GovCompass
AI governance

AI governance and enterprise risk management: where they meet

By GovCompass.ai· Last updated August 2026· Aligned with the consolidated EU AI Act, COSO ERM 2017, and the three lines model (2020).

AI governance is not a parallel structure that sits beside enterprise risk management. It belongs inside it. The seven pillars of responsible AI are the control structure the organization uses to govern each AI system; enterprise risk management is the machine that carries the residual risk those controls leave behind into the board's risk appetite, the risk register, and the assurance plan. The practical question is not whether to build AI governance or ERM, but how to slot the first into the second so that one accountable structure, not two competing ones, owns AI risk.

Two questions that get conflated

Before the two disciplines can be connected, one confusion has to be cleared. Organizations routinely merge two different uses of the word AI in their riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry → conversations.

The first is AI as a risk to be managed. An AI systemAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry → the organization builds or deploys introduces risks to fairnessfairnessThe responsible-AI principle that systems should not create or reinforce unjust discrimination; operationalized through bias testing, representative data and per-group thresholds. It has multiple, mutually incompatible mathematical definitions. Under the EU AI Act, providers of high-risk AI systems must examine their data sets for possible biases (Article 10), and several discriminatory uses are prohibited outright (Article 5). See bias, proxy discrimination, high-risk AI system, responsible AI.Open full entry →, safety, privacyprivacyThe principle that personal data used by or produced through an AI system stays within the purpose and the legal basis it was collected for. Three routes cause most of the trouble: personal data in training material that was never intended for it, model output that reproduces what the model retained, and purpose creep, where a system built for one use drifts into another the original basis never covered. The GDPR governs this in full, and the EU AI Act adds data governance duties for high-risk systems (Article 10). See DPIA, purpose limitation, responsible AI.Open full entry →, security, and the rest of the seven pillarspillarA responsible-AI principle as something an organization actively holds rather than merely endorses: one of the seven pillars of responsible AI, one per principle. A pillar is held, not implemented, by naming the harms that would breach the principle, assessing their risk, and placing controls that reduce it. Distinct from agentic AI, which is not one of the seven but a condition that changes how all of them are governed. See principle, harm, risk, agentic AI.Open full entry → of responsible AIresponsible AIThe set of principles an AI system should live up to: fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, and human oversight. Widely shared and sitting under the EU AI Act and the major frameworks. On their own the principles are statements of intent; the law turns them into duties that cannot be met unless they are carried inside the organization's governance, which is how responsible AI lands in governance rather than beside it. The seven principles are organized into seven pillars, one pillar per principle. See principle, pillar, governance. The seventh principle carries two names in practice: human oversight in the seven-pillar model, and human-centricity in the IAPP AIGP body of knowledge; the substance overlaps.Open full entry →. Governing those risks is what AI governanceAI governanceGovernance extended for AI: the same organizational steering at the highest level, widened to cover what makes AI different (it works in probabilities rather than fixed rules, learns from data, and can act at a speed and scale no human reviewer can match). It inherits the existing governance structure and brings AI inside the disciplines the organization already runs, rather than creating a parallel system in a silo. It operates on two levels, design and execution. See governance, governance design, execution level, responsible AI.Open full entry → is for.

The second is AI as a tool to manage risk. A risk function can use AI to process more data, monitor exposures in real time, detect anomalies, or triage claims. That is a productivity question about the risk function's own operating model, not a governancegovernanceThe system through which an organization steers itself: corporate governance, risk management, compliance, lines of accountability, risk appetite, and the operating model. It exists across everything the organization does, before and beyond AI. AI governance is this same system extended for AI. See AI governance, governance design, execution level.Open full entry → question.

These are different problems. AI as a tool is governed like any other AI system the organization deploys: it goes into the AI inventoryAI inventoryA register of all AI systems an organization builds, buys or embeds, with owners and risk tiers. It is the prerequisite for governing any of them.Open full entry → and is held to the seven pillars of responsible AI like everything else. But the discipline of AI governance is about the first question, and it is the first question that has to be connected to enterprise risk management.

