AI Governance, Compliance & Regulation

AI Governance in action: Regulations to real controls

November 3, 2025

Understanding AI regulations is only half the challenge. The real test comes when organizations translate those high-level requirements into practical, measurable governance controls that teams can actually implement.

This is where AI governance moves from policy to practice. Below, we explore how each type of control connects directly to the AI Act’s legal obligations, and what it looks like when governance is truly working across your teams.

Governance Operations Controls

Strong AI governance starts with the right organizational controls. Before any model is built, teams need clear frameworks defining accountability, approval processes, and literacy requirements. Article 4 of the AI Act even makes AI literacy a legal expectation at the organizational level.

Governance OperationsEvidence
GO1 - Organization policiesOrganization-wide AI policies, standard procedures & workflows: created, maintained, and stored in a centralized location.
GO2 - Roles & responsibilitiesClear roles, responsibilities, and associated competences for AI governance must be defined, documented, and maintained.
GO3 - AI LiteracyTraining and upskilling of employees to understand the dynamics, potential, and risk of AI in a so-called AI literacy program/training.

You’ll know this is working when:

Risk Management Controls

Risk management controls translate the AI Act’s risk-based approach into operational processes.

These controls must systematically identify, assess, and mitigate risks throughout the AI lifecycle. The controls aren’t just compliance boxes to check, they’re the operational backbone of your AI governance. Each control addresses a specific way AI systems can fail or cause harm.

Risk ManagementEvidence
RM1 - Model registryA complete and up-to-date overview of AI use cases or systems.
RM2 - Risk AssessmentA risk assessment per use case, documented, and maintained proactively to identify, assess, and mitigate risks, including impacts on fundamental rights, safety, and societal welfare, both technical risks (bias, accuracy) and operational risks (misuse, errors).
RM3 - Risk classification
A risk classification for each use case, based on its intended use and potential impact. This classification drives all subsequent compliance requirements.
RM4 - Risk management systemA risk management system to periodically evaluate and update risk assessments (RM2), including a process for risk monitoring, review, and mitigation.

You’ll know this is working when:

Data Governance Controls

Poor data governance remains one of the top causes of AI failures and compliance breaches. Article 10 of the AI Act sets strict requirements around data quality, representativeness, and documentation of datasets. These controls help you avoid becoming the next cautionary tale.

Data GovernanceEvidence
DG1 - Process A documented process & templates for data governance:
  • Data collection
  • Source & dataset characteristics
  • Copyright and ownership of data
  • (pre) Processing
  • Quality assessments
  • Lineage / tracking
  • Known limitations
DG2 - Documentation Documentation for each use case based on DG1.
This can be done in data cards or filled in templates.
DG3 - Bias Detection Systematic (unwanted) bias testing across different demographic groups, geographic regions, and use case scenarios. Implement mitigation strategies including data augmentation, algorithmic fairness techniques, and ongoing monitoring.

You’ll know this is working when:

Transparency Controls

Transparency controls ensure stakeholders understand AI system capabilities, limitations, and decision-making processes. These controls are essential for building trust and enabling effective human oversight.

TransparencyEvidence
TP1 - Capabilities and Limitations Information about the capabilities and limitations of models in the use case, documented to assist relevant stakeholders’ decision-making. This can be done in Documentation, Templates, or Model Cards.
TP2 - Explainability Decisions and outputs of models in the use case must be explainable and interpretable for relevant stakeholders. This might include SHAP values, LIME explanations, natural language descriptions, or other methods.
TP3 - Instructions User instruction documents and training materials are accessible to relevant stakeholders, including setup instructions, operating procedures, troubleshooting guides, and safety warnings. Tailor instruction format and detail level to different user types.
TP4 - Impact Assessment The potential impacts of the use case on individuals, groups, and society must be assessed, documented, and reviewed.

You’ll know this is working when:

Human Oversight Controls

Article 14 mandates that qualified humans must always remain in meaningful control of AI systems. This is essential for high-risk use cases where automated decisions can affect individuals or society.

Human OversightEvidence
HO1 - Operational Oversight Natural persons must be able to effectively oversee (monitor) the use case while in use to minimize risks to health, safety, or fundamental rights. Appropriate monitoring is available.
HO2 - Intervention Individuals responsible for human oversight must be able to intervene in the operations or override the outcomes of the models in the use case (feedback loop).

Individuals affected by AI decisions must have clear mechanisms to challenge decisions and seek redress. This includes accessible complaint procedures, human review processes, and meaningful remedies when AI systems cause harm.
HO3 - Competence Individuals responsible for human oversight must be equipped to effectively and reasonably perform their duties by actively giving feedback or overruling decisions.

You’ll know this is working when:

Operations Controls

Operational controls ensure AI systems maintain performance, security, and auditability throughout their operational lifecycle.

OperationsEvidence
OP1 - Event Logging Events have to be automatically recorded over the duration of the use case lifecycle:
  • System events
  • User interactions
  • Predictions & outcomes
Logs are tamper-proof and retained according to regulatory requirements.
OP2 - Accuracy & Performance Use cases have appropriate metrics defined, with continuous monitoring, and set alert thresholds for performance degradation. Establish retraining procedures when accuracy falls below acceptable levels.
OP3 - Robustness The use case must be resilient to errors, faults, model/data drift, and inconsistencies arising from within the system or its environment, especially during interactions with people or other systems. The system is stress tested on edge cases.
OP4 - Security The use case must be protected against unauthorized third-party attempts to exploit vulnerabilities that could alter its use or performance. Address AI-specific security risks like adversarial attacks and data poisoning.

You’ll know this is working when:

Lifecycle Management Controls

AI systems evolve. Lifecycle controls ensure every update, retraining, and decommissioning step follows a clear governance process.

Lifecycle ManagementEvidence
LC1 - Version Control Version control for all models in the use case must be maintained, including records of changes. Retirement of AI systems should be part of the lifecycle, clearly offboarding systems.
LC2 - Sign-off All model versions must be reviewed and approved by relevant stakeholders before deployment or updates:
  • Technical review
  • Business approval
  • Compliance verification
LC3 - Technical Documentation Essential technical components for the ongoing operation of the use case must be defined, documented, and provided to the relevant stakeholders in an appropriate and accessible format:
  • System architecture
  • API specifications
  • Deployment procedures
  • Maintenance requirements

You’ll know this is working when:

Conformity & CE marking

If you’re developing or commercializing high-risk AI systems, you’ll need to complete a formal conformity assessment to obtain a CE marking before entering the EU market. This confirms your system complies with all AI Act requirements and can be listed in the EU database.
 
For AI deployers, this step doesn’t apply directly, but you’re still responsible for ensuring any third-party AI system you use is CE-marked and compliant.

ControlEvidence
CE1 - Conformity assessment Conduct a conformity assessment, checking if all controls together conform to the AI Act, resulting in an EU AI conformity assessment and CE marking.
CE2 - EU Database In case you start to market a high-risk AI system, it’s crucial to register the system in the database provided by the EU.

You’ll know this is working when:

Learn more: Get the AI Governance & Control Framework Whitepaper

AI Governance & Control Framework Whitepaper

This discussion is just one section of our broader framework. To explore the full picture download the our latest whitepaper. It covers all essential topics across the AI lifecycle and offers a clear roadmap for compliance and risk management.

Explore how to:

More news

Whitepaper: AI Governance & Control Framework
August 26, 2026
Introducing the EU AI Act Hub: a reference for a moving target
July 21, 2026
AI agent governance is no longer optional: Why accountability matters
June 22, 2026

Thank you for subscribing!

You will receive a confirmation shortly.

Build audit-ready AI governance from day one