Start here if you own the AI governance programme.

Eight stops, in order — from operating model to working registers to downloadable templates. Framework-cited throughout, so you can go straight to the clause or article that matters.

  1. The operating model and evidence expectations The ISO/IEC 42001 clause table, mapped to what a reviewer actually expects to see.
  2. The regulatory timeline and framework crosswalk What's active now versus deferred under the EU AI Act, and where ISO/IEC 42001 and the NIST AI RMF each answer a different question.
  3. The security control flow Five stages, mapped to the OWASP Top 10 for LLM Applications, and what evidence a security reviewer expects.
  4. The delivery lifecycle control points From architecture through retirement — where governance intent has to become enforced, running behaviour.
  5. How risk actually maps to control The taxonomy, severity model, and the difference between a primary, supporting, and compensating control.
  6. The registers themselves 48 risks, 22 controls, each mapped to framework clauses and to each other — the working reference, not a summary of it.
  7. Third-party and vendor governance Where AI risk that genuinely isn't yours to control still needs to be governed as if it were.
  8. Templates you can use today Downloadable checklists and register templates built for running an AIMS, not just reading about one.

Building or running an AIMS is one of five areas of expertise.

AI Governance & AIMS Implementation is grounded in exactly this clause structure.