<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Model Governance Index</title><description>Model Governance Index is a procurement-grade reference for AI governance and model oversight. Understand where your program stands against named frameworks (NIST AI RMF, ISO/IEC 42001, IIA’s AI Auditing Framework), learn exactly what to verify before you retain an AI governance or compliance consultant, and explore a sourced reference to the frameworks and real firms active in the space. Procurement support, not a compliance guarantee.</description><link>https://modelgovernanceindex.com/</link><language>en-us</language><item><title>Artificial Intelligence Risk Management Framework (AI RMF 1.0)</title><link>https://modelgovernanceindex.com/frameworks/nist-ai-rmf/</link><guid isPermaLink="true">https://modelgovernanceindex.com/frameworks/nist-ai-rmf/</guid><description>The NIST AI RMF provides voluntary guidance to help organizations that design, develop, deploy, or use AI systems manage risks to individuals, organizations, and society. It is intended for use across sectors, use cases, and organization sizes, and is not tied to any specific technology. The framework organizes AI risk management around four functions, Govern, Map, Measure, and Manage, oriented toward seven characteristics of trustworthy AI: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed.</description></item><item><title>ISO/IEC 42001:2023 - Information technology - Artificial intelligence - Management system</title><link>https://modelgovernanceindex.com/frameworks/iso-iec-42001/</link><guid isPermaLink="true">https://modelgovernanceindex.com/frameworks/iso-iec-42001/</guid><description>ISO/IEC 42001:2023 specifies requirements, with guidance, for establishing, implementing, maintaining, and continually improving an AI management system (AIMS) within an organization. It is the first international management-system standard written specifically for AI and is designed for any organization, of any size or sector, that provides or uses AI-based products or services. It addresses AI-specific concerns such as algorithmic bias, transparency, and lifecycle impacts rather than treating AI as generic IT.</description></item><item><title>Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)</title><link>https://modelgovernanceindex.com/frameworks/eu-ai-act/</link><guid isPermaLink="true">https://modelgovernanceindex.com/frameworks/eu-ai-act/</guid><description>The EU AI Act is a binding EU regulation establishing harmonised rules for the development, placing on the market, and use of AI systems across the European Union. It applies a risk-based approach: it bans certain &apos;unacceptable risk&apos; AI practices, imposes detailed obligations on &apos;high-risk&apos; AI systems, sets lighter transparency duties on limited-risk systems, and adds separate obligations for providers of general-purpose AI (GPAI) models. It applies to providers and deployers of AI systems placed on the EU market or whose AI output is used within the EU, regardless of where the provider is established.</description></item><item><title>The IIA&apos;s Artificial Intelligence Auditing Framework</title><link>https://modelgovernanceindex.com/frameworks/iia-ai-auditing-framework/</link><guid isPermaLink="true">https://modelgovernanceindex.com/frameworks/iia-ai-auditing-framework/</guid><description>The IIA&apos;s AI Auditing Framework gives internal auditors principles-based guidance for assessing an organization&apos;s AI governance, risk management, and controls. It covers AI risk from strategy and governance through model development, deployment, and monitoring, including generative AI and large language models. It is intended for internal audit functions, chief audit executives, and audit committees performing assurance or advisory engagements on AI use, and it is explicitly structured around the IIA&apos;s Three Lines Model.</description></item><item><title>The IIA&apos;s Three Lines Model</title><link>https://modelgovernanceindex.com/frameworks/iia-three-lines-model-ai-governance/</link><guid isPermaLink="true">https://modelgovernanceindex.com/frameworks/iia-three-lines-model-ai-governance/</guid><description>The IIA&apos;s Three Lines Model is a governance and risk-management model that assigns distinct roles to a governing body, management (split into first-line and second-line roles), and an independent internal audit function, the third line. Internal audit practitioners and the IIA apply this same structure to AI governance: first-line roles build, deploy, and operate AI systems and own the resulting risk; second-line roles provide AI-specific risk expertise, monitoring, and challenge; and internal audit provides independent assurance that AI risk is being governed and managed effectively. It is a principles-based model meant to be adapted to an organization&apos;s structure rather than a prescriptive control checklist.</description></item><item><title>AI Governance Audit — sourcing an AI governance consultant</title><link>https://modelgovernanceindex.com/guides/ai-governance-audit/</link><guid isPermaLink="true">https://modelgovernanceindex.com/guides/ai-governance-audit/</guid><description>What an independent AI governance audit actually covers, how it differs from self-assessment, the IIA and NIST frameworks it should cite, and RFP questions for hiring an auditor.</description></item><item><title>LLM Security &amp; Red-Team Testing — sourcing an AI governance consultant</title><link>https://modelgovernanceindex.com/guides/llm-security-testing/</link><guid isPermaLink="true">https://modelgovernanceindex.com/guides/llm-security-testing/</guid><description>How to vet LLM security and AI red-team testing vendors: what prompt-injection and adversarial testing actually covers, what to verify, and RFP questions before you sign.</description></item><item><title>AI Governance Consultants — sourcing an AI governance consultant</title><link>https://modelgovernanceindex.com/guides/ai-governance-consultants/</link><guid isPermaLink="true">https://modelgovernanceindex.com/guides/ai-governance-consultants/</guid><description>How to evaluate an AI governance consultant or firm: what a program-design engagement should cover, real firms active in the space, and RFP questions before you retain one.</description></item><item><title>AI Compliance Consultants — sourcing an AI governance consultant</title><link>https://modelgovernanceindex.com/guides/ai-compliance-consultants/</link><guid isPermaLink="true">https://modelgovernanceindex.com/guides/ai-compliance-consultants/</guid><description>How to evaluate an AI compliance consultant or platform for a specific regulatory requirement (EU AI Act, ISO 42001), real vendors active in the space, and what to verify before you retain one.</description></item></channel></rss>