Three international frameworks define the state of the art in AI governance: the NIST AI RMF (risk management), the ISO/IEC 42001 (management system) and the EU AI Act (risk-based regulation). Knowing them isn’t bureaucracy—it’s what enables a consultant to recommend proportionate, defensible structures.
The three frameworks complement one another — risk management + management system + regulatory classification.
🗂️ NIST AI RMF — the 4 functions
O AI Risk Management Framework from NIST (National Institute of Standards and Technology) is the most widely adopted AI risk management framework in the U.S. and a global reference. It organizes management into 4 functions that form a continuous cycle.
GOVERN — Culture and policies
Establishes an organizational culture of AI accountability: policies, roles and responsibilities, team training, and accountability. This is the function that defines “how we behave around AI.”
MAP — Identify risks by context
For each AI system, identify its usage context, affected parties, and relevant risks. The same model can pose very different risks depending on how and where it is used.
MEASURE — Assess impacts
Quantify and assess the identified risks — likelihood, impact severity, affected groups. This turns the risk list into data that informs decisions.
MANAGE — Address and monitor
Implement controls for priority risks and monitor continuously—including detecting new risks that emerge with operations and over time.
💡 How to use NIST in practice
For SMEs, use NIST as a minimum checklist: "Do we have policies? Have we identified this system's risks? Have we measured the impact? Do we have controls?" You don't need to implement the full framework — just cover the critical points for the context.
🌐 ISO/IEC 42001 — the AI management system
Published in 2023, the ISO/IEC 42001 is the first international management system standard specifically for AI (AIMS — AI Management System). If you know ISO 9001 or 27001, the structure will be familiar: PDCA and compliance requirements.
🔄 The PDCA cycle applied to AI
Plan — Plan
Define the AIMS scope, identify stakeholders, analyze risks and opportunities, and establish AI management objectives.
Do — Do
Implement policies, controls, and processes. Document the organization’s AI development and usage practices.
Check — Check
Monitor, measure, and audit the AIMS. Check whether the controls are working and the objectives are being met.
Act — Take action
Take corrective action and continually improve the management system based on monitoring results.
📌 Who needs 42001
Organizations that develop or deploy AI at scale, serve clients with compliance requirements, or seek competitive differentiation through certification. For SMEs without these drivers, apply the principles without formal certification.
🇪🇺 EU AI Act — risk classification
O EU AI Act (in effect since 2024) is the world’s first comprehensive AI regulation. It classifies AI uses into 4 categories and defines obligations proportional to risk. Brazilian companies that handle data belonging to European citizens are subject to it.
Unacceptable risk — systems that violate fundamental rights. Examples: government social scoring, real-time biometric recognition in public spaces, subliminal manipulation.
High risk — AI in critical infrastructure, healthcare, education, employment, credit, migration, and justice. Requires registration, transparency, human oversight, and conformity assessment.
Limited risk — chatbots, deepfakes. Requires transparency: users need to know they’re interacting with AI or consuming content generated by it.
Minimal risk — spam filters, AI games, playlist recommendations. No specific obligations beyond general laws.
⚡ The 5 AI risks every consultant should know
Regardless of frameworks, every AI consultant needs to know the following by heart: 5 fundamental risks — because these are the ones that come up in real projects and that the client will need to decide how to handle.
⚖️ Bias
Models trained on historically biased data replicate and amplify discrimination. In credit, employment, or healthcare, this can be illegal as well as unfair.
🌀 Hallucination
LLMs generate incorrect outputs presented with confidence. In legal, medical, or financial contexts, an undetected hallucination can cause real harm.
🔐 Security
Prompt injection, data extraction through malicious prompts, or inadvertent submission of sensitive data to external APIs without appropriate contracts.
👤 Privacy
Personal data entered in prompts may be stored and used for training. Employee or customer context in third-party LLMs without a DPA poses LGPD risk.
🏢 Reputational risk
An AI incident — whether an offensive response, a discriminatory decision, or a data leak — can go viral before the company knows what happened. The company’s reputation pays the price for a lack of governance.
⚖️ Risk-proportionate governance
The most common mistake is proposing the same level of governance for every use of AI. An internal FAQ chatbot requires much less structure than a credit approval system. Proportionality is what makes governance viable and widely adopted.
📐 Governance by risk level
control ∝ risk
SMEs can implement
grows with AI usage
the team follows because it makes sense
🚀 Governance as an enabler, not a brake
The narrative matters. A consultant who presents governance as “mandatory compliance” meets resistance. One who presents it as "which allows AI to scale without crises" finds allies in leadership.
✗ Without governance
- ✗Ad hoc AI decisions — no audit trail
- ✗An incident becomes a public crisis before a response can be made
- ✗Scaling AI means scaling uncontrolled risks
- ✗B2B clients reject vendors without an AI policy
✓ With proportional governance
- ✓Clear policies speed up operational decisions
- ✓Monitoring detects problems before they become crises
- ✓Scale AI with confidence — documented foundation
- ✓An AI policy becomes a competitive advantage in B2B
💡 How to sell governance to leadership
Don’t talk about compliance. Talk about speed: “With clear policies, your team can use AI without having to ask Legal every time — that speeds up operations.” Good governance is governance no one sees as an obstacle.
🎒 Module summary
Next track:
T4 — Plans: from diagnosis to an actionable roadmap, with a business case, prioritization, and pilot structure