AIGRAF
AI Governance & Risk Assessment Framework — a practical framework designed to help organisations establish responsible AI adoption through integrated governance and security controls, with measurable outcomes.
Two Integrated Disciplines
Pillar 1
AI Governance
Strategy, risk management, compliance readiness, and accountability structures that make AI adoption auditable and board-reportable.
Pillar 2
AI Security
Technical controls before deployment and runtime controls in production — grounded in OWASP Agentic Top 10 and real architecture review.
Theory vs. Operational Reality
| Most Frameworks | AIGRAF |
|---|---|
| Focus on deploying AI slowly & safely | Focus on accelerating responsible AI adoption |
| Covers governance OR security — rarely both | Integrates governance and security controls in one framework |
| Written by lawyers, policy specialists, compliance professionals | Designed by practitioners who actually make governance work |
| Define principles | Measure outcomes — KPI-driven governance |
| Ignore AI agent identity and access | Agent ownership, authorisation, certification, revocation |
| No structure for runtime security or incident response | Runtime security controls and post-incident architecture fix built in |
ADOPTS
A structured path from AI ideation to governed, secure operations — covering both governance accountability and security controls at every stage.
Authorize
Establish AI ownership, identity, and authorisation structures. Define who approves AI use and on what terms. Set access boundaries for agents and models.
Define
Define AI use case scope, risk classification, security controls, and stakeholder accountability before a model or agent is deployed.
Orchestrate
Orchestrate the governance processes, security controls, and oversight mechanisms that will operate throughout the AI lifecycle — not just at launch.
Produce
Produce governance artefacts, security assessments, risk registers, accountability maps, and reporting dashboards that make governance visible and auditable.
Transfer
Transfer governance and security knowledge to internal teams. Ensure capability is embedded — not dependent on consultants.
Sustain
Sustain through continuous monitoring, KPI measurement, periodic reviews, and adaptation as the AI and threat landscape evolves.
Technical vs. Runtime Controls
Technical Controls (pre-deployment)
- ›Architecture review (OWASP Agentic Top 10)
- ›Agent identity & access management
- ›Trust boundary mapping
- ›Tool & API surface minimisation
- ›Pre-deployment adversarial testing
Runtime Controls (in production)
- ›Monitoring & observability strategy
- ›Guardrails design & advisory
- ›Anomaly detection framework
- ›Incident response playbook
- ›Post-incident architecture fix
Want to see AIGRAF applied to your organisation?
We run governance maturity assessments and AI security architecture reviews — practical, not theoretical.
Request an Assessment →