Reference, not a compliance guarantee

AI governance frameworks

Model Governance Index is organized around named, real frameworks rather than a generic explainer. Each page below covers what the framework actually requires, who issues it, and its real adoption status, sourced directly from the issuing body. Framework mentions are informational context only, never a claim that this index or any listed vendor satisfies the framework.

See which vendors publicly state alignment to these frameworks: vendor alignment matrix →

NIST AI RMF

Artificial Intelligence Risk Management Framework (AI RMF 1.0)

The NIST AI RMF provides voluntary guidance to help organizations that design, develop, deploy, or use AI systems manage risks to individuals, organizations, and society. It is intended for use across sectors, use cases, and organization sizes, and is not tied to any specific technology. The framework organizes AI risk management around four functions, Govern, Map, Measure, and Manage, oriented toward seven characteristics of trustworthy AI: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed.

Issued by National Institute of Standards and Technology (NIST), U.S. Department of Commerce

ISO 42001

ISO/IEC 42001:2023 - Information technology - Artificial intelligence - Management system

ISO/IEC 42001:2023 specifies requirements, with guidance, for establishing, implementing, maintaining, and continually improving an AI management system (AIMS) within an organization. It is the first international management-system standard written specifically for AI and is designed for any organization, of any size or sector, that provides or uses AI-based products or services. It addresses AI-specific concerns such as algorithmic bias, transparency, and lifecycle impacts rather than treating AI as generic IT.

Issued by International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC), developed by joint technical committee ISO/IEC JTC 1/SC 42

EU AI Act

Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)

The EU AI Act is a binding EU regulation establishing harmonised rules for the development, placing on the market, and use of AI systems across the European Union. It applies a risk-based approach: it bans certain 'unacceptable risk' AI practices, imposes detailed obligations on 'high-risk' AI systems, sets lighter transparency duties on limited-risk systems, and adds separate obligations for providers of general-purpose AI (GPAI) models. It applies to providers and deployers of AI systems placed on the EU market or whose AI output is used within the EU, regardless of where the provider is established.

Issued by European Union (European Parliament and Council of the European Union)

IIA AI Auditing Framework

The IIA's Artificial Intelligence Auditing Framework

The IIA's AI Auditing Framework gives internal auditors principles-based guidance for assessing an organization's AI governance, risk management, and controls. It covers AI risk from strategy and governance through model development, deployment, and monitoring, including generative AI and large language models. It is intended for internal audit functions, chief audit executives, and audit committees performing assurance or advisory engagements on AI use, and it is explicitly structured around the IIA's Three Lines Model.

Issued by The Institute of Internal Auditors (IIA)

Three Lines Model

The IIA's Three Lines Model

The IIA's Three Lines Model is a governance and risk-management model that assigns distinct roles to a governing body, management (split into first-line and second-line roles), and an independent internal audit function, the third line. Internal audit practitioners and the IIA apply this same structure to AI governance: first-line roles build, deploy, and operate AI systems and own the resulting risk; second-line roles provide AI-specific risk expertise, monitoring, and challenge; and internal audit provides independent assurance that AI risk is being governed and managed effectively. It is a principles-based model meant to be adapted to an organization's structure rather than a prescriptive control checklist.

Issued by The Institute of Internal Auditors (IIA)