AI Governance

Available now

AI Governance Essentials · 1.0

AI Governance Essentials is Keel’s free, plain-language baseline for governing AI responsibly. It gives you 34 practical expectations across eight areas (governance, risk and impact, data, transparency, human oversight, security, lifecycle, and third parties) that you can put in place and evidence today, then map to a formal standard when you need one.

34

requirements in Keel’s authored baseline

Free

Access

Free on every plan

Scope

How much of the standard Keel models

Keel-defined scope

This is a Keel-defined composite rather than a published standard, so there is no external leaf count it could be complete or incomplete against. Keel sets the scope, and the requirement count below is Keel’s own baseline.

Authored in Keel
34 requirements
Defined by the standard
Not applicable: no external standard

Keel publishes this for every framework it ships, complete or not, so a readiness percentage can be read against a denominator you can see. Compare every framework

Who it is for

Who needs AI Governance Essentials?

  • Teams that started using or building with AI and need a governance starting point
  • Companies fielding "how do you govern AI?" questions from customers and boards
  • Anyone who wants a running start on ISO 42001, the NIST AI RMF, or the EU AI Act

What Keel does

How Keel helps with AI Governance Essentials

  • A free, ready-to-use control set of 34 responsible-AI expectations, on every plan
  • Evidence collected once and reused across your other frameworks
  • A live readiness score, and a clean on-ramp to ISO 42001, NIST AI RMF, and the EU AI Act

Collect once, comply everywhere

AI Governance Essentials shares canonical controls with ISO/IEC 42001, NIST AI Risk Management Framework and EU AI Act and others in the catalog. Implement one of those controls and it counts toward every framework it satisfies, so adding AI Governance Essentials rarely means starting from scratch.

Shares canonical controls with

  • ISO/IEC 27001 shares canonical controls
  • CIS Critical Security Controls no shared canonical controls
  • PCI DSS no shared canonical controls
  • SOC 2 shares canonical controls
  • SOX (Sarbanes-Oxley) Section 404 shares canonical controls
  • NIST Cybersecurity Framework shares canonical controls
  • NIST SP 800-53 no shared canonical controls
  • FedRAMP Rev5 Class B no shared canonical controls
  • FedRAMP Rev5 Class C no shared canonical controls
  • FedRAMP Rev5 Class D no shared canonical controls
  • FedRAMP 20x no shared canonical controls
  • FedRAMP Consolidated Rules no shared canonical controls
  • NIST SP 800-171 no shared canonical controls
  • HIPAA no shared canonical controls
  • GDPR shares canonical controls
  • COPPA no shared canonical controls
  • Google Play Families no shared canonical controls
  • Amazon Appstore Child-Directed Apps no shared canonical controls
  • Apple App Store Kids Category no shared canonical controls
  • PIPEDA shares canonical controls
  • ISO 9001 shares canonical controls
  • ISO/IEC 42001 shares canonical controls
  • NIST AI Risk Management Framework shares canonical controls
  • EU AI Act shares canonical controls
  • ESG Essentials shares canonical controls
  • US Employment Law - Federal Baseline no shared canonical controls

A framework is lit when at least one canonical control satisfies both AI Governance Essentials and that framework. Unlit means none of them do, which is an absence rather than a judgment about that standard. 11 of 26 are lit here.