Framework-grounded AI governance · updated 2026-07-14
Assess AI governance maturity and source vetted AI governance consultants.
Model Governance Index organizes 5 named frameworks - NIST AI RMF, ISO/IEC 42001, IIA's AI Auditing Framework - into 4 buyer guides, and pairs each with a sourced reference to20 notable real vendors in the space. Buyer education and a direct line to consultants. Not a compliance guarantee, not legal advice.
Named frameworks
What this index is organized around
Real, independently-issued frameworks, cited directly rather than paraphrased.
Artificial Intelligence Risk Management Framework (AI RMF 1.0)
The NIST AI RMF provides voluntary guidance to help organizations that design, develop, deploy, or use AI systems manage risks to individuals, organizations, and society. It is intended for use across sectors, use cases, and organization sizes, and is not tied to any specific technology. The framework organizes AI risk management around four functions, Govern, Map, Measure, and Manage, oriented toward seven characteristics of trustworthy AI: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed.
ISO 42001ISO/IEC 42001:2023 - Information technology - Artificial intelligence - Management system
ISO/IEC 42001:2023 specifies requirements, with guidance, for establishing, implementing, maintaining, and continually improving an AI management system (AIMS) within an organization. It is the first international management-system standard written specifically for AI and is designed for any organization, of any size or sector, that provides or uses AI-based products or services. It addresses AI-specific concerns such as algorithmic bias, transparency, and lifecycle impacts rather than treating AI as generic IT.
EU AI ActRegulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)
The EU AI Act is a binding EU regulation establishing harmonised rules for the development, placing on the market, and use of AI systems across the European Union. It applies a risk-based approach: it bans certain 'unacceptable risk' AI practices, imposes detailed obligations on 'high-risk' AI systems, sets lighter transparency duties on limited-risk systems, and adds separate obligations for providers of general-purpose AI (GPAI) models. It applies to providers and deployers of AI systems placed on the EU market or whose AI output is used within the EU, regardless of where the provider is established.
IIA AI Auditing FrameworkThe IIA's Artificial Intelligence Auditing Framework
The IIA's AI Auditing Framework gives internal auditors principles-based guidance for assessing an organization's AI governance, risk management, and controls. It covers AI risk from strategy and governance through model development, deployment, and monitoring, including generative AI and large language models. It is intended for internal audit functions, chief audit executives, and audit committees performing assurance or advisory engagements on AI use, and it is explicitly structured around the IIA's Three Lines Model.
Three Lines ModelThe IIA's Three Lines Model
The IIA's Three Lines Model is a governance and risk-management model that assigns distinct roles to a governing body, management (split into first-line and second-line roles), and an independent internal audit function, the third line. Internal audit practitioners and the IIA apply this same structure to AI governance: first-line roles build, deploy, and operate AI systems and own the resulting risk; second-line roles provide AI-specific risk expertise, monitoring, and challenge; and internal audit provides independent assurance that AI risk is being governed and managed effectively. It is a principles-based model meant to be adapted to an organization's structure rather than a prescriptive control checklist.
Audit methodology guides
In-demand assessment categories
The categories buyers search for most, each a buyer checklist rather than a vendor ranking.
Retain with confidence
Need a consultant now?
Submit a procurement-safe scope and the service category you need. We route it toward qualified AI governance, model risk, and AI compliance consultants, usually within one business day. Procurement support, not a compliance guarantee.
Scope the need
Use the maturity model hub and guides to define what you need assessed and what to verify.
Request consultants
Send a procurement-safe sourcing request. We match it to the right category and route it.
Vet and retain
Use the RFP questions and red-flag list to compare candidates and verify credentials directly.
Vendor sourcing guides
Consultant and vendor sourcing categories
AI governance consultants, AI compliance consultants, and LLM security testing firms.
LLM Security & Red-Team Testing
Adversarial testing for prompt injection, jailbreaking, and model manipulation, before an attacker finds the gap first.
AI Governance Consultants
Building an AI governance program from ad hoc to managed, with outside expertise instead of trial and error.
AI Compliance Consultants
Mapping your program to a specific regulation or certifiable standard, not a generic governance overview.
Sourced reference
Notable AI governance vendors
Frequently asked questions
What is Model Governance Index?
A procurement-grade reference for AI governance and model oversight. It organizes named frameworks (NIST AI RMF, ISO/IEC 42001, IIA's AI Auditing Framework) into an assessment hub, explains what to verify before you retain an AI governance or compliance consultant, and pairs each guide with a sourced reference to notable real vendors in the space.
Is this a compliance guarantee or legal advice?
No. Model Governance Index is procurement support and buyer education only. It does not provide a compliance guarantee, does not audit your systems, and does not provide legal advice. Framework citations are informational context, never a claim that this index or a listed vendor satisfies a regulator.
How do I source a consultant here?
Use the sourcing request form to submit a procurement-safe scope and the service category you need. We route it toward qualified AI governance, model risk, and AI compliance consultants. Keep confidential model architecture or training data out of the request.
Does it cost anything?
The guides, glossary, frameworks reference, and vendor reference are free to use. Featured and Verified placements are clearly labeled and never change the editorial content or ordering.
AI governance sourcing brief
Occasional emails when we publish a new guide, framework update, or glossary update. No spam, unsubscribe anytime.
Single opt-in. We store only your email to send these updates. See ourprivacy notice. This is procurement information, not a compliance guarantee or legal advice.