Good AI Governance Starts with Understanding Your Organization—Not Choosing a Framework
Before adopting an AI governance framework, organizations should first understand their business objectives, AI use cases, risks, and governance needs.
When organizations begin discussing AI governance, one of the first questions is often:
Which AI governance framework should we adopt?
NIST AI RMF?
ISO/IEC 42001?
The EU AI Act?
Or another industry framework?
These are important references. But the question may come too early.
Before selecting a framework, organizations should first understand their own operating context.
What business objectives is AI expected to support?
Which AI systems and use cases are already being developed, procured, or used?
What decisions can those systems influence?
What risks could materially affect the organization, its customers, employees, or other stakeholders?
Who owns those risks?
And what level of oversight is proportionate to the potential impact?
These questions matter because AI governance should not begin as a documentation exercise.
It should begin as an organizational understanding exercise.
From my experience across legal, compliance, and operations roles, effective governance rarely starts with selecting a framework and then asking the organization to fit within it. It should starts by understanding how the organization actually works—its objectives, decision-making processes, risk appetite, accountability structures, operational realities, and governance maturity.
Only then can an organization determine which frameworks, standards, regulatory requirements, and internal controls are relevant.
A financial institution, a healthcare provider, a technology company, and a public-sector organization may all use AI. But their risks, responsibilities, stakeholders, and governance needs will not be the same.
Even within the same organization, a low-risk productivity tool should not necessarily be governed in the same way as an AI system that influences employment, credit, healthcare, safety, or legal rights.
This is why good AI governance should be risk-based, context-specific, and proportionate.
Frameworks can provide structure, common language, and useful guidance.
But they cannot decide an organization’s priorities, assign accountability, define risk appetite, or determine which AI decisions require executive oversight.
Those responsibilities remain with the organization.
The practical starting point is therefore not:
Which framework should we choose?
It is:
What are we trying to govern, why does it matter, and who should be accountable?
Frameworks provide structure.
Understanding the organization provides direction.
Good AI governance requires both—but in that order.