Skip to main content
AI Governance Execution Framework

AI Governance
Execution Framework

CSM6 operationalizes governance into six operating functions across the AI lifecycle

For AI/system owners, product, engineering, security, data, risk, compliance, legal, architecture, program leadership and accountable executives. A risk-proportionate path from intent to evidence.

6
Operating functions
3
Audience perspectives
Lifecycle
Coverage across the AI lifecycle
Risk-based
Proportionate by design
Extends Cognitive Systems Management (CSM)Designed to map to NIST AI RMF & ISO/IEC 42001Provider-agnostic methodology

From CSM to CSM6

CSM6 operationalizes and extends the Cognitive Systems Management (CSM) methodology into six cross-functional governance functions.

Cognitive Systems Management (CSM)

Established governance domains across enterprise, project, code, and UX/human interaction.

CSM6

Evolved those principles into six operating functions that can be implemented across the same domains throughout the AI lifecycle.

Framework characteristics

Lifecycle-oriented
Risk-proportionate
Cross-functional
Evidence-aware
Iterative with feedback loops
Provider-agnostic at the methodology level

The AI Governance Gap

Organizations are deploying AI without the operating model to govern it across the lifecycle

Without an Operating Model

AI Without Clear Ownership or Intent

AI tools are deployed with no documented intended use, accountable owner, or autonomy boundaries, making accountability impossible when something goes wrong.

Hidden Dependencies and Concentration

Organizations do not know which models, providers, data sources and subprocessors their AI depends on, creating blind spots and single points of failure.

Unmanaged Change

Models, prompts, datasets and agent authority change without approval, classification, or rollback plans, so significant modifications go unreviewed.

No Evidence to Reconstruct Decisions

When issues arise, organizations cannot reconstruct what was evaluated, approved, changed, or overseen, undermining audit, review and assurance.

With CSM6

Accountable Intent Per System

Each system has a documented intended use, accountable owner, autonomy boundaries, and a preliminary risk classification that drives proportionate governance.

Visible Systems and Dependencies

An inventory of models, data sources, integrations and subprocessors surfaces concentration and single points of failure before they become incidents.

Controlled, Reversible Change

Meaningful changes are classified, approved and reversible, with significant modifications triggering reassessment rather than slipping through unnoticed.

Traceable Governance Evidence

Decisions, evaluations, approvals, changes, oversight and incidents are recorded so governance activities can be reconstructed for audit and review.

The Six Operating Functions

A useful starting sequence — then continuous interaction, feedback loops and reassessment

Organizations commonly begin with Functions 1–3 (purpose, mapping, risk) before strengthening delivery, oversight and evidence. After that, all six functions operate continuously — no function is ever "finished".

Function 1

Purpose, Scope & Accountability

Why the system exists, what it covers, and who is accountable

Accountable AI Intent

Establishes the business objective, intended use, acceptable and prohibited uses, and accountable ownership for each AI system before it scales.

Business objective and intended-use statement per system
Accountable owner and affected stakeholders identified
Autonomy boundaries and prohibited uses defined upfront
Clear ownership and intended use per system
Function 2

System, Data & Dependency Mapping

What the system is made of and what it depends on

Enterprise AI Inventory

Provides visibility into which AI systems exist, what they depend on, and where concentration or single points of failure create business risk.

Inventory of AI systems and business impact
Vendor and subprocessor concentration visible
Critical dependencies and single points of failure
AI inventory with dependencies
Function 3

Risk, Evaluation & Monitoring

Assess risk before deployment and monitor behavior during operation

Risk Awareness & Early Warning

Surfaces material risks, ensures meaningful evaluation before deployment, and provides early warning of drift, anomalies, or business-impact changes during operation.

Material risks identified before deployment
Acceptance criteria and thresholds defined
Early warning for drift and anomalies during operation
Risk register and monitoring priorities
Function 4

Controlled Delivery & Change

Approve, control, and roll back meaningful changes

Change Accountability

Ensures meaningful changes to AI systems - models, prompts, data, agents, permissions, integrations - are classified, approved, and reversible where it matters.

Change classification and approval records
Release criteria and rollback plans
Significant-modification review for high-impact changes
Approved and reversible changes
Function 5

Human Oversight, Feedback & Learning

Keep humans in the loop and learn from operations

Oversight & Organizational Learning

Establishes human review, escalation and override where applicable, and turns incidents and feedback into institutional knowledge that survives turnover.

Human review and escalation for high-impact decisions
Contestability and recourse where applicable
Incident review and lessons-learned captured
Oversight and lessons-learned records
Function 6

Compliance, Evidence & Assurance

Organize obligations, evidence and assurance across all functions

Assurance & Reporting

Organizes applicable obligations, internal policies, and evidence from Functions 1–5 into management reporting and assurance activities.

Applicability and obligations tracked
Evidence from Functions 1–5 organized
Management reporting and assurance activities
Organized evidence and assurance

Continuous, not a waterfall

CSM6 is not a strict six-step sequence. After an initial starting sequence, all six functions operate continuously with feedback loops. Compliance is cross-cutting across Functions 1–5; Function 6 organizes obligations, evidence and assurance rather than being where compliance begins.

Useful starting sequence: 1 → 2 → 3
Then strengthen 4, 5, 6
All functions then run continuously

Reassessment Triggers

These events re-open one or more functions. They keep governance tied to how the system actually evolves.

New use case or expanded scope
New model, provider, or subprocessor
Significant prompt, config, dataset or knowledge-base change
New integration or expanded agent authority
Material incident or significant performance drift
New jurisdiction or regulatory change
Major vendor change or system retirement

How HAIEC Can Support Implementation

The framework is methodology. HAIEC provides tooling that can help operationalize it.

AI inventory & dependency mapping

Capture systems, models, providers, data sources and dependencies that feed Function 2.

Risk & evaluation records

Record risk classifications, evaluation plans and results that feed Function 3.

Change & approval records

Track classified changes and approvals through review workflows that feed Function 4.

Evidence index & control mapping

Organize evidence and control mappings across functions for assurance and reporting.

Where HAIEC uses hashing or signatures, evidence is tamper-evident — alteration is detectable. Tamper-evident is not the same as immutable, and cryptographic integrity does not by itself prove a compliance conclusion is correct.

Frequently Asked Questions

Common questions about the AI Governance Execution Framework

Limitations

What CSM6 is, and what it is not.

CSM6 is not legal advice.

CSM6 is not certification.

CSM6 does not guarantee compliance.

CSM6 does not replace sector-specific requirements.

CSM6 does not determine regulatory applicability automatically without context.

CSM6 does not eliminate the need for qualified human judgment.

CSM6 does not require identical implementation for every AI system.

CSM6 does not replace NIST AI RMF, ISO/IEC 42001, or applicable laws — it complements them.

Ready to Implement AI Governance?

Start with the implementation guide, then use the checklist and HAIEC tooling to operationalize the six functions.