The design layer for AI governance.
Every regulation, standard and client contract you answer to, resolved onto one set of controls — so you can see what is covered, what actually runs, and what is missing.
Built by AI Career Pro, who have trained over a thousand AI governance practitioners.
EU AI Act
ISO/IEC 42001
Client MSA
The problem
Everyone owns a piece. Nobody owns the join.
Legal reads the obligation. Engineering builds the system. Risk keeps the register. Each does its part in a different tool — and the space between them, where a requirement becomes a control and a control becomes something that actually runs, belongs to no one.
That join is where governance quietly stops working.
Nowhere to see the whole
Requirements sit in one tool, registers in another, control tracking in a third. Everyone can describe their slice. Nobody can draw the system.
Built for a moment that has passed
Regulations move. Systems move. Governance designed around a single snapshot starts failing the day after it is signed off.
Controls with nothing behind them
Frameworks tell you what to control. They rarely tell you how. A control with nothing running behind it is a sentence in a policy.
The chain
From a clause on a page to a process that runs.
An artefact with nothing extracted from it is a document. An expectation with no control is a wish. A control with no mechanism is a sentence in a policy.
Artefacti
EU AI Act, Article 9
The document that governs you — a regulation, a standard, a client contract.
Expectationii
“Establish, implement, document and maintain a risk management system.”
The individual clause, pulled out and classified by what it actually demands of you.
Controliii
Risk Assessment
One control, answering the same expectation across three separate frameworks. This is where the work stops multiplying.
Mechanismiv
Risk Classification Process
Inputs, outputs, owner, tooling, metrics. The part that actually happens.
Running
Add a fourth artefact next year and most of it lands on controls you already built. The second framework costs a fraction of the first.
Nexus
Map what governs you.
Bring in every artefact you answer to, map its clauses onto a single control set, and watch coverage build across all of them at once.
BoardEU AI Act × Control set
2 editing
Then read it as coverage.
The same board, turned on its side: every expectation you have taken on, against every control you have designed.
Expectation
Risk assessment
Data governance
Documentation
Logging
Human oversight
Incident response
State
EU AI Act
Art. 9(1)Risk management system
Implemented
Art. 10(2)Data and data governance
Implemented
Art. 11Technical documentation
Covered
Art. 12Record-keeping
Implemented
Art. 14Human oversight
Covered
ISO/IEC 42001
6.1.2AI risk assessment
Implemented
8.3AI system impact assessment
Covered
Client MSA
Sch. 3 §4Incident notification within 24h
Gap
Sch. 3 §7Audit rights and evidence
Covered
GapNothing mapped to it yet
CoveredA control is mapped
ImplementedA mechanism runs it
No undefined middle.
Bring in an artefact
Drop in a regulation, standard or client contract as a PDF. You get back a structured clause tree, with each leaf classified by what it demands.
Map it to controls
Point every clause at your control set. When three frameworks want the same risk assessment, that is one control with three mappings — not three workstreams.
Read the crosswalk
Every expectation resolves to one of three states. Nothing is allowed to sit in an undefined middle.
Work it together
Legal knows the obligation, engineering knows what is feasible. Shared boards, live cursors, and the argument happening on the artefact itself.
Mechanic
Design the mechanism behind the control.
A policy line says what should happen. A mechanism says what consumes what, who owns it, how you measure it, and whether it is working right now.
Mechanism
Risk Classification Process
4 of 7 functioning
- Inputs
- What sets it off, and what it consumes
- Functioning
- Outputs
- What it produces, and who receives it
- Functioning
- Objective
- The controls it claims to satisfy
- Partial
- Scope
- Which AI systems it applies to
- Functioning
- Tooling
- The tools, and the ordered playbook
- Partial
- Metrics
- Leading and lagging, with targets
- Absent
- Ownership
- A named person, not a function
- Functioning
If you cannot name who owns it and how you would know it stopped working, it is not a mechanism yet.
Scored separately, so a missing owner cannot hide behind a well-written scope.
Health, part by part
Each of the seven scores on its own. A mechanism with no owner and no metrics reads as critical, instead of being averaged into a comfortable number.
Chains
Wire one mechanism’s output into another’s input. When a link breaks, you can see everything downstream of it.
Branches
Fork a mechanism, redesign it in isolation, open it for review. The diff warns which chain connections a merge would break.
Live metrics
Push measurements in over the API, upload a CSV, or type them in. The same numbers drive the health badges and your dashboards.
The method
Adaptive governance.
Governance that senses change, catches emerging harm early, responds quickly, and improves its own controls as it goes.
Cruise, HireVue and South Wales Police all had governance structures. Each was designed around a snapshot, and then the ground moved underneath it.
Good intentions never work. You need good mechanisms to make anything happen.
Jeff Bezos
Founder
James Kavanagh
Formerly leader of the Responsible AI team at AWS. The method came out of watching governance work, and fail, at scale — and it is the same method a thousand practitioners have now been trained on. Read the full approach
Seven principles we teach and build around
- Design-first
- Safety is a property that emerges from how a system is built. It cannot be bolted on afterwards.
- Mechanisms
- Defined inputs, real tooling, a named owner, and a loop that improves it over time.
- Safety culture
- People report problems only when they trust the system to treat them fairly.
- Balcony and dance floor
- See the whole system from above, and understand how it behaves where the work is actually done.
- Vertical connectivity
- Bad news has to travel upward fast. In most organisations it is softened at every layer.
- Technical and adaptive
- Some problems have an expert answer. Others need behaviour to change. Misdiagnose which is which and you lose years.
- Approachable
- Governance cannot live inside a specialist function. It has to reach the people creating the risk.
The Academy
The school that teaches this is inside it.
AI Career Pro delivers its courses through Balcony — so you learn the method in the same place you will use it, next to the boards you are going to apply it to. See the Academy
- Courses
- The full AI Career Pro curriculum, including AIGP exam preparation and the Practitioner Program — the same programme a thousand practitioners have already come through.
- Open now
- Skills
- Short and fully interactive. Watch the method, practise it, defend your work to an AI playing your CEO, and finish with a capstone you could use on Monday.
- New
- Exams
- Full practice papers for the certifications, sat against the clock — or opened in study mode, marked question by question with the reasoning.
- Open now
Who it is for
Wherever you are starting from.
Governance and responsible AI leadsyou already know what needs to happen. You need somewhere to design it, show it, and prove it runs.
Consultants and advisorsa separate workspace per client, a curated control framework to start from, and a method you can hand over at the end.
Given AI governance on top of your day jobnobody trained you for this. Start in the Academy, then build your first board while the method is still fresh.
Moving into the fieldcareer changers, students and engineers, on the same curriculum a thousand practitioners have already taken.
Start with one board.
Pick a regulation you are actually subject to, map it, and see what comes back.