A build guide for boards and executives

AI governance framework: how to build one your board can defend.

Every board is now being asked the same question: how exactly is AI governed here? An AI governance framework is the answer, ownership, policy, controls and reporting that operate together. This guide breaks the framework into eight buildable components, and shows how StackUp baselines each one against NIST, ISO/IEC 42001 and the EU AI Act in hours.

Independent · no upsell · money-back guarantee

Framework build snapshot · Sample Co6 gaps found

Value of completing the framework

$280,000

  • HighNo accountable owner for AI risk$85K
  • HighStaff using unapproved AI tools$75K
  • MediumNo escalation path for AI incidents$60K
  • Quick winMap controls to NIST AI RMF$60K
Each component scored, priced and assigned
8
framework components, from ownership to incident response
3
standards mapped: NIST AI RMF, ISO/IEC 42001, EU AI Act
<1 hr
of leadership input to baseline your current framework
48 hrs
to a documented, board-ready framework baseline

Trusted by former CTOs of

Toyota logo
HSBC logo
Lendlease logo
Merivale logo
Seek logo
Dubai Holding logo
ASX logo
BOQ logo

The blueprint

The eight components of a working AI governance framework

A framework is not a policy PDF. It is a set of components that operate together, and that you can evidence on demand when a regulator, insurer or acquirer asks. Once built, track how it strengthens over time with an AI maturity assessment.

Leadership team mapping the components of an AI governance framework on a whiteboard

Components 1–4: make someone accountable

The foundation is ownership. A named owner for AI risk, an acceptable-use policy staff have actually read, data protection rules for what AI tools may touch, and a register of every AI system and vendor in use. Most organisations discover in their first StackUp assessment that at least two of these do not exist yet.

Named AI ownerAcceptable-use policyData protection rulesAI system register

Components 5–8: make it observable

The second half keeps the framework alive: a risk assessment cadence, testing that controls actually work, reporting the board can read, and an incident response path for when AI gets it wrong. Before you design these, run an AI readiness assessment to see which components already exist in some form.

Risk cadenceControl testingBoard reportingAI incident response

How it works

From blank page to working framework in three steps

01

Baseline

Establish what exists today before writing anything.

  • Structured assessment of current AI use and controls
  • AI calling agents surface how staff really use AI day to day
  • Under an hour of leadership input, no integrations
02

Map

See how your framework compares to the standards.

  • Gap analysis against NIST AI RMF, ISO/IEC 42001 and the EU AI Act
  • A dollar figure on every missing framework component
  • A board-ready report you can table as evidence
03

Operate

A framework only counts if it keeps running.

  • Prioritised action plan with owners and timelines
  • AI CTO guidance as design questions come up
  • Reassessment each quarter as your AI use grows

Why StackUp

Build the framework without hiring a framework consultant

The same components a top-tier advisory would scope, grounded in 30 years of CTO experience, delivered as a platform.

A consultant-built framework

  • $40,000+ to scope and draft the framework
  • Six weeks of workshops before a first draft
  • Generic templates retrofitted to your business
  • A binder that starts ageing the day it lands

StackUp

  • A measured baseline of your real AI use first
  • Framework gaps priced in dollars, not adjectives
  • Controls and templates mapped to recognised standards
  • A living platform that evidences the framework quarterly

Reviews

What leaders say about governing with StackUp

Executives and technology leaders on what an independent, evidence-first approach changed for them.

StackUp gave us immediate clarity. It's like having a 20-year CTO on call 24×7, without the $500K price tag.
Geoff Kruyt, CEO
Geoff Kruyt
CEO
Takes the subjectivity and emotion out of assessing technology capability and drives focus on the right areas for improvement.
Ben Tabell, CIO, Technically Savvy
Ben Tabell
CIO, Technically Savvy
StackUp is your secret weapon for staying ahead.
Steven Fulop, Director, xceltium
Steven Fulop
Director, xceltium

FAQs

AI Governance Framework questions, answered

What is an AI governance framework?

An AI governance framework is the documented structure an organisation uses to control how artificial intelligence is adopted and operated: who owns AI risk, what policies apply, which controls are in place, and how compliance is monitored and reported. It turns AI governance from a set of good intentions into something you can evidence to a board, regulator or acquirer.

What should an AI governance framework include?

Eight components cover the ground: a named accountable owner, an acceptable-use policy, data protection rules for AI tools, a register of AI systems and vendors, a risk assessment cadence, control testing, board-level reporting, and an incident response path for AI failures. If any one of these is missing, the framework has a gap another party will eventually find.

Which standards should our framework align to?

Three reference points dominate: the NIST AI Risk Management Framework, ISO/IEC 42001 and the EU AI Act. StackUp benchmarks your AI maturity and governance against all three, alongside broader technology best practice, so one assessment shows how your framework measures up where it will actually be judged.

How long does it take to build an AI governance framework?

The baseline is fast: StackUp needs under an hour of leadership input, and organisations typically have a documented, board-ready view of their current state within 48 hours. Building out the missing components is then a prioritised programme over one to two quarters, far faster when you start from evidence instead of a blank page.

Do we need a framework if we barely use AI?

Almost certainly, because your staff are already using AI even if the organisation has not sanctioned it. Shadow AI handling customer or commercial data is one of the most common high-severity findings in StackUp assessments. A right-sized framework is how you enable AI use safely rather than pretending it is not happening.

Start your framework from a measured baseline

Book a demo to unlock your free 30-day trial. 30 minutes with the founder. Money-back guarantee.

Book a demo