This Practice Playbook is a field guide for Cyber Risk and Governance leaders taking AI governance from a one-off assessment to a repeatable practice. Nine chapters, structured in three acts: See It (map what you're actually exposed to), Govern It (turn that map into defensible controls), Scale It (turn the practice into something you can offer and sell). Every chapter ships with a working artefact from the toolkit below — a template, a question bank, a scoring model — so each idea comes with something you can actually run, not just read. This is published work, not a pitch. Frameworks built for real engagements, generalized and shared because governance gets better when the tools behind it aren't kept behind closed doors. The Acts II & III will soon be updated here, so stay tuned for that.
A working toolkit of AI governance frameworks, risk assessments, and practice-building strategy — built by a practitioner and sharpened through real engagements, turning regulatory pressure into governance programs that pass audit, and AI adoption into something a risk committee can actually sign off on.
We turn AI governance frameworks into an operating model that produces evidence a risk committee and auditor can actually use
A nine-chapter field guide for risk leaders taking AI governance from a one-off assessment to a repeatable, sellable practice. Structured across three acts.

Pillar: AI Inventory & Maturity Baselining
Status: Live
Toolkit: AIMA-01, AIMA-02, AIMA-03
Pillar: Vendor & Third-Party AI Risk
Status: Live
Toolkit: Coming soon
Pillar: Data Governance & Consent
Status: Coming soon
Pillar: Framework Adoption · Status: Coming soon
Pillar: Assessment & Evidence · Status: Coming soon
Pillar: Policy & Control Design · Status: Coming soon
Pillar: Practice-Building · Status: Coming soon
Pillar: Executive & Board Reporting · Status: Coming soon
Pillar: Go-to-Market & Growth Strategy for Risk Practices · Status: Coming soon
Frameworks built, not just referenced. Every artefact below started as a real engagement problem — 'how mature are we, really?' — and was generalized into something reusable. Artefacts linked to already-published chapters open as full templates; the rest are reference cards for now.
A practitioner-level introduction to the OWASP AI Maturity Assessment model: its lineage, its business-function layers, and why regulated use cases need it.
A diagnostic tool for scoping an organization's AI risk exposure, including a risk heat map and a sequenced remediation roadmap.
A ten-category set of exploratory questions to ask before running any AI maturity assessment, designed to surface the evidence gaps that a self-reported maturity score usually hides.
End-to-end consent governance framework — discovery through ongoing monitoring — mapped across GDPR, CCPA, LGPD and India's DPDP Act, with block-until-consent technical controls.
Get the next chapter when it drops.
Each month brings one new chapter from the Practice Playbook, paired with the artefact it's built on. If you're a risk leader, CISO, or governance practitioner building out an AI governance capability — this is the signal, not the noise.
Available for advisory engagements and partner-track conversations. If you're building a GRC or AI governance practice and need a practitioner who has done it — let's talk.
And if you want to start your journey on this AI Governance and Risk Management track:
Before you read another chapter, find out where you actually stand. The AI Governance Readiness Assessment scores your organization across all 13 categories this Playbook is built on.
39 questions, about 10 minutes. Your overall maturity score is free and instant.
"Everything you need to establish your AI Governance capability"
© 2026 Runa Dalal. Bengaluru.
AI Governance & Risk Mapping: