Guide

What is an AI governance framework, and how can an operations team use one?

An AI governance framework is a set of steps and responsibilities for controlling AI in an organization. A practical version for operations teams has four steps: Know every AI and its owner, Authorize what each may access, do and spend, Operate with human approval for high-risk actions, and Prove what happened with a record.

  • Sourced
  • Updated 5 Oct 2026

Request early access

In 30 seconds

Four steps

Know

List every AI and its owner.

Authorize

Set what each may do.

Operate

Approve what matters.

Prove

Keep the record.

What a framework is for

Public frameworks, such as the NIST AI Risk Management Framework and the ISO/IEC 42001 management system standard, are broad. They cover many kinds of AI and many risks. An operations team that needs to start this quarter often wants something smaller: a working loop for AI agents that act in the business.

The four steps

1. Know

Keep one list of every AI agent and tool in use, with a named owner, a purpose and the systems it reaches.

  • Owner: operations lead, with IT.
  • Output: the register.
  • Check: can you name every agent running today?

82%

of surveyed enterprises reported AI agents running in their environment that they did not know about.

Source: Cloud Security Alliance survey, commissioned by a security vendor, April 2026. 418 IT and security professionals

2. Authorize

Decide what each agent may access, do and spend.

  • Owner: the business owner of each agent, with risk.
  • Output: a policy per agent: access, allowed actions, spend limit.
  • Check: does any agent have more access than its job needs?

3. Operate

Run agents day to day with a person approving high-risk actions.

  • Owner: named approvers and the operations lead.
  • Output: approved or declined actions, an Emergency Stop plan.
  • Check: who approves an email to a customer, and how fast?

4. Prove

Keep a record of every action, approval and cost, and review it.

  • Owner: operations lead, with finance and compliance.
  • Output: an audit log and a monthly review.
  • Check: can you show last month's agent actions to a customer or auditor?

A monthly rhythm

WeekActivity
1Update the register: new, changed, retired agents
2Review limits and approvals: too many or too few requests?
3Review the record and costs: anything unexpected?
4Report to leadership: what AI did, what it cost, what changed

How this relates to public frameworks

The four steps are a working loop, not a replacement for public frameworks. They map loosely: Know and Authorize support what NIST calls Govern and Map, and Operate and Prove support Measure and Manage. This is an orientation, not a formal mapping. MFDIO is not certified to, audited against or endorsed by NIST or ISO. If your business needs to meet a specific rule or standard, work with a qualified adviser.

How MFDIO applies the framework today

The platform is built around these four steps: Know, Authorize, Operate, Prove.

See what works today.

Questions people ask

Do we need a committee? Not to start. A named lead, a register and a monthly review are enough for a first version.

How long does it take to start? A first register and set of limits can often be drafted in days. The rhythm builds over a quarter.

Limits of this guide

This guide is general information and not legal advice. MFDIO is in invite-only early access and is pre-revenue. MFDIO does not hold SOC 2 or ISO 27001 today. Market figures are analyst or survey estimates and vary between sources.

Sources

  1. NIST, AI Risk Management Framework (AI RMF 1.0), January 2023: Govern, Map, Measure, Manage
  2. ISO/IEC 42001:2023, Artificial intelligence management system standard (referenced by name; not reproduced)
  3. Cloud Security Alliance, "Autonomous but Not Controlled: AI Agent Incidents Now Common in Enterprises", 21 April 2026 (418 IT and security professionals; commissioned by a security vendor)
  4. MFDIO product facts: checked against /status on 5 October 2026

Published . Last updated . Written by the MFDIO team.

See the four steps

Early access is invite-only.

Request early access