AI Governance
Execution Framework
CSM6 operationalizes governance into six operating functions across the AI lifecycle
For AI/system owners, product, engineering, security, data, risk, compliance, legal, architecture, program leadership and accountable executives. A risk-proportionate path from intent to evidence.
From CSM to CSM6
CSM6 operationalizes and extends the Cognitive Systems Management (CSM) methodology into six cross-functional governance functions.
Cognitive Systems Management (CSM)
Established governance domains across enterprise, project, code, and UX/human interaction.
CSM6
Evolved those principles into six operating functions that can be implemented across the same domains throughout the AI lifecycle.
Framework characteristics
The AI Governance Gap
Organizations are deploying AI without the operating model to govern it across the lifecycle
Without an Operating Model
AI Without Clear Ownership or Intent
AI tools are deployed with no documented intended use, accountable owner, or autonomy boundaries, making accountability impossible when something goes wrong.
Hidden Dependencies and Concentration
Organizations do not know which models, providers, data sources and subprocessors their AI depends on, creating blind spots and single points of failure.
Unmanaged Change
Models, prompts, datasets and agent authority change without approval, classification, or rollback plans, so significant modifications go unreviewed.
No Evidence to Reconstruct Decisions
When issues arise, organizations cannot reconstruct what was evaluated, approved, changed, or overseen, undermining audit, review and assurance.
With CSM6
Accountable Intent Per System
Each system has a documented intended use, accountable owner, autonomy boundaries, and a preliminary risk classification that drives proportionate governance.
Visible Systems and Dependencies
An inventory of models, data sources, integrations and subprocessors surfaces concentration and single points of failure before they become incidents.
Controlled, Reversible Change
Meaningful changes are classified, approved and reversible, with significant modifications triggering reassessment rather than slipping through unnoticed.
Traceable Governance Evidence
Decisions, evaluations, approvals, changes, oversight and incidents are recorded so governance activities can be reconstructed for audit and review.
The Six Operating Functions
A useful starting sequence — then continuous interaction, feedback loops and reassessment
Organizations commonly begin with Functions 1–3 (purpose, mapping, risk) before strengthening delivery, oversight and evidence. After that, all six functions operate continuously — no function is ever "finished".
Purpose, Scope & Accountability
Why the system exists, what it covers, and who is accountable
Accountable AI Intent
Establishes the business objective, intended use, acceptable and prohibited uses, and accountable ownership for each AI system before it scales.
System, Data & Dependency Mapping
What the system is made of and what it depends on
Enterprise AI Inventory
Provides visibility into which AI systems exist, what they depend on, and where concentration or single points of failure create business risk.
Risk, Evaluation & Monitoring
Assess risk before deployment and monitor behavior during operation
Risk Awareness & Early Warning
Surfaces material risks, ensures meaningful evaluation before deployment, and provides early warning of drift, anomalies, or business-impact changes during operation.
Controlled Delivery & Change
Approve, control, and roll back meaningful changes
Change Accountability
Ensures meaningful changes to AI systems - models, prompts, data, agents, permissions, integrations - are classified, approved, and reversible where it matters.
Human Oversight, Feedback & Learning
Keep humans in the loop and learn from operations
Oversight & Organizational Learning
Establishes human review, escalation and override where applicable, and turns incidents and feedback into institutional knowledge that survives turnover.
Compliance, Evidence & Assurance
Organize obligations, evidence and assurance across all functions
Assurance & Reporting
Organizes applicable obligations, internal policies, and evidence from Functions 1–5 into management reporting and assurance activities.
Continuous, not a waterfall
CSM6 is not a strict six-step sequence. After an initial starting sequence, all six functions operate continuously with feedback loops. Compliance is cross-cutting across Functions 1–5; Function 6 organizes obligations, evidence and assurance rather than being where compliance begins.
Reassessment Triggers
These events re-open one or more functions. They keep governance tied to how the system actually evolves.
How HAIEC Can Support Implementation
The framework is methodology. HAIEC provides tooling that can help operationalize it.
AI inventory & dependency mapping
Capture systems, models, providers, data sources and dependencies that feed Function 2.
Risk & evaluation records
Record risk classifications, evaluation plans and results that feed Function 3.
Change & approval records
Track classified changes and approvals through review workflows that feed Function 4.
Evidence index & control mapping
Organize evidence and control mappings across functions for assurance and reporting.
Where HAIEC uses hashing or signatures, evidence is tamper-evident — alteration is detectable. Tamper-evident is not the same as immutable, and cryptographic integrity does not by itself prove a compliance conclusion is correct.
Frequently Asked Questions
Common questions about the AI Governance Execution Framework
Limitations
What CSM6 is, and what it is not.
CSM6 is not legal advice.
CSM6 is not certification.
CSM6 does not guarantee compliance.
CSM6 does not replace sector-specific requirements.
CSM6 does not determine regulatory applicability automatically without context.
CSM6 does not eliminate the need for qualified human judgment.
CSM6 does not require identical implementation for every AI system.
CSM6 does not replace NIST AI RMF, ISO/IEC 42001, or applicable laws — it complements them.
Interactive Tools
Assess your current state before implementing the framework.