AI Governance & Risk Mapping:

Know Every AI System. Know Its Risk. Prove It's Governed.

See IT, Govern IT, Scale IT

This Practice Playbook is a field guide for Cyber Risk and Governance leaders taking AI governance from a one-off assessment to a repeatable practice. Nine chapters, structured in three acts: See It (map what you're actually exposed to), Govern It (turn that map into defensible controls), Scale It (turn the practice into something you can offer and sell). Every chapter ships with a working artefact from the toolkit below — a template, a question bank, a scoring model — so each idea comes with something you can actually run, not just read. This is published work, not a pitch. Frameworks built for real engagements, generalized and shared because governance gets better when the tools behind it aren't kept behind closed doors. The Acts II & III will soon be updated here, so stay tuned for that.

A working toolkit of AI governance frameworks, risk assessments, and practice-building strategy — built by a practitioner and sharpened through real engagements, turning regulatory pressure into governance programs that pass audit, and AI adoption into something a risk committee can actually sign off on.

We turn AI governance frameworks into an operating model that produces evidence a risk committee and auditor can actually use

ISO/IEC 42001 NIST AI RMFOWASP AIMAEU AI ACT
Explore the Toolkit

The Practice Playbook — Nine Chapters

A nine-chapter field guide for risk leaders taking AI governance from a one-off assessment to a repeatable, sellable practice. Structured across three acts.

Act I — See It

Chapters 01–03: AI Inventory, Vendor Risk & Data Governance

Chapter 01 — You Can't Govern What You Haven't Mapped

Pillar: AI Inventory & Maturity Baselining

Status: Live

Toolkit: AIMA-01, AIMA-02, AIMA-03

Chapter 02 — Borrowed Risk: Governing AI You Didn't Build

Pillar: Vendor & Third-Party AI Risk

Status: Live

Toolkit: Coming soon

Chapter 03 — Data Governance & Consent in the Age of AI

Pillar: Data Governance & Consent

Status: Coming soon


Act II & Act III — Govern It & Scale It- Coming Soon

Act II — Govern It

Chapter 04 — Adopting OWASP AIMA and the NIST AI RMF

Pillar: Framework Adoption · Status: Coming soon

Chapter 05 — Maturity Scoring & Evidence

Pillar: Assessment & Evidence · Status: Coming soon

Chapter 06 — Policy & Control Design for AI Systems

Pillar: Policy & Control Design · Status: Coming soon

Act III — Scale It

Chapter 07 — Turning a Framework into a Practice Offering

Pillar: Practice-Building · Status: Coming soon

Chapter 08 — Selling Governance to a Board That Doesn't Speak Risk

Pillar: Executive & Board Reporting · Status: Coming soon

Chapter 09 — The Case for the Business

Pillar: Go-to-Market & Growth Strategy for Risk Practices · Status: Coming soon


Artefact Register — The Toolkit (Updates as new chapters release)

Frameworks built, not just referenced. Every artefact below started as a real engagement problem — 'how mature are we, really?' — and was generalized into something reusable. Artefacts linked to already-published chapters open as full templates; the rest are reference cards for now.

A practitioner-level introduction to the OWASP AI Maturity Assessment model: its lineage, its business-function layers, and why regulated use cases need it.

NIST AI RMFEU AI ActPresentation-ready

A diagnostic tool for scoping an organization's AI risk exposure, including a risk heat map and a sequenced remediation roadmap.

Maturity ScorecardPresentation-ready

A ten-category set of exploratory questions to ask before running any AI maturity assessment, designed to surface the evidence gaps that a self-reported maturity score usually hides.

Pre-assessmentWorking Document

GRC-04 — Eight-Stage Cookie & Consent Deployment Workflow(Coming Soon)

End-to-end consent governance framework — discovery through ongoing monitoring — mapped across GDPR, CCPA, LGPD and India's DPDP Act, with block-until-consent technical controls.

Multi-jurisdictionField-tested

Get in Touch

Runa Dalal — Cyber Risk & AI Governance Advisory

Get the next chapter when it drops.

Stay in the Loop

Each month brings one new chapter from the Practice Playbook, paired with the artefact it's built on. If you're a risk leader, CISO, or governance practitioner building out an AI governance capability — this is the signal, not the noise.

Advisory & Partnerships

Available for advisory engagements and partner-track conversations. If you're building a GRC or AI governance practice and need a practitioner who has done it — let's talk.

Bengaluru, IndiaAvailable for Advisory

And if you want to start your journey on this AI Governance and Risk Management track:

Take the Readiness Assessment

Before you read another chapter, find out where you actually stand. The AI Governance Readiness Assessment scores your organization across all 13 categories this Playbook is built on.

AI Inventory

Ownership & Accountability

Governance

AI Risk Classification

Policies

Lifecycle Controls

Third-Party AI

Data & Privacy

Security

Human Oversight

Regulatory Readiness

Evidence & Audit Readiness

Board Reporting

39 questions, about 10 minutes. Your overall maturity score is free and instant.


"Everything you need to establish your AI Governance capability"

© 2026 Runa Dalal. Bengaluru.