AI governance belongs inside ERM, not beside it

When AI governance appears on the agenda, the common instinct is to build a new structure: an AI committee, an AI policy, an AI risk taxonomy, sitting alongside the existing enterprise risk management framework. This produces two parallel machines that do not talk to each other. The AI committee tracks AI risks in its own register; the ERM function tracks enterprise risks in another; and the board sees AI risk as a separate topic rather than as part of the risk profile it already governs.

The COSO ERM 2017 framework was built precisely to avoid this fragmentation. Its premise is that risk is integrated with strategy and performance, not managed in a silo. AI risk is an enterprise risk like any other: it affects strategy, it has an owner, it carries a severity, and it competes for attention and budget against every other risk the organization faces. Treating it as a separate domain undermines the integration COSO ERM exists to create.

The cleaner model is one structure. The seven pillars of responsible AI provide the controlcontrolThe concrete, testable measure that reduces a specific risk, and through that risk protects the principle behind it. Also called a risk management measure, risk response, or risk treatment. Always traceable to the risk it addresses: under EU AI Act Art. 9 every control must map back to a specific risk, and controls recorded separately from their risks is a recognized compliance failure. It works in one of three types: preventive, detective, or corrective. See risk, control types, evidence.Open full entry → structure at the level of each AI system: the preventive, detective, and corrective controls that hold each pillar in place. Enterprise risk management provides the layer above: it takes the residual riskresidual riskThe risk that remains after controls have reduced it. No control reduces a risk to zero, and not every control is worth its cost, so a deliberate judgment is made: whether the cost of further control is justified by the reduction it would buy, and whether the remaining risk is acceptable against the organization's risk appetite. This is a design-level judgment, where execution reports back up and governance accepts the residual risk, calls for more control, or declines the use case. EU AI Act Art. 9(5) requires it to be judged acceptable per hazard and overall. See risk, control, risk appetite.Open full entry → those controls leave behind, weighs it against the organization's risk appetiterisk appetiteThe level of risk an organization's leadership is willing to accept in pursuit of its objectives, set at the governance design level. It is the benchmark against which residual risk is judged acceptable or not, inherited from the organization's broader governance and applied to AI. A concept from enterprise risk management (COSO ERM) before it is an AI one. See residual risk, governance design.Open full entry →, records it in the enterprise risk registerrisk registerThe living record of an AI system's identified risks, ratings, responses, owners and review dates, kept current from design through retirement.Open full entry →, and routes it into the board's oversight. AI governance is the system-level control discipline; ERM is the enterprise-level aggregation and oversight discipline. They are two layers of one structure, not two structures.

The three lines model applied to AI

The clearest way to assign ownership is the three lines model, updated by the Institute of Internal Auditors in 2020 from the older "three lines of defensethree lines of defenseAccountability model: the first line owns and operates risk, the second line sets policy and challenges, the third line (internal audit) independently assures, adapted to AI governance organization-wide.Open full entry →" language. Applied to AI governance, it resolves a question that much of the risk-management literature raises but does not answer: who, exactly, is accountable for what.

The first line owns and operates the AI system. The business owner who deploys an AI system to make or support decisions owns the risk that system creates. They run the preventive controls in daily operation: they keep the system within its intended purpose, apply the human oversighthuman oversightDesigned-in human ability to monitor, intervene in, override or shut down an AI system. It is meaningful only when the human has authority, information and time to act. One of the seven pillars of responsible AI, and under the EU AI Act a requirement for high-risk AI systems: Article 14 requires that those systems are designed so natural persons can effectively oversee them. Oversight that exists on paper but amounts to confirming in practice does not meet that bar. See override rate, automation bias, high-risk AI system, fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, responsible AI. In the IAPP AIGP body of knowledge, this principle appears as human-centricity, with human oversight as one of its elements.Open full entry → measures, and act on the monitoring signals. In pillar terms, the first line is where the controls actually operate. AI governance fails most often because the first line treats the controls as someone else's job.

