D5: AI Governance & Risk — AEBOK™

AEBOK™D5AI Governance & Risk
D5

AEBOK™ v0.1 · Knowledge Domain

AI Governance & Risk

21 min read
Updated June 2026
ATP™AGL™

Scope

Domain 5 covers the design and implementation of AI governance frameworks — the policies, controls, oversight mechanisms, and accountability structures that ensure autonomous AI systems operate within defined ethical, legal, and organizational boundaries.

AI governance is the most consequential domain in the AEBOK™ for organizations deploying autonomous systems in high-stakes environments. It is also the most frequently underinvested. Organizations that treat governance as a compliance exercise — a set of policies to be documented and filed — consistently encounter governance failures that damage their reputation, expose them to regulatory risk, and undermine stakeholder trust in their AI programs.

The AEBOK™ treats governance as an enabler of transformation, not a constraint on it. Organizations with strong governance frameworks can deploy autonomous systems faster, with greater confidence, and with broader stakeholder support than those without. Responsible AI is faster AI.

What This Domain Covers

  • The AEGF™ five governance domains: Ethics, Risk, Compliance, Oversight, Accountability
  • AI policy design — the policies that govern AI development, deployment, and operation
  • AI risk management — identifying, assessing, and mitigating AI-specific risks
  • AI compliance — navigating the regulatory landscape for autonomous AI
  • AI oversight mechanisms — the controls that ensure human accountability for AI-executed processes
  • AI accountability structures — who is responsible for what when AI systems cause harm
  • Governance operating model — how the governance framework is operationalized

Core Concepts

C5.1 — The AEGF™ Five Governance Domains

The Autonomous Enterprise Governance Framework organizes AI governance around five domains. Each domain addresses a distinct dimension of the governance challenge — and each is necessary. Organizations that address only some of the five domains have governance frameworks with structural gaps that will eventually produce failures.

  • Domain 1 — Ethics: The principles and values that govern how AI systems are designed, deployed, and operated. Ethical governance addresses questions of fairness, transparency, privacy, and human dignity. It establishes the boundaries within which AI systems may operate — regardless of what is technically possible or commercially attractive.
  • Domain 2 — Risk: The identification, assessment, and mitigation of AI-specific risks. AI risk management extends traditional enterprise risk management to address risks that are unique to autonomous systems: model drift, adversarial attacks, unintended consequences, and the compounding effects of AI errors in automated workflows.
  • Domain 3 — Compliance: The policies and controls that ensure AI systems comply with applicable laws, regulations, and standards. The regulatory landscape for AI is evolving rapidly — the EU AI Act, the NIST AI Risk Management Framework, and sector-specific regulations in financial services, healthcare, and critical infrastructure are creating new compliance requirements that organizations must navigate.
  • Domain 4 — Oversight: The mechanisms that ensure human accountability for AI-executed processes. Oversight governance addresses the question of how humans maintain meaningful control over autonomous systems — not by micromanaging every decision, but by establishing the monitoring, alerting, and intervention mechanisms that allow humans to detect and correct AI errors before they cause significant harm.
  • Domain 5 — Accountability: The structures that define who is responsible for what when AI systems cause harm. Accountability governance addresses the accountability gap that autonomous systems create: when an AI agent makes a decision that causes harm, who is responsible? The developer? The deployer? The user? The organization? Accountability governance answers this question before harm occurs — not after.

C5.2 — AI Risk Taxonomy

AI risk management requires a taxonomy that distinguishes AI-specific risks from the general enterprise risk categories that traditional risk management addresses. The AEBOK™ AI risk taxonomy identifies six categories:

  • Model risk: The risk that an AI model produces incorrect, biased, or unreliable outputs. Includes training data quality risk, model drift risk, and distributional shift risk — the risk that the model encounters inputs that differ significantly from its training data.
  • Operational risk: The risk that AI systems fail, produce errors, or behave unexpectedly in production. Includes infrastructure failure risk, integration failure risk, and the risk of cascading failures in multi-agent systems where one agent's error propagates through a workflow.
  • Ethical risk: The risk that AI systems produce outcomes that are unfair, discriminatory, or harmful to individuals or groups. Includes algorithmic bias risk, privacy risk, and the risk of unintended consequences from optimization objectives that do not fully capture human values.
  • Regulatory risk: The risk that AI systems violate applicable laws, regulations, or standards. This risk is growing rapidly as the regulatory landscape for AI evolves — organizations that deploy AI systems without monitoring the regulatory environment may find themselves in violation of new requirements without warning.
  • Reputational risk: The risk that AI systems produce outcomes that damage the organization's reputation with customers, employees, investors, or the public. Reputational risk from AI failures can be severe and rapid — AI incidents that go viral on social media can cause lasting brand damage.
  • Strategic risk: The risk that AI governance failures undermine the organization's AI Transformation strategy. This includes the risk that governance failures cause the board or executive team to withdraw support for the transformation program, and the risk that regulatory action forces the organization to shut down AI systems that are central to its competitive strategy.

