14 items in AI Governance
Responsible AI fails as a poster and works as a control system. This guide turns three commitments into operating practice: bias testing built on NIST's three-category taxonomy of systemic, statistical, and human bias; explainability grounded in NIST's four principles and the SHAP, LIME, and attention-visualization toolbox; and ethics training run as a measured control on human judgment.
Model risk management is not a discipline you need to invent for AI. SR 11-7 defined it in 2011: validate every model you use — including the ones you buy — monitor it continuously, and keep the authority and the machinery to restrict, fix, or roll it back when it fails. This guide maps that framework onto third-party AI models end to end.
ISO/IEC 42001 is the standard you certify against, the NIST AI RMF is the framework you organize risk work around, and continuous monitoring is how either stays true between audits. This guide maps the two instruments, the documentation layer that feeds them, and the automation that makes governance an operational property rather than a binder.