Doing AI Governance | Edition #59: How I scope compliance obligations for AI governance


This newsletter provides practical guidance, tools and resources for the real work of governing safe, secure and lawful AI.

Newsletter #59 - June 2026

Feature Article #1

How I scope compliance obligations for AI governance

By James Kavanagh


The biggest compliance obligations on your AI systems rarely come from AI regulation. Here's how I work out what actually applies, starting from what the business does, not the law.

When practitioners new to AI Governance start scoping their compliance work, they tend to reach for the AI-specific stuff first. They pick up the EU AI Act, or ISO 42001, or the NIST AI RMF, work through it asking "does this apply to us?", and quietly assume the rest, privacy law, sector regulation, employment law, consumer protection, the client contracts, has already been handled by someone else. More often than not it hasn't, at least not in a way that accounts for AI. And that existing body of requirements is where the most consequential obligations on your use of AI almost always sit.

So I flip the order. Instead of starting with a regulation and asking whether it applies, I start by describing the business: what it does, where it operates, who it serves, what data it handles, what decisions it makes about people. It's an idea I've borrowed from environmental management, of all places, where ISO 14001 has organisations identify their "aspects" first and let the legal requirements follow from them. I use seven categories of aspects to do the same for AI, and once they're described, the applicable regulations surface from them rather than the other way round.

The payoff is that you can scope quickly and roughly, then iterate, instead of reading a hundred regulations one at a time and still missing the ones that matter. The full method, the seven categories, how organisation-level and system-level aspects stack, and where you absolutely need a lawyer in the room, is in the article.

This kind of risk prioritisation is the work we cover in the AI Governance Foundation Track and AI Compliance Speciality course. Join the waitlist.

What's your AI governance practitioner capability score?

Feature Article #2

How I map compliance expectations to controls and mechanisms

By James Kavanagh


New AI regulations don't replace your existing compliance work, they pile on top of it. Here's how I map every source into one common control framework, as an essential first step in building a scalable and efficient compliance program.

This is the natural sequel to scoping. Once you know what's in scope, you're left holding a stack of regulations, standards and contracts that all speak different languages but keep pointing at the same governance territory. The tempting thing is to give each one its own owner and its own workstream: the EU AI Act here, ISO 42001 there, GDPR somewhere else, the client contracts with whoever was closest when they landed. It grows that way without anyone deciding it should, and it fails in three predictable ways. It duplicates effort, it leaves gaps at the boundaries between programs, and it quietly papers over the conflicts nobody gets around to resolving.

The alternative is one internal framework, organised by what governance actually does rather than by where each requirement came from. Functional domains like risk management, security and incident management, with every external source mapped into it, but most importantly tailored to your organization.

The article walks through the methodology I use to create this kind of consolidated crosswalk: Artifact to Expectation to Control to Mechanism. It's a straightforward but powerful approach to building your crosswalk and mechanism portfolio across all twelve domains of AI governance and all the major regulatory and compliance sources.

If your compliance pile keeps growing while the work stays the same size, this is what to do about it. It sits at the center of our AI Compliance Specialty Course, launching in July, with AI Risk close behind. Join the waitlist.


What we're working on

We started our first Foundation Track Practitioner Cohort last week with 15 participants from a range of legal, technology and policy disciplines. Through one complex case study of AI governance in a children's hospital, we're working to identify harms, set principles and commitments, build inventory, diagnose and redesign mechanisms and finally write policies that people will genuinely use. And all of it implemented within the VerifyWise GRC platform. This is hands-on real practice of AI governance. Our next cohort starts in August and spots are filling fast - secure your place here.

Our AI Compliance Specialty Course is coming along nicely and is on schedule for a July release date. Right now, we're focusing on the Balcony tool you'll use throughout the course. We will go out to our waitlist with a special offer prior to the course being made available to the general public, so be sure to join the waitlist here.

And for those of you who have completed, or are working through, the Foundation Track, we'll be in touch over the coming weeks with more information on our new credential - the Practitioner Award, AI Governance Foundations. Learn more about AI Career Pro Practitioner Awards and other credentials here.

As always, reach out if you have questions or need further clarity on any of our work, or if you need help navigating your professional path. We're learning with you and really appreciate your enquiries and feedback.

PS. You're receiving this as a subscriber to communications from AI Career Pro. We respect your privacy, so please unsubscribe through the link below if you do not wish to receive these communications in the future.

PO BOX 7087, Redhead, NSW 2290
Unsubscribe · Preferences

Doing AI Governance

Join over 4,500 subscribers and learn about the real work of AI governance. Moving beyond theory, we focus on the practical application of AI governance in real-world organisations with case studies, tools, templates and guidance. Led by James Kavanagh - the AI governance practitioner who led governance at both AWS and Microsoft.

Read more from Doing AI Governance

This newsletter provides practical guidance, tools and resources for the real work of governing safe, secure and lawful AI. Newsletter #60 - July 2026 Feature Article #1 Building an AI Inventory is your First Governance Intervention By James Kavanagh Your first meaningful governance intervention is most likely building an AI inventory. It's the first time anyone in the organisation has to sit down and agree, out loud, on what AI is really running and what it's for. That's not an admin task...

This newsletter provides practical guidance, tools and resources for the real work of governing safe, secure and lawful AI. Newsletter #58 - June 2026 Feature Article #1 How I triage AI governance problems By James Kavanagh You get hired to review one AI system. Within hours you find a dozen, and the one everyone's worried about turns out to be the safest of the lot. The systems that should worry you are usually the ones nobody can see. This is the method I use to work out where to start....

This newsletter provides practical guidance, tools and resources for the real work of governing safe, secure and lawful AI. Newsletter #57 - May 2026 Feature Article A new path to demonstrated practitioner capability in AI governance. By James Kavanagh Law has supervised practice before admission to the bar. Medicine has residency. Engineering has years of oversight by senior engineers before obtaining a charter. Each serious profession recognizes that capability builds in stages, and that...