
AI Governance in Practice: Build responsible, audit-ready programs with ISO/IEC 42001, NIST AI RMF, and lifecycle controls
Author(s): Hemang Doshi (Author)
- Publisher Finelybook 出版社: Packt Publishing
- Publication Date 出版日期: September 30, 2026
- Edition 版本: 1st
- Language 语言: English
- Print length 页数: 250 pages
- ISBN-10: 1807300811
- ISBN-13: 9781807300814
Book Description
Build an audit-ready AI governance program with practical assessments, lifecycle controls, and guidance aligned with ISO/IEC 42001, NIST AI RMF, OECD AI Principles, and the EU AI Act
Key Features
- Apply ISO/IEC 42001, NIST AI RMF, OECD AI Principles, and the EU AI Act in practice
- Conduct AI impact and risk assessments using structured methods and practical templates
- Build audit-ready lifecycle controls, documentation, monitoring, and accountability
- Purchase of the print or Kindle book includes a free PDF eBook
Book Description
Turn AI governance principles, standards, and regulatory requirements into a practical program that operates across the AI lifecycle.
This book shows you how to build responsible AI governance around ISO/IEC 42001, the NIST AI RMF, OECD AI Principles, the EU AI Act, and other frameworks. You’ll conduct AI risk and impact assessments, define governance roles and decision rights, establish policies and lifecycle controls, and create documentation for transparency, accountability, and AI compliance.
You’ll apply governance through development, deployment, monitoring, and retirement; address AI security and safety; prepare for AI incidents; and use AI audits and monitoring findings to strengthen controls. Practical scenarios, templates, checklists, and step-by-step guidance turn frameworks into repeatable organizational practices.
Written by Hemang Doshi, who has more than 20 years of experience in system audit, IT risk and compliance, internal audit, risk management, information security audit, third-party risk management, and operational risk management, this book connects governance frameworks with practical implementation. By the end, you’ll be able to build an accountable, audit-ready AI governance program and integrate AI risk management with existing compliance, security, privacy, and risk processes.
What you will learn
- Explain responsible AI principles and governance lifecycle risks
- Compare ISO/IEC 42001, NIST AI RMF, OECD, and the EU AI Act
- Conduct structured AI impact and risk assessments
- Define accountable governance roles and decision rights
- Create policies and lifecycle controls for responsible AI
- Document AI systems for transparency and auditability
- Prepare for AI incidents with structured response processes
- Perform AI audits and improve governance from findings
Who this book is for
AI governance, compliance, and risk management professionals responsible for overseeing AI systems, evaluating AI risks, or implementing responsible AI practices, along with data scientists, ML engineers, internal auditors, privacy leaders, and technology executives. A foundational understanding of AI concepts, basic IT risk principles, and organizational policies or governance frameworks is recommended. This book also provides a strong foundation for AI GRC certifications such as AIGP, AAIA, AAIR, AAISM, AIMS, and others.
Table of Contents
- Understanding Artificial Intelligence
- Introduction to AI Governance
- Principles of Responsible AI
- Overview of Global AI Governance Frameworks – ISO/IEC 42001 and EU AI Act
- AI Governance Framework – ISO/IEC 42001
- AI Governance Framework – NIST AI RMF
- AI Governance Framework – OECD AI Principles
- European Union AI Act
- AI Impact Assessment
- AI Risk Assessment
- Comparative Analysis of AI Frameworks – ISO/IEC 42001 and EU AI Act
- AI Governance Structure
- AI Governance Documents
- AI Lifecycle Governance
- Security of AI Systems
- AI Incident Management
- AI System Audits
Editorial Reviews
Editorial Reviews
About the Author
Hemang Doshi has more than 15 years of experience in the field of system audit, IT risk and compliance, internal audit, risk management, information security audit, third-party risk management, and operational risk management. He has authored several books for certifications such as CISA, CRISC, CISM, DISA, CEH, and enterprise risk management. His books and lectures are sold in more than 175 countries and in more than 35 languages.
finelybook
