STEADY · Pane 05

Governance, Risk & Compliance

Who owns AI risk, and can we evidence responsible use?

Insight

  • AI and agent register (purpose, owner, risk tier, grounding data, EU exposure)
  • Control gaps versus policy

Action

  • Stand up a register, DPIA triggers, and a literacy programme
  • Map to ISO 42001 AIMS / NIST RMF; publish a minimum viable AI policy

Owner

GRC / DPO / Risk

Illustrative signals

  • % systems in register
  • Open high risks
  • Literacy completion
  • DPIAs done

Standards bridges

  • ISO/IEC 42001
  • NIST AI RMF
  • UK GDPR
  • EU AI Act Art. 4 literacy and deployer duties

Pane 05 sits in the STEADY arc.

Use this page as the canonical definition for Insight and Action. Signals are illustrative.