web analytics
AI Governance

General Business Governance

ISO 27001, SOC 2, NIST CSF, COSO ERM

The one-paragraph answer

AI general governance is the pre-existing set of business control frameworks that layer beneath AI-specific governance. ISO 27001 (information security), SOC 2 (service organization controls), NIST CSF (cybersecurity), and COSO ERM (enterprise risk management) all cover parts of what AI governance requires. None of them substitute for AI-specific frameworks like ISO/IEC 42001 and NIST AI RMF, but all of them provide the foundation on which AI governance sits.

The pain AI general governance is causing our customers

Companies with mature ISO 27001, SOC 2, and NIST CSF programs assumed those frameworks would cover AI. They partially do. But AI introduces specific risks (bias, hallucination, model drift, training data provenance) that pre-existing frameworks were not designed to address. The pain is figuring out what carries over from existing frameworks, what needs new AI-specific coverage, and how to integrate without creating parallel compliance systems.

What AI general governance frameworks cover

Each of the four frameworks addresses different but overlapping domains. Click into each for detail.

Why AI general governance matters to you

Because AI governance built without leveraging existing frameworks is inefficient and expensive. Companies with SOC 2 already have vendor management, access controls, and monitoring. Companies with ISO 27001 have information security. Companies with COSO ERM have risk management structure. Integrating AI into these existing frameworks (rather than building parallel ones) is what mature governance looks like.

What the research says about business governance

The academic literature on business governance is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.

“the understanding of how such principles can be operationalized in designing, executing, monitoring, and evaluating AI applications is limited”

That is the gap between having AI and governing it. The second finding is the one that tends to change the room.

“AI governance is a system of rules, practices and processes employed to ensure an organization's use of AI aligns with its strategies, objectives, and values.”

Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about business governance arrives from the board, the buyer, or the regulator.

How to get compliant with General Business Governance: a 5-step path

This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.

  1. Inventory the AI in scope. List every AI system that could fall under business governance. Record what it does, what decision it influences, what data it touches, and who owns it. You cannot govern AI you cannot name, and almost every organisation we assess is running more AI than its leadership believes.
  2. Determine whether you are actually in scope. Work out precisely which of your AI systems and activities business governance reaches, and write the determination down with its reasoning. Do this in writing. A documented scope determination, right or wrong, is defensible. An undocumented assumption is not.
  3. Assign one accountable owner. Name a person, not a committee, with the authority to stop a deployment. Governance without someone who can say no is documentation, not control.
  4. Build the evidence file. Assemble the documentation business governance expects: the scope, the risk assessment, the controls, the testing evidence, and the incident record. Assemble it before anyone asks. Reconstructing it under a regulator's deadline costs several times more and looks exactly like what it is.
  5. Set a review cadence and hold it. Re-run the assessment on a schedule and after any material change to the model, the data, or the use case. Alignment decays. A control tested once is a snapshot, not a control.

Done in this order, business governance becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.

Frequently asked questions about AI general governance

Does having SOC 2 satisfy AI governance?

No. SOC 2 covers security, availability, confidentiality, processing integrity, and privacy. It does not address AI-specific risks like bias or model management.

Where does AI general governance fit in SRJ's work?

The AI Governance Framework Crosswalk™ (Appendix L of Volume III of The Operating Discipline for AI Library™) maps each general framework to specific AI governance artifacts.

What each area of business governance covers

The detail pages below each take one component of business governance and answer the same four questions: what it actually is, what it requires of you, why it matters commercially and legally, and what a defensible position looks like. Read the one that maps to your exposure first. The others become relevant as your AI footprint widens.

  • ISO 27001 and AI. How ISO 27001 information security controls apply to AI systems and where they fall short.
  • SOC 2 and AI. How SOC 2 Trust Services Criteria (security, availability, confidentiality, processing integrity, privacy) apply to AI providers.
  • NIST Cybersecurity Framework and AI. How the NIST Cybersecurity Framework (Identify, Protect, Detect, Respond, Recover, Govern) applies to AI systems.
  • COSO ERM and AI. How the COSO Enterprise Risk Management framework covers AI risks and where AI needs its own layer.

How to prioritise your work on business governance

Executives ask, reasonably, where to start. The sequence that works is the same one every time, and it is not the sequence most organisations choose. Start with an inventory: you cannot govern AI you cannot list, and almost every organisation we assess is using more AI than its leadership believes. Then rank by consequence, not by volume, because the tool that makes one high-stakes decision a week carries more exposure than the one that drafts a thousand emails.

Only then assign an owner. Not a committee, an owner, named, with the authority to stop a deployment. Governance without a person who can say no is documentation, not control. With those three steps done, the specific requirements of business governance become tractable, because you now know what you have, what matters, and who answers for it.

The organisations that struggle are the ones that begin with the framework and work backwards toward reality. The frameworks are the map. The inventory is the territory. Start with the territory.

Primary sources on business governance

The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning business governance that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.

Deep dives in this category

  • ISO 27001 and AI How ISO 27001 information security controls apply to AI systems and where they fall short.
  • SOC 2 and AI How SOC 2 Trust Services Criteria (security, availability, confidentiality, processing integrity, privacy) apply to AI providers.
  • NIST Cybersecurity Framework and AI How the NIST Cybersecurity Framework (Identify, Protect, Detect, Respond, Recover, Govern) applies to AI systems.
  • COSO ERM and AI How the COSO Enterprise Risk Management framework covers AI risks and where AI needs its own layer.

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including General Business Governance, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation