Writing about AI governance by people who have to implement it.
No maturity curves, no vendor scorecards. Each piece takes one hard question in AI governance, risk or assurance and answers it in a way you can act on this quarter.
Most governance tooling asks whether you are compliant with a framework and answers with a number. That question cannot be audited. Here is the one that can, the nine-link chain behind it, and what it costs to answer honestly on day one.
Adopting ISO 42001 after NIST AI RMF should add a view, not a backlog. What it takes to hold one internal control library and map every standard onto it.
A percentage is a weighted average of things that are not commensurable. Mapped, covered, partially covered, evidence pending and not assessed are the only honest states.
A deterministic gate is only useful if the verdict carries its reasoning, and if a PASS invalidated by later change raises new work instead of being quietly edited.
Licence checks, content pack delivery, model providers and telemetry are the four places an on-premise governance tool quietly assumes the internet. Each one is solvable.