
AI governance and GRC are converging. Organisations deploying AI systems without formal governance structures face growing regulatory, legal, and reputational exposure.
AI governance GRC is the integration of AI risk management into your governance, risk, and compliance programme. It means treating AI systems as accountable assets with documented controls, human oversight, and board-level reporting.
In 2026, this is no longer optional. The EU AI Act is in active enforcement. ISO/IEC 42001 provides a certifiable AI management system standard. UK financial regulators have published clear expectations on AI risk. Boards need a structured response.
This guide covers what AI governance is, why boards must treat it as a formal risk category, the key frameworks, and how to integrate AI into your GRC programme.
EU AI Act:
High-risk AI provisions in force from August 2026
ISO/IEC 42001:
First international AI Management System standard (Dec 2023)
UK approach:
Pro-innovation sector regulators (FCA, ICO, CMA) apply existing law
FCA/PRA:
Published AI governance expectations for financial services firms
DORA:
Algorithmic models included in ICT risk management obligations
Fines (EU AI Act):
Up to 35,000,000 EUR or 7% of global annual turnover for prohibited AI
AI governance is the set of policies, processes, and controls that determine how an organisation builds, deploys, monitors, and retires artificial intelligence systems.
It covers who is accountable for AI decisions, how AI risk is identified and managed, and what safeguards exist when AI systems affect people or regulated processes. It is not the same as IT governance, though they overlap.
AI systems introduce risks that general IT controls do not fully address. These include model hallucination, algorithmic bias, explainability gaps, and uncontrolled model drift over time. A governance framework sets the rules for managing all of them.
AI risk is a board-level issue in 2026. Regulatory obligations, personal liability, and stakeholder scrutiny have all increased. Boards that treat AI as purely an IT or innovation matter are exposed.
The EU AI Act imposes fines of up to 35,000,000 EUR or 7 per cent of global annual turnover for prohibited AI use. Even limited-risk AI systems require transparency disclosures. High-risk AI systems, those used in employment, credit, essential services, or law enforcement, carry full conformity obligations.
UK financial regulators are equally focused. The FCA and PRA have both published discussion papers on AI risk in financial services. They expect firms to apply the same model governance discipline to AI systems that they apply to algorithmic trading and credit scoring models.
Regulatory fines:
EU AI Act penalties apply to UK organisations serving EU users
Personal liability:
FCA SMCR Senior Managers are accountable for AI systems in their remit
Provision 29:
AI governance controls are material controls under UK Corporate Governance
DORA:
Algorithmic models and automated systems are within ICT risk scope
Procurement risk:
Enterprise clients increasingly require AI governance evidence
Reputational risk:
AI incidents, bias, hallucination, data exposure, attract regulatory scrutiny
Two frameworks define AI governance obligations for UK and EU organisations in 2026. The EU AI Act provides the regulatory baseline. ISO/IEC 42001 provides the management system standard.
The EU AI Act is the world's first comprehensive AI regulation. It entered into force in August 2024. Its provisions apply in phases through to August 2027. High-risk AI system obligations apply from August 2026.
The Act takes a risk-based approach. AI systems are classified into four tiers based on the risk they pose to health, safety, and fundamental rights.
The EU AI Act applies to any organisation placing AI systems on the EU market or putting them into service in the EU. UK-based organisations offering AI-powered products to EU users are within scope.
August 2024:
Act entered into force
February 2025:
Prohibited AI provisions apply (Chapter II)
August 2025:
General Purpose AI (GPAI) model obligations apply
August 2026:
High-risk AI system obligations apply (Chapter III and IV)
August 2027:
Remaining provisions for Annex I and II AI systems
ISO/IEC 42001 was published in December 2023. It is the first international standard for AI management systems. Organisations can pursue formal certification against it, just as they certify against ISO 27001 for information security.
The standard covers AI strategy and objectives, risk assessment for AI systems, data governance for AI training and operation, performance monitoring and transparency, and responsible AI design principles. It is structured to integrate with ISO 27001, ISO 9001, and ISO 31000.
For UK organisations, ISO/IEC 42001 provides a structured path to demonstrable AI governance. Certification can be used as evidence in procurement, regulatory reviews, and client due diligence processes.