The second line provides the framework, the expertise, and the challenge. This is where the AI governance function sits, often an AI Officer or an AI governance team. The second line owns the seven-pillar framework itself: it defines the controls each pillar requires, maintains the AI inventory and the risk classification, sets the policy, and challenges the first line on whether the controls are designed and operating. The second line does not run the AI system; it sets the standard the first line is held to and reports the aggregate picture into ERM. Crucially, the second line is also where AI risk is translated into enterprise risk language: a pillar control gap becomes a risk register entry with a severity, an owner, and a treatment.

The third line provides independent assurance. Internal auditinternal auditThe third line of defense: independent assurance that AI assessments, controls and documentation actually operate, reporting to the board, never to the builders.Open full entry →, the third line, does not own the controls and does not set the framework. It independently assesses whether the first line is operating the controls and whether the second line's framework is adequate. For AI systems, this is where the conformity evidenceevidenceThe concrete proof that a control is designed, implemented, and working: a test report, an audit trail, an impact assessment, a monitoring log. Each link in the governance chain produces an artifact, and together they are what an organization hands to its own board, a regulator, a customer, or an affected person to show, not say, that a system is governed. Its absence is itself the failure: a risk register without test results, or a mitigation claimed without validation, is a governance gap, not a paperwork one. The closing link of the governance chain. See control, governance.Open full entry → the EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry → requires meets an independent eye: internal audit tests whether the technical documentationtechnical documentationRecords a provider must compile and keep for a high-risk AI system to demonstrate conformity, covering its design, data, testing, risk management and monitoring.Open full entry →, the human oversight measures, and the post-market monitoringpost-market monitoringProvider-side duty to systematically collect and act on experience from systems in use, the product-regulation half of continuous monitoring.Open full entry → actually exist and function, rather than existing on paper. An organization whose AI governance has never been through the third line has assurance gaps it cannot see.

The governing body sits above all three. The board exercises oversight: it sets the risk appetite that determines how much AI risk the organization will accept, and it holds management accountable for staying within it. Under the EU AI Act and increasingly under investor and supervisory expectations, AI risk oversight is becoming an explicit board responsibility, which makes the reporting line from the second line, through ERM, to the board the spine of the whole structure.

How a pillar gap becomes an enterprise risk

The connection between the two disciplines is made concrete in one mechanism: the translation of a control gap into a risk register entry.

Take a high-risk AI systemhigh-risk AI systemAn AI system that falls under the EU AI Act's strictest requirements, following Article 6. There are two routes in: a system that is a product or safety component covered by the Union harmonization legislation in Annex I and subject to third-party conformity assessment, or a system used in one of the areas listed in Annex III, such as employment, education, or access to essential services. Article 6(3) contains a filter: an Annex III system is not high-risk if it does not pose a significant risk of harm to health, safety, or fundamental rights, although a system that profiles natural persons is always high-risk. See EU AI Act, Annex III, conformity assessment.Open full entry →. The second line assesses it against the seven pillars of responsible AI: for each pillar, are the preventive, detective, and corrective controls designed, implemented, and evidenced. Suppose the fairness pillar is governed by a pre-deployment biasbiasA systematic skew in data, model behavior, or outcomes that treats one group differently from another without justification. Bias usually enters through training data that reflects historical patterns. For high-risk AI systems, Article 10 of the EU AI Act requires examination of datasets for possible biases and measures to detect, prevent, and mitigate them. See fairness, proxy discrimination.Open full entry → test but has no production monitoring and no corrective process. That is a control gap. On its own it is a governance finding. But it does not stay a governance finding.

The gap is translated into an enterprise risk: the risk that the system produces discriminatory outcomes in production that go undetected and uncorrected, with a severity driven by the consequence of the decision the system makes and the number of people affected. That risk is recorded in the enterprise risk register, weighed against the organization's risk appetite for discrimination and regulatory exposure, assigned to the first line owner with the second line as the framework owner, and surfaced to the board if it exceeds appetite. The treatment, building the missing detective and corrective controls, becomes a tracked action with a deadline.

