PTENES
MODULE 3.4

🏛️ Governance and risk: NIST AI RMF, ISO 42001, EU AI Act

Governance isn’t a brake—it’s what makes it possible to scale AI with control and confidence. Knowing the three main frameworks makes the consultant a trusted resource for clients who need to establish their approach to AI.

6
Topics
~50
Minutes
Audit
Level
Govern.
Type

Three international frameworks define the state of the art in AI governance: the NIST AI RMF (risk management), the ISO/IEC 42001 (management system) and the EU AI Act (risk-based regulation). Knowing them isn’t bureaucracy—it’s what enables a consultant to recommend proportionate, defensible structures.

NIST AI RMF GOVERN · MAP MEASURE · MANAGE AI risk management continuous cycle + ISO/IEC 42001 AIMS — Management System for AI Management PDCA cycle certifiable + EU AI Act Unacceptable / High / Limited / Minimum risk-based regulation extraterritorial Governance proportional to risk

The three frameworks complement one another — risk management + management system + regulatory classification.

1

🗂️ NIST AI RMF — the 4 functions

O AI Risk Management Framework from NIST (National Institute of Standards and Technology) is the most widely adopted AI risk management framework in the U.S. and a global reference. It organizes management into 4 functions that form a continuous cycle.

GOV

GOVERN — Culture and policies

Establishes an organizational culture of AI accountability: policies, roles and responsibilities, team training, and accountability. This is the function that defines “how we behave around AI.”

MAP

MAP — Identify risks by context

For each AI system, identify its usage context, affected parties, and relevant risks. The same model can pose very different risks depending on how and where it is used.

MEA

MEASURE — Assess impacts

Quantify and assess the identified risks — likelihood, impact severity, affected groups. This turns the risk list into data that informs decisions.

MAN

MANAGE — Address and monitor

Implement controls for priority risks and monitor continuously—including detecting new risks that emerge with operations and over time.

💡 How to use NIST in practice

For SMEs, use NIST as a minimum checklist: "Do we have policies? Have we identified this system's risks? Have we measured the impact? Do we have controls?" You don't need to implement the full framework — just cover the critical points for the context.

2

🌐 ISO/IEC 42001 — the AI management system

Published in 2023, the ISO/IEC 42001 is the first international management system standard specifically for AI (AIMS — AI Management System). If you know ISO 9001 or 27001, the structure will be familiar: PDCA and compliance requirements.

🔄 The PDCA cycle applied to AI

Plan — Plan

Define the AIMS scope, identify stakeholders, analyze risks and opportunities, and establish AI management objectives.

Do — Do

Implement policies, controls, and processes. Document the organization’s AI development and usage practices.

Check — Check

Monitor, measure, and audit the AIMS. Check whether the controls are working and the objectives are being met.

Act — Take action

Take corrective action and continually improve the management system based on monitoring results.

📌 Who needs 42001

Organizations that develop or deploy AI at scale, serve clients with compliance requirements, or seek competitive differentiation through certification. For SMEs without these drivers, apply the principles without formal certification.

3

🇪🇺 EU AI Act — risk classification

O EU AI Act (in effect since 2024) is the world’s first comprehensive AI regulation. It classifies AI uses into 4 categories and defines obligations proportional to risk. Brazilian companies that handle data belonging to European citizens are subject to it.

PROHIBITED

Unacceptable risk — systems that violate fundamental rights. Examples: government social scoring, real-time biometric recognition in public spaces, subliminal manipulation.

HIGH

High risk — AI in critical infrastructure, healthcare, education, employment, credit, migration, and justice. Requires registration, transparency, human oversight, and conformity assessment.

LIMITED

Limited risk — chatbots, deepfakes. Requires transparency: users need to know they’re interacting with AI or consuming content generated by it.

MINIMUM

Minimal risk — spam filters, AI games, playlist recommendations. No specific obligations beyond general laws.

4

⚡ The 5 AI risks every consultant should know

Regardless of frameworks, every AI consultant needs to know the following by heart: 5 fundamental risks — because these are the ones that come up in real projects and that the client will need to decide how to handle.

⚖️ Bias

Models trained on historically biased data replicate and amplify discrimination. In credit, employment, or healthcare, this can be illegal as well as unfair.

🌀 Hallucination

LLMs generate incorrect outputs presented with confidence. In legal, medical, or financial contexts, an undetected hallucination can cause real harm.

🔐 Security

Prompt injection, data extraction through malicious prompts, or inadvertent submission of sensitive data to external APIs without appropriate contracts.

👤 Privacy

Personal data entered in prompts may be stored and used for training. Employee or customer context in third-party LLMs without a DPA poses LGPD risk.

🏢 Reputational risk

An AI incident — whether an offensive response, a discriminatory decision, or a data leak — can go viral before the company knows what happened. The company’s reputation pays the price for a lack of governance.

5

⚖️ Risk-proportionate governance

The most common mistake is proposing the same level of governance for every use of AI. An internal FAQ chatbot requires much less structure than a credit approval system. Proportionality is what makes governance viable and widely adopted.

📐 Governance by risk level

Low risk Acceptable use policy + human review of outputs + incident logging. Simple.
Medium risk Additionally: bias assessment before deployment + output monitoring + designated AI owner.
High risk Additionally: review committee + complete audit trail + EU AI Act/ISO 42001 compliance + mandatory human oversight for decisions.
Proportional

control ∝ risk

Feasible

SMEs can implement

Scalable

grows with AI usage

Adopted

the team follows because it makes sense

6

🚀 Governance as an enabler, not a brake

The narrative matters. A consultant who presents governance as “mandatory compliance” meets resistance. One who presents it as "which allows AI to scale without crises" finds allies in leadership.

✗ Without governance

  • ✗Ad hoc AI decisions — no audit trail
  • ✗An incident becomes a public crisis before a response can be made
  • ✗Scaling AI means scaling uncontrolled risks
  • ✗B2B clients reject vendors without an AI policy

✓ With proportional governance

  • ✓Clear policies speed up operational decisions
  • ✓Monitoring detects problems before they become crises
  • ✓Scale AI with confidence — documented foundation
  • ✓An AI policy becomes a competitive advantage in B2B

💡 How to sell governance to leadership

Don’t talk about compliance. Talk about speed: “With clear policies, your team can use AI without having to ask Legal every time — that speeds up operations.” Good governance is governance no one sees as an obstacle.

🎒 Module summary

✓
NIST AI RMF — 4 functions: GOVERN, MAP, MEASURE, MANAGE. Continuous risk management cycle.
✓
ISO/IEC 42001 — AIMS with a PDCA cycle. Certifiable, for those who need formal compliance.
✓
EU AI Act — 4 classes: unacceptable → high → limited → minimal. Obligations proportional to risk.
✓
Governance as an enabler — clear policies speed up adoption; early detection prevents crises.

Next track:

T4 — Plans: from diagnosis to an actionable roadmap, with a business case, prioritization, and pilot structure