Tier 1: Foundation controls
AI management system (AIMS)
A structured management system that defines AI governance policies, roles, processes, and controls across the AI lifecycle, aligned to an auditable standard.
Board-defensible evidence
- AIMS scope statement defining which business units, geographies, and AI systems are covered, who approves scope changes, and how exclusions are justified and documented.
- Policy and procedure set covering risk classification, approval gates, documentation requirements, monitoring, incident response, vendor governance, and exceptions, including version history and approval dates.
- Management review artifacts showing periodic review by executive leadership, decisions made, resourcing actions taken, and tracked corrective actions with owners and deadlines.
- Internal audit or control testing records showing that AIMS controls were tested, deficiencies were logged, remediation was verified, and repeat findings were escalated.
- Training and competency records showing who is authorized to develop, deploy, approve, or monitor AI systems, with completion dates and role-based training requirements.
Why this matters
When scrutiny hits, a defensible management system is how you show governance is operational, not a slide deck.
How ready is your board on foundation controls?
Twelve questions, scored across all four tiers, with your gaps named — or take the whole framework into your next meeting.