The AI Risk & Governance Review™
How Executives Defend Their AI Decisions When the Board, the Regulator, the Acquirer, or the Lawyer Asks
Available NowThe governance discipline of the Library. A structured operating model for converting the audit and the assessment into a defensible dossier when a regulator, an auditor, an acquirer, or a carrier asks. The 6-Step Review produces a per-use-case governance dossier; the AI Governance Framework Crosswalk aligns it to ISO/IEC 42001, the NIST AI RMF, the EU AI Act, NYC Local Law 144, SR 11-7, and the sector rules. Plain English, no background in AI law or formal standards required.
The executive briefing, in one page at a time.
A condensed visual companion to the framework. The four forces, the 6-Step Review, the AI Governance Framework Crosswalk, and the per-use-case governance dossier executives use to defend their AI decisions when the board, the regulator, the acquirer, or the lawyer asks. Built for board distribution and leadership team review.
The AI Risk & Governance Review™ is the discipline every leadership team is now being asked to demonstrate, and the one most cannot yet hand across the table.
The pain AI Risk & Governance Review is built to address
The audit did the work. The assessment did the work. Then a regulator opens an inquiry. An auditor tests the AI program against ISO/IEC 42001 or the NIST AI Risk Management Framework. An acquirer runs diligence. An enterprise customer requests an AI attestation. A cyber, E&O, or D&O carrier puts AI questions on the renewal application. The question lands the same way every time. What do you hand them?
Most leadership teams do not have a clean answer to that question right now. Slide decks about AI strategy do not close it. A vendor policy stapled to an employee handbook does not close it. The gap between running AI and being able to defend running AI is what The AI Risk & Governance Review is built to close.
The book is written for the leader who has done the AI work, told the team it was going to change the business, absorbed the friction of adoption, and now has to answer a different kind of question. Not what tools are being used. Not how many employees have logged in. The real question, in the room where the real question gets asked: is this program defensible if someone tests it?
The question has moved from adoption to defensibility
Four stakeholders have arrived at the AI conversation, and they are asking different versions of the same question.
The regulator: is the program consistent with the rules that already apply. The board: who is accountable, and how do we know. The carrier: is the risk exposure understood well enough to underwrite. The acquirer: is the AI program documented, controlled, and clean enough to buy. None of those questions are answered by an adoption metric, a usage report, or a general policy document.
The new executive standard is straightforward. Show that AI is under formal governance discipline, not simply that AI is in use. Volume III is how that standard gets met by a leadership team running with the resources it already has.
What The AI Risk & Governance Review book is
Volume III is an operational execution book for the leader accountable for AI outcomes, not just AI activity. The difference between those two things is larger than it sounds. AI activity is easy to document. A policy fills two pages, a usage report fills a dashboard, and the leadership team feels the box is checked. AI outcomes are harder. They require use-case-level review, evidence collection, framework crosswalking, and a documented decision an outside party can read and accept.
The book does not require a Big Four firm, a Chief AI Officer, an in-house counsel with an AI specialty, or a dedicated compliance department. It requires the same operating discipline a leadership team already applies to finance, hiring, and customer obligations, and it gives that discipline the structure to produce the dossier the business now needs to have ready.
Every chapter connects AI risk to a named operating instrument. Every artifact is built for a small or mid-sized business with a real budget and a lean team. Every framework is designed to produce something you can walk into a room with and defend, not just something you can read and feel good about.
What you will learn from AI Risk & Governance Review
How to run a 6-Step AI Risk & Governance Review that produces a per-use-case governance dossier for each material AI use case. How to map that dossier to the frameworks a regulator, auditor, or acquirer will actually reach for. How to place executive accountability so a board can see who owns what. How to score the program against a five-dimension AI Governance Maturity Scale™ that complements the readiness scoring from Volume II.
The book introduces and develops the named operating instruments leadership teams use to place the AI Operating System™ under formal governance discipline: the 6-Step Review, the Governance Dossier Template, the AI Governance Framework Crosswalk™, the AI Governance Maturity Scale™, the AI Accountability Matrix™, the AI Data Exposure Model™, the Decision Influence Matrix™, the AI Vendor Risk Inventory™, the AI Steering Committee Charter™, three new operating logs that satisfy ISO 42001 Clauses 9 and 10, and the 90-Day Governance Launch Plan™. Each instrument carries a worked example and a usable template.
The lesson that runs through every chapter is the same. AI usage is not AI governance. A policy is not a control. A dashboard is not a dossier. A business that cannot show its work when someone tests it is still running a story rather than a program.
Who AI Risk & Governance Review is written for
The book is written for executives and operating leaders, not lawyers, auditors, or compliance specialists. No background in AI law, information security, procurement, or formal standards is assumed. The goal is a defensible operating program, not a legal treatise.
The roles include owners and presidents, CEOs, CFOs, and COOs, managing partners, board members and operating partners, general counsel and outside counsel, cyber, E&O, and D&O underwriters, and consultants advising mid-market clients. The sectors include professional services, accounting, legal, construction, manufacturing, distribution, healthcare, insurance, financial services, and education, alongside any organization subject to Colorado, Texas, California, New York City, or EU AI rules.
