How to Build an AI Governance Program: a records-based guide for organizations that use AI.
This white paper describes how a small or midsize organization that deploys and uses artificial intelligence builds a governance program, in order, from the first management decision to the first sustainment review. Its thesis runs through every section: the program is built from records outward, because records are what every statute, framework, customer, and carrier ultimately asks for. Published August 2026. Free PDF, no registration.
The program, built in sequence
- Step Zero: the management mandate, owner, and scope
- The AI use inventory, built from the environment
- The eight decisions of a working AI use policy
- NIST AI RMF and ISO/IEC 42001 alignment at deployer depth
- AI vendor and embedded AI oversight
- Sustainment, and the program at a fifty person manufacturer
Built for the executive who has to answer AI questions in writing.
Most organizations now facing AI governance questions did not choose the timing. The questions arrive from outside: an AI clause in a customer contract, a question on a cyber insurance renewal, a due diligence questionnaire, a flowdown from a prime, or a statute that reaches the organization through the residents its systems affect. The paper opens with the question executives ask first, why build now when the rules keep moving, and answers it with the record: the statutes have churned while the frameworks underneath them held still, and one state has written framework compliance into its statutory defense structure. Waiting is not neutral, because representations are being made during the wait.
The paper then builds the program's five components in sequence, each defined by the records it produces: the AI use inventory, the use policy, framework alignment, vendor and embedded AI oversight, and sustainment. It closes with the program at working scale, a profile of what each component looks like at a fifty person manufacturer, and a one page build sequence that can be handed to whoever will own the work. The scope is deliberate: this is the deployer and user version of the program, for organizations that buy and use AI rather than developing it, which is the honest scope for most small and midsize companies.
What the paper covers.
Eight sections, each ending where a governance program should: with the records produced.
Why build now, against rules that keep moving
The Colorado repeal and reenactment, the revised EU application dates, the unresolved federal preemption initiative, and the Texas defense structure, resolved into the planning conclusion the rest of the paper builds on: govern to stable frameworks and hold the records.
The architecture and Step Zero
The five components in one view, the record set each produces, the deployer and developer scaling note, and the management mandate that precedes component one: sponsor, owner, scope, decision authority, and reporting cadence.
The AI use inventory
Why the inventory precedes the policy, the two entry paths it must cover, employee adoption and vendor embedded features, the evidence sources that build it, and the jurisdictional reach field that maps state law exposure.
The AI use policy
A policy as a set of decisions rather than a document about intentions: the eight decisions a working policy makes, who owns them, and the rollout that pairs new rules with the approved path.
Framework alignment
The NIST AI RMF at deployer depth, the Generative AI Profile applied where generative tools exist, ISO/IEC 42001 as the institutionalization path, and an honest rule for when certification earns its cost.
Vendors, sustainment, and working scale
The six areas of AI vendor and embedded AI review, the sustainment calendar that keeps the program accurate, and the full build profiled at a fifty person manufacturer with a one page build sequence.
Read the paper.
The white paper is available as a free PDF with no registration: How to Build an AI Governance Program: A Records-Based Guide for Small and Midsize Organizations That Use AI (August 2026). The GRC for AI white paper hub lists each paper in this series as it publishes, and the reference pages of the AI governance cluster carry the maintained analysis behind it, including the state AI law tracker and the Texas TRAIGA analysis the paper draws on. New papers are announced through the Daily Cybersecurity Brief.
Discuss the Program the Paper Describes
Inquiries may involve any component the paper covers: building the AI use inventory, developing the use policy, NIST AI RMF or ISO/IEC 42001 alignment, AI vendor review, or standing up the sustainment rhythm. Call, email, or send a note. I respond personally to every inquiry, usually within one business day.
Discuss an Assessment
If the paper raises a question about your organization's AI use, its policy, its framework position, or its records, the first conversation carries no commitment and no pitch.
Discuss an Assessment →