Client Trust Center Contract vehicles Contact Traverge

Home / Practices / AI Governance

The AI obligations are already inside your boundary.

NIST AI RMF, ISO/IEC 42001, the EU AI Act, CDAO Responsible AI and the COSAiS overlays ask overlapping questions in different vocabularies. We answer them once, against the control baseline you already hold.

Three questions most organizations cannot answer about their own AI

Which models are in production. What data trains them. Who approved the deployment. Until those have answers, an AI policy is a document nobody can enforce, and an AI risk register is a guess.

The frameworks converging on this problem ask overlapping questions in different vocabularies. NIST AI RMF wants governance, mapping, measurement and management. ISO/IEC 42001 wants a management system with owners and review cycles. The EU AI Act wants risk classification by use case. CDAO Responsible AI wants testing and operational governance for defense components. AIUC-1 wants evidence an auditor can inspect. Answer the underlying questions once and most of the mapping falls out.

AI obligations are landing inside boundaries you already hold

This is the part organizations miss. An AI capability added to an authorized system is not a greenfield governance problem, it is a change inside an existing boundary. NIST COSAiS layers AI-specific security and testing requirements onto the SP 800-53 control families already in your baseline. OMB M-25-21 creates obligations for agency use cases. A model added to a system under a DoD Impact Level inherits that system's accreditation constraints.

Governance that ignores the compliance program you already run produces a second set of artifacts nobody reconciles. We build the AI program so it lands inside the one you have.

Frameworks

Four frameworks, depending on who is asking.

Which one governs you is a function of your market and your customers, not of what a consultancy prefers to sell. Most organizations need more than one, and the overlap is larger than it looks.

NIST AI RMF

The common foundation

  • All four functions implemented: Govern, Map, Measure and Manage
  • AI inventory and risk classification across models, data and third-party dependencies
  • Outcomes mapped to the SP 800-53 controls already in your baseline
  • Works whether or not you hold a federal authorization
Scope AI RMF

ISO/IEC 42001

Commercial and international

  • An AI management system with named owners, risk treatments and review cycles
  • Built toward certification rather than toward a binder
  • Aligned with ISO 27001 where you already hold it
  • EU AI Act risk tiering for organizations with European exposure
Scope 42001

Federal AI mandates

Agencies and their suppliers

  • OMB M-25-21 obligations traced to specific agency use cases
  • COSAiS overlay applicability against your current control baseline
  • Executive orders and agency directives reconciled into one program
  • CDAO Responsible AI Framework for defense components
Scope federal AI

AIUC-1 readiness

Agentic systems facing audit

  • Gap assessment against the control set an auditor will actually test
  • Agent monitoring and accountability structures built before the audit, not during
  • Evidence assembled as the system runs rather than reconstructed afterward
  • Readiness work only: we prepare you for the audit, we do not conduct it
Scope AIUC-1

Overlap

One body of evidence, several frameworks.

The frameworks disagree on vocabulary far more than they disagree on substance. Evidence gathered once can satisfy several of them, if it is gathered with that in mind.

What you produceWhat it satisfies
AI inventoryAI RMF Map, ISO/IEC 42001 scope definition, EU AI Act risk classification, and the system component list your assessor already expects.
Model risk assessmentAI RMF Measure, CDAO Responsible AI testing requirements, and the risk assessment control family in your existing baseline.
Approval and oversight recordsAI RMF Govern, ISO/IEC 42001 management review, AIUC-1 accountability evidence, and change control inside your authorization boundary.
Adversarial test resultsCOSAiS testing expectations, AIUC-1 safety and security evidence, and the assessment artifacts required at your impact level.
Supply chain recordsThird-party model and training data provenance for AI RMF, ISO/IEC 42001 supplier controls, and SP 800-161 supply chain requirements.

Next step

Tell us what you hold today and what your agency customer expects next.

It starts with a gap analysis at no cost, and a scoped proposal follows.

Request a call Capability statement