This is the mechanism that keeps AI governance from becoming a parallel world. Every pillar gap has a path into the enterprise risk register, where it competes for attention against every other enterprise risk on equal terms, in language the board already understands.

Mapping to COSO ERM

The five components of COSO ERM 2017 give the structure a recognizable shape, and AI governance maps onto each.

Governance and culture: the board's AI risk oversight, the operating structure that assigns the three lines, and a culture that treats AI risk as everyone's responsibility rather than the AI team's alone.

Strategy and objective-setting: the organization's risk appetite for AI, set deliberately rather than discovered after an incident, and the alignment of AI deployment with that appetite.

Performance: the heart of the connection. The AI inventory, the risk classification, the pillar assessment of each high-risk system, and the translation of control gaps into prioritized risks.

Review and revision: the continuous monitoringcontinuous monitoringOngoing observation of a deployed system's performance, drift, fairness and usage against thresholds with named owners. It is the control that matches AI's speed and scale.Open full entry → that the EU AI Act's Article 9 risk management system and post-market monitoring obligations require, feeding changes back into the controls.

Information, communication, and reporting: the reporting line from the second line, through ERM, to the board, and the external reporting the EU AI Act requires, including incident reporting.

Where to start

If your organization has both an ERM function and an emerging AI governance effort, the most valuable first step is to refuse to let them run as two structures. Place the AI governance function explicitly in the second line, give it the seven pillars of responsible AI as its control structure, and build the one mechanism that connects the two disciplines: the translation of each control gap into an enterprise risk register entry with an owner, a severity, and a path to the board.

From there, the three lines each know their job. The first line operates the controls. The second line owns the framework and reports the aggregate. The third line provides independent assurance. And the board governs AI risk as part of the risk profile it already oversees, rather than as a separate topic it was asked to care about. That is what it means to govern AI inside enterprise risk management rather than beside it.

Professionals who carry AI risk at this level increasingly certify the skill with the AIGP.

Legal referencesArt. 9
Continue withAccountability
Share Share on LinkedIn

More on Accountability

Agentic AI and governance: why autonomy sharpens the control question

Analysis

Agentic AI does not need a new kind of governance. Autonomy widens the gap between what a system does and who is accountable for it, which makes the existing governance chain, control tracing to risk and forward to evidence, more important, not less. The actions are real and sometimes irreversible, so the stakes on each control rise.

Agentic AI risk assessment: from architecture decisions to control objectives

Analysis

Assessing the risk of an AI agent does not need a separate method. The steps stay the same: recognize the risk, assess how likely and how severe it is for your system, and control it. What changes is the input. An agent runs the process through recorded architecture decisions, about the model, the instruction, retrieved knowledge, tools, orchestration, memory, and autonomy, and each of those decisions, alone or in combination, creates the possibility of harm. The output of the assessment is a set of risk scenarios with a control objective for each.

AI certification: what exists and what it proves

Analysis

AI certification is not one category. Three different objects are assessed, each by a different kind of assessor: a person, an organization's AI management system, and an AI system placed on the EU market. The first two can be certified. The third is subject to a legal conformity assessment, which produces a certificate on one of its two routes and none on the other. Identifying which object a credential covers is the first step to judging what it is worth.

Control-level compliance: the EU AI Act as an instrumented system

Analysis

Control-level compliance means satisfying the EU AI Act through engineered, evidenced controls rather than policy documents. The technical articles translate directly into system controls: automatic, retained logs (Art. 12, 19), a stop function to a safe state (Art. 14(4)(e)), input masking before the model as a GDPR and Art. 26(4) control, configurable block policies (Art. 26), risk scoring and incident reporting within deadline (Art. 9, 73), and workspace isolation with role-based access (Art. 14, 26). Compliance at this level is an instrumented system, not a policy as PDF.