If you are responsible for the AI program, accountable for board reporting, or in a position where someone is going to ask you to defend an AI decision, the book is for you.
How to use AI Risk & Governance Review in your business
Read it with your AI Tool Inventory from Volume I, your readiness decisions from Volume II, and your top three material AI use cases in front of you. Each chapter is designed to help you review one part of your AI program, document what you find, and convert that finding into a decision your leadership team, your board, or an outside party can act on.
The tools in the book are not meant to be read and set aside. They are meant to be used, filled in, and brought into your next leadership meeting. The fifteen-instrument Companion Worksheet library accompanying the book provides every artifact as an editable file, with the 6-Step Review Process Workbook as the operating master.
If you have not completed Volumes I and II, the book still works. You will need to do some foundational mapping as you move through the early chapters, and the book will guide you through that.
The case continuity across the Library
Readers who recognize the seventy-five-person construction firm, the forty-person accounting firm, and the sixty-person professional services practice from earlier Volumes will see them again here. The case patterns are continuations of the same operating realities those businesses face as AI work moves from visibility (Volume I) to readiness (Volume II) to governance (this Volume) to optimization (Volume IV).
Each composite is drawn from patterns observed across many consulting engagements spanning more than two decades of professional practice. No single composite represents a single real engagement. Every composite combines elements from multiple distinct situations, and the specific numeric details are illustrative constructions designed to convey operating patterns in concrete terms.
What is inside AI Risk & Governance Review, chapter by chapter
Chapter 1 names the four forces that have made AI governance an executive obligation, not a compliance topic, and shows why AI governance is not just business governance. Chapter 2 introduces the AI Governance Framework Crosswalk™ and the operational risk categories that organize the rest of the book. Chapter 3 places executive accountability and AI literacy at the top of the program, where a regulator or acquirer will look first. Chapter 4 maps data risk and confidentiality exposure through the AI Data Exposure Model™. Chapter 5 maps decision risk against the trustworthiness characteristics from the NIST AI RMF, using the Decision Influence Matrix™. Chapter 6 maps vendor dependency risk and third-party exposure through the AI Vendor Risk Inventory™. Chapter 7 maps compliance, regulatory, and financial reporting exposure across the sector rules already in force. Chapter 8 installs the 6-Step AI Risk & Governance Review as the operating routine that produces the per-use-case governance dossier. Chapter 9 places the governance operating structure and board oversight around the review so accountability holds. Chapter 10 installs policies, internal audit, and management review as the recurring discipline. Chapter 11 installs the AI Incident Response Framework™ so an incident is met with a documented process rather than an improvised one. Chapter 12 launches the program on the 90-Day Governance Launch Plan™ and shows how governance discipline converts into commercial value: cleaner renewals, better diligence outcomes, and a defensible position when the question arrives.
Where AI Risk & Governance Review sits in The Operating Discipline for AI Library™
Volume III is the governance discipline of Pillar I, AI Business Services™. The four Volumes in Pillar I sequence the operating disciplines a business needs to install AI honestly: visibility (Volume I), readiness (Volume II), governance (this Volume), and optimization (Volume IV). Volumes I and II build the foundation the review draws from. Volume III makes the AI program defensible. Volume IV makes it measurably valuable. A business that finishes Pillar I has both.
Pillar II, AI Risk Governance & Security™, runs in parallel and addresses the security side of the AI Operating System™ through five further Volumes. The two pillars are deliberately independent.
How the book and the AI Risk & Governance Review engagement work together
The book is the methodology, written for leadership teams that want to run the discipline themselves. The AI Risk & Governance Review engagement is the execution, designed for leadership teams that want the per-use-case governance dossier produced, scored, and pressure-tested against their own AI use cases and their own operating context inside a defined engagement window.
Both share the same underlying operating instruments. The choice is whether to read, draft, and refine internally over six months, or to bring the firm in and have the dossier on the table when the next diligence question, carrier renewal, or regulator inquiry arrives. Aligning with the NIST AI Risk Management Framework and ISO/IEC 42001 does not, by itself, produce these answers. Those frameworks define the governance obligations. The book is the operating discipline that meets them inside a real business, with a real cost base and a lean team.
Free downloads for this book
The worksheets and templates that ship with this book are free. Enter your email once, click the confirmation link we send you, and every book's downloads unlock across the site, forever.
Every governance instrument, editable and ready to use.
Every governance instrument from the book, free and editable, ready to use in a live Risk & Governance Review. Works in Microsoft Office, Google Workspace, Apple iWork, and LibreOffice.
The book’s operating workbook. Walks each material AI use case through the six-step Risk & Governance Review and produces the per-use-case governance dossier.
Visual frameworks, ready for your presentations.
Every diagram, framework, and chart from the book is available here as an individual file. Use them in your slide decks, internal memos, board presentations, or training sessions. Free to use within your organization. Browse by chapter, click any image to download.
Explore the full book series.
The Operating Discipline for AI Library™ is the nine-book series across two pillars — AI Business Services™ (four books) and AI Risk Governance & Security™ (five books) — each mapped to one of the nine SRJ service lines. Browse the series, or speak with us directly about applying the framework in your organization.