C5.3 — AI Policy Architecture

An AI policy architecture is the structured set of policies that govern AI development, deployment, and operation across the enterprise. A complete AI policy architecture includes policies at three levels:

  • Enterprise AI Policy: The top-level policy that establishes the organization's principles, values, and commitments for AI. This policy is approved by the board and signed by the CEO. It establishes the ethical boundaries within which all AI development and deployment must occur.
  • Domain-Specific AI Policies: Policies that address specific governance domains — AI risk management policy, AI data governance policy, AI model governance policy, AI vendor management policy, and AI incident response policy. These policies are approved by the CAIO and the relevant functional leaders.
  • Operational AI Standards: The technical and procedural standards that operationalize the domain-specific policies. These standards define the specific controls, processes, and tools that AI teams must use to comply with the policies. They are approved by the AI CoE and updated as technology and best practices evolve.

C5.4 — The Governance Operating Model

A governance framework that exists only as a set of policy documents is not a governance framework — it is a compliance artifact. Effective AI governance requires a governance operating model: the organizational structures, processes, and tools that make the governance framework operational.

The governance operating model has four components:

  • AI Governance Council: The cross-functional body that owns the AI governance framework and makes governance decisions at the enterprise level. Chaired by the CAIO, with membership from Legal, Risk, Compliance, HR, and the major business units.
  • AI Risk and Compliance Function: The team responsible for AI risk assessment, compliance monitoring, and governance reporting. This function is typically part of the second line of defense in the three-lines-of-defense model.
  • AI Audit Function: The independent function responsible for assessing the effectiveness of the AI governance framework. This function is typically part of the third line of defense.
  • AI Incident Response Process: The process for detecting, investigating, and responding to AI governance failures. Includes escalation procedures, communication protocols, and remediation requirements.

C5.5 — Governance by Design

The most effective AI governance is governance that is designed into AI systems from the beginning — not retrofitted after deployment. Governance by design means that every AI system is designed with its governance requirements in mind: the monitoring mechanisms, the audit trails, the human oversight interfaces, and the shutdown procedures are built into the system architecture, not added as afterthoughts.

Governance by design has three practical implications for AI development teams:

  • Explainability requirements: AI systems deployed in high-stakes contexts must be able to explain their decisions in terms that human overseers can understand and evaluate. This requirement must be specified before development begins — not after the model is built.
  • Audit trail requirements: Every AI agent action must be logged in a way that supports post-hoc investigation of AI behavior. The audit trail must be complete, tamper-proof, and accessible to the governance function.
  • Human override requirements: Every AI system must have a clearly defined and tested human override mechanism. The override must be accessible to the appropriate human overseer and must be capable of stopping or reversing AI actions within a defined time window.

Framework Alignment

AEGF™ — Primary Framework

The AEGF™ is the primary framework for D5. All governance design work in this domain uses the five-domain architecture as its organizing structure.

AEOM™ — Supporting Framework

The governance operating model is a component of the AI operating model. D5 governance design must be integrated with D4 operating model design — the governance council, risk function, and audit function are organizational structures that must be reflected in the operating model.

Practitioner Tools

Tool D5.1 — AEGF™ Governance Assessment

A structured assessment of the organization's current governance framework across the five AEGF™ domains. Identifies gaps between the current framework and the governance requirements of the target AI operating model.

Tool D5.2 — AI Risk Register Template

A structured template for documenting AI risks across the six risk categories. Includes risk description, likelihood assessment, impact assessment, current controls, residual risk rating, and risk owner.

Tool D5.3 — AI Policy Architecture Template

A structured template for developing the three-level AI policy architecture. Includes the Enterprise AI Policy template, domain-specific policy templates, and operational standards templates.

Tool D5.4 — AI System Governance Checklist

A pre-deployment checklist for AI systems that verifies governance requirements have been met before the system goes into production. Covers explainability, audit trail, human override, risk assessment, compliance review, and stakeholder communication.

Tool D5.5 — AI Incident Response Playbook

A structured playbook for responding to AI governance failures. Covers detection, investigation, containment, remediation, communication, and post-incident review.

