulators ask for independent proof, or when AI is central to your product. Many companies start by aligning their practices with ISO/IEC 42001 and NIST AI RMF, then certify later. If you already hold ISO 27001, much of the management-system structure carries over.

Does the EU AI Act apply to US companies?

It can. The Act applies to companies that place AI systems on the EU market or whose AI outputs are used in the EU, regardless of where the company is based. Obligations depend on the risk category of each system, and several deadlines have been phased in or proposed for adjustment, so confirm the current timeline with legal counsel.

What is shadow AI and why does it matter?

Shadow AI is AI use the organisation does not know about — employees pasting data into public chatbots, or AI features switched on inside existing SaaS tools. It matters because it is where confidential and personal data most often leaks. An AI inventory and a clear acceptable-use policy are the first defence.

Who should own AI governance in a mid-size company?

A small cross-functional group works best: a senior business sponsor, security or compliance, legal or privacy, and a technical lead who understands how the AI systems are built. It should meet regularly and own the AI inventory, the risk tiers, and approvals for new use cases.

Need to show customers and auditors your AI is under control?

Our AI Governance & Compliance Audit inventories your AI use, maps the gaps, and gives you a prioritised remediation plan.