The UK has not enacted a standalone AI Act. The government's approach relies on sector regulators applying existing law to AI. The FCA, ICO, CMA, and Ofcom each have published or are developing AI guidance for their sectors.
The UK AI Security Institute conducts safety evaluations of frontier AI models. UK organisations subject to GDPR, the Equality Act, and product liability law face existing obligations when AI systems affect individuals.
Managing AI risk requires a structured approach. The ten practices below apply whether your organisation builds AI internally, uses third-party AI tools, or both.
AI inventory completed and maintained
Each system classified against EU AI Act risk tiers
AI governance policy approved and published
Human oversight mechanisms documented for high-risk AI
AI risk categories in the risk register
Vendor AI risk assessments completed
Continuous model monitoring in place with documented reviews
Staff AI use training with records
AI incident response process defined
AI governance included in board risk reporting
AI governance is not a separate workstream. It belongs within your existing GRC structure. Organisations that treat AI governance as a standalone IT project typically end up with documentation that sits outside the main compliance framework and is never reviewed in the risk cycle.
Integration starts with the risk register. AI should be a defined risk category with sub-categories for model risk, data risk, regulatory risk, and third-party AI risk. Each entry should have a named owner, a current risk rating, and linked controls.
AI risk maps directly to existing GRC domains. You do not need a new framework to govern it. You need to extend your current one.
The three lines of defence model applies directly to AI. The business owns AI risk and operates the controls. Compliance provides oversight and governance. Internal audit tests the controls independently.
A GRC assessment that does not address AI risk is incomplete. AI systems are now embedded in operations, customer interactions, and compliance processes at most organisations. Excluding them from GRC assessment leaves significant blind spots.
The GRC Index benchmark assesses AI governance risk within the existing domain structure. Organisations that complete a GRC Index benchmark receive a scored view of how well their current GRC programme addresses AI risk alongside all other control domains.
Organisations at maturity Level 1 to 2 in these domains typically have no formal AI governance at all. The GRC Index score identifies the specific gaps and prioritises remediation. From Level 3 upward, structured AI governance is both achievable and evidenced.
Before building an AI governance programme, measure where you are today.
A GRC Index benchmark gives you:
Scored maturity across six GRC domains (0-100 per domain)
RAG status per domain with priority action list
Evidence of AI governance gaps for Provision 29 and DORA
Board-ready reporting on GRC performance
A public GRC profile demonstrating governance commitment
Book your GRC Index benchmark at grci.net
AI governance in GRC refers to the policies, processes, and controls that manage how an organisation develops, deploys, and monitors AI systems. It addresses who is accountable for AI decisions, how AI risk is identified and assessed, and how AI systems are audited. AI governance sits within the Governance and Oversight and Risk Management domains of a GRC framework, and extends into Information Security and Third-Party Risk.
UK organisations should start by building an AI inventory covering all systems in use. Each system should be classified by risk level aligned to the EU AI Act tiers. AI risk should be added to the organisational risk register with named owners and reviewed at every risk cycle. Human oversight mechanisms must be documented. Vendor AI risk assessments are required for all third-party AI tools. Staff training records demonstrate that AI use policies are being applied.
The primary frameworks are the EU AI Act (Regulation EU 2024/1689), which applies a risk-based approach to AI regulation with high-risk provisions applying from August 2026, and ISO/IEC 42001, the first international AI Management System standard published in December 2023. In the UK, sector regulators including the FCA, ICO, and CMA apply existing law to AI, and organisations should monitor sector-specific guidance from each relevant regulator.
Yes. The EU AI Act applies to any organisation placing AI systems on the EU market or deploying them for EU users, regardless of where the organisation is headquartered. UK companies offering AI-powered products or services to EU customers or operating in the EU must comply with EU AI Act requirements. High-risk AI provisions apply from August 2026. Non-compliance risks fines of up to 35,000,000 EUR or 7 per cent of global annual turnover.
AI governance is assessed within the existing GRC domain structure rather than as a standalone assessment. Governance and Oversight covers AI policy ownership and board accountability. Risk Management covers AI risk register entries and assessment processes. Information Security covers AI system security controls and data access governance. Third-Party Risk covers vendor AI due diligence and model provenance. A GRC Index benchmark scores all six domains and identifies where AI governance gaps exist.
© 2025 GRC Index. All rights reserved.