Competency Indicators

Level 1 — Awareness

Can describe the five AEGF™ governance domains and explain why each is necessary. Understands the AI risk taxonomy and can identify examples of each risk category. Can explain the difference between a governance framework and a compliance program.

Level 2 — Practitioner

Can conduct an AEGF™ governance assessment. Can develop an AI risk register for a specific AI system or program. Can produce an AI policy architecture for a specific organizational context. Can facilitate a governance by design review for an AI system in development.

Level 3 — Architect

Can design the complete AI governance framework for an enterprise AI Transformation program. Can integrate governance design with operating model design, technology architecture, and compliance requirements. Can lead the governance operating model implementation for a complex organization.

Level 4 — Leader

Can own the AI governance framework at the enterprise level. Can represent the organization's governance standards to regulators, investors, and the board. Can make the governance investment decisions required to build a trustworthy Autonomous Enterprise.

Certification Mapping

ATP™

D5 constitutes approximately 15% of the ATP™ exam. Candidates are tested on their ability to describe the AEGF™ architecture, identify AI risks, and explain the governance operating model.

AGL™ — AI Governance Leader

D5 constitutes approximately 70% of the AGL™ exam. The AGL™ is the specialist certification for AI governance practitioners. The capstone requires candidates to design a complete AI governance framework — including risk register, policy architecture, governance operating model, and incident response playbook — for a real or hypothetical organization.

Case Study: GlobalBankCo (Governance Failure)

Composite case study. All names and identifying details are anonymized.

Context

GlobalBankCo (introduced in D1) had successfully deployed an AI-powered credit decisioning system that reduced loan processing time from 5 days to 4 hours. The system was performing well on its primary metrics — speed and approval rate — when a routine audit revealed a significant problem.

The Problem

The credit decisioning AI had developed a pattern of systematically disadvantaging applicants from certain zip codes — zip codes that correlated with minority populations. The model had not been trained to discriminate; it had learned the pattern from historical lending data that reflected decades of discriminatory lending practices. The model was perpetuating historical bias at scale and at speed.

The governance failure was not in the model — it was in the governance framework. The AI system had been deployed without an ethical risk assessment, without a bias monitoring mechanism, and without a defined process for detecting and responding to discriminatory outcomes. The governance framework existed on paper but had not been applied to this deployment.

The Intervention

The system was taken offline while a governance remediation was conducted. The AEGF™ governance assessment revealed that GlobalBankCo's governance framework had significant gaps in the Ethics and Oversight domains — the two domains most relevant to the bias failure.

The remediation included: a bias assessment methodology for all AI systems in production, a fairness monitoring dashboard that tracked outcomes by demographic group, a pre-deployment governance checklist that required ethical risk assessment before any AI system could go into production, and an AI Governance Council with explicit responsibility for ethical oversight.

The Outcome

The credit decisioning system was redeployed 4 months later with bias controls in place. The governance remediation took 6 months and cost significantly more than the governance framework would have cost if it had been designed upfront. The reputational damage from the incident — which became public — took longer to repair.

Key Lesson

Governance by design is not a luxury — it is a risk management imperative. The cost of retrofitting governance onto deployed AI systems is an order of magnitude higher than designing governance upfront. And the cost of a governance failure — in regulatory exposure, reputational damage, and stakeholder trust — can be existential.

Monday Morning Actions

For Practitioners — This Week

  • Conduct an AEGF™ governance assessment for one AI system currently in production in your organization. Which of the five governance domains are adequately addressed? Which are missing or underdeveloped?
  • Review the AI risk register for your current program. Does it include all six risk categories? Are the risks rated accurately? Are the controls adequate?
  • Identify one AI system in your organization that was deployed without a governance by design review. What governance gaps does it have? What would it take to remediate them?

For Managers — This Month

  • Implement the AI System Governance Checklist as a mandatory pre-deployment requirement for all new AI systems in your domain. Identify any systems currently in development that would not pass the checklist and initiate governance remediation.
  • Establish a quarterly AI risk review process for your AI program. Review the risk register, assess the effectiveness of current controls, and identify emerging risks that need to be addressed.
  • Develop an AI incident response plan for your domain. Define the escalation procedures, communication protocols, and remediation requirements for AI governance failures.

For Executives — This Quarter

  • Commission an AEGF™ governance assessment for your enterprise AI program. Present the results to the board with a recommendation for the governance investments required to address identified gaps.
  • Establish an AI Governance Council with clear membership, authority, and accountability. Ensure the council has the cross-functional representation required to address all five governance domains.
  • Review your organization's regulatory exposure for AI. Which regulations apply to your AI systems? Are you compliant? What would a regulatory audit reveal?