Back to the library
Whitepaper
AI Governance

AI governance: from policy to operating control

Where most AI policies fail in practice and the seven control patterns (model inventory, evals, human-in-the-loop, incident response) that actually hold up under audit.

Apr 2026 18 min read By Dr. Nadia Al-Hashimi
Overview

Where most AI policies fail in practice and the seven control patterns (model inventory, evals, human-in-the-loop, incident response) that actually hold up under audit.

Written by Dr. Nadia Al-Hashimi and pressure-tested on live ai governance engagements before publication, this whitepaper is designed to move a programme forward the same week you open it.

Every section is annotated with the decision it should unblock, the owner it should sit with, and the evidence it should leave behind — so the artefact still holds up under audit twelve months later.

What you'll take away
  • Field-tested against real Stage 1 and Stage 2 audit findings
  • Mapped to the controls and cadences the AI Governance faculty deploy in cohort work
  • Editable, credit-line optional — use it inside your organisation without attribution
  • Includes evidence pointers, owner fields and a first-90-days cadence
Who this is for
  • Heads of GRC, CISOs, DPOs and internal audit leads
  • Lead Implementers and Lead Auditors preparing for cert cycles
  • Consulting teams standing up client programmes
See it live

Book a demo with the faculty who wrote this.

Walk through the whitepaper with a MAST practitioner — mapped against your controls, your evidence and your next audit window.