The Shielded AI Governance Pathway: A 6-Phase Roadmap for Implementing AI Governance

Six glowing diamond-shaped waypoint markers along a winding path, representing the six phases of the Shielded AI Governance Pathway

Knowing which frameworks exist and where your organization sits on a maturity model still leaves an open question: what order do you actually do things in? The Shielded AI Governance Pathway is our own answer to that question — an original, six-phase implementation methodology developed from what we’ve seen work across engagements. It is not an industry standard, and it doesn’t replace NIST AI RMF, ISO/IEC 42001, or any other framework discussed in our companion post, AI Governance Frameworks Compared. Instead, it’s a practical sequence for putting those frameworks to work, phase by phase, without trying to do everything at once.

Each phase below includes what it’s for, what typically happens during it, what it produces, and which third-party frameworks most directly inform it — because even though the Pathway itself is ours, almost nothing inside each phase is invented from scratch. It draws on the same publicly available frameworks and standards covered throughout this content series.

Phase 1 — Discover

Objective: Build real visibility into what AI is actually in use across the organization. This is the mandatory starting point — you cannot govern, secure, or assess the risk of AI you don’t know exists.

Typical activities: Inventorying known AI tools and platforms, auditing AI features embedded in existing SaaS products, interviewing business units about how they’re actually using AI day to day, and mapping initial stakeholders across IT, security, legal, and the business.

Outputs: A first-pass AI inventory, a stakeholder map, and a rough picture of how widely AI use has already spread — usually wider than expected.

Frameworks that inform it: No framework mandates a specific discovery method, but NIST AI RMF’s Map function and standard asset-management discipline from ISO/IEC 27001 both point toward the same underlying practice: you cannot manage what you haven’t found.

Phase 2 — Assess

Objective: Turn the raw inventory from Discover into a structured understanding of risk — which AI use cases actually matter, and why.

Typical activities: Classifying AI use cases by business impact, data sensitivity, and autonomy; running a gap assessment against a checklist like our AI Governance Checklist; and scoping initial regulatory exposure, including whether the EU AI Act or other regulations apply.

Outputs: A risk-tiered AI use case register, a documented gap assessment, and a prioritized list of what needs attention first.

Frameworks that inform it: NIST AI RMF’s Map and Measure functions and ISO/IEC 23894’s risk-management guidance are the most direct references for structuring this phase’s methodology.

Phase 3 — Govern

Objective: Establish the organizational structure — ownership, policy, and process — that every later phase depends on. Without this, technical controls end up enforcing inconsistent or undefined rules.

Typical activities: Assigning governance roles or standing up a governance committee, drafting and publishing an AI acceptable-use policy, defining an intake and approval process for new AI use cases, and setting a reporting cadence to leadership and the board.

Outputs: A documented governance structure with clear accountability, an approved AI policy employees can actually read and follow, and a working approval workflow for new AI adoption.

Frameworks that inform it: ISO/IEC 42001’s AI management system structure and ISO/IEC 38500/38507’s board-level IT and AI governance principles are the clearest anchors here.

Phase 4 — Secure

Objective: Layer AI-specific security controls on top of the organization’s existing cybersecurity program, rather than building a separate one from scratch.

Typical activities: Extending identity and access management to cover AI systems and their administrative interfaces, addressing LLM-specific risks like prompt injection and insecure output handling, reviewing third-party AI vendors’ security posture, and building an initial AI-specific threat model.

Outputs: AI-specific controls mapped into the existing security program, updated vendor security questionnaires that actually ask about AI, and a documented starting threat model.

Frameworks that inform it: OWASP’s LLM, GenAI, and Agentic Top 10 guidance, the CIS Controls’ AI and LLM companion guides, and NIST CSF 2.0 — including its emerging AI profile — are the primary references for this phase.

Phase 5 — Manage

Objective: Move from a one-time project to an ongoing operational discipline. This is where governance either becomes durable or quietly stops being followed.

Typical activities: Applying lifecycle governance from initial approval through eventual retirement, building AI-specific review into standard vendor procurement, establishing regular reporting to leadership, and tracking AI risk in the enterprise risk register alongside other enterprise risks.

Outputs: A repeatable AI lifecycle process that survives staff turnover, integrated leadership reporting, and AI risk that’s visible in the same risk register as everything else the organization tracks.

Frameworks that inform it: ISO/IEC 42001’s continual-improvement requirements and NIST AI RMF’s Manage function converge here with standard enterprise risk management practice.

Phase 6 — Mature

Objective: Progress from a managed program to an optimized one — continuous monitoring, automated controls where feasible, and governance that explicitly accounts for autonomous AI and AI agents.

Typical activities: Standing up continuous AI monitoring and alerting, scheduling recurring AI red-team exercises, building governance processes specifically designed for agentic AI autonomy levels, and maintaining ongoing tracking of framework and regulatory changes.

Outputs: Automated AI inventory discovery, a sustained red-team cadence, and governance that doesn’t quietly stop applying the moment an AI system starts acting rather than just suggesting.

Frameworks that inform it: MITRE ATLAS for AI-specific threat modeling and red-team scenario design, along with the dedicated cybersecurity track in our AI Governance Maturity Model, are the primary references for this final phase.

How the Pathway Maps to the Frameworks

PhaseObjectivePrimary frameworks referenced
1. DiscoverBuild AI visibilityNIST AI RMF (Map), ISO/IEC 27001 asset management
2. AssessStructure risk understandingNIST AI RMF (Map, Measure), ISO/IEC 23894
3. GovernEstablish ownership and policyISO/IEC 42001, ISO/IEC 38500 / 38507
4. SecureApply AI-specific security controlsOWASP LLM/GenAI/Agentic Top 10, CIS Controls + AI guides, NIST CSF 2.0
5. ManageOperationalize as a lifecycleISO/IEC 42001, NIST AI RMF (Manage)
6. MatureOptimize and cover autonomous AIMITRE ATLAS, AI cybersecurity maturity track

Using the Pathway

The six phases are sequential in the sense that each depends on groundwork from the one before it — you can’t meaningfully assess risk before you’ve discovered what AI is in use, and you can’t secure what governance hasn’t yet defined ownership for. In practice, though, most organizations run phases in overlapping waves rather than waiting for one to fully complete before starting the next, and it’s common to revisit earlier phases as new AI use cases surface.

This methodology is our own framing of how to sequence AI governance work — it draws on the frameworks and standards covered throughout this series without reproducing or claiming ownership of any of them. If you’re earlier in the process, our main guide, AI Governance for Enterprises: A Practical Framework for IT, Cybersecurity, and Risk Leaders, and our AI Governance Checklist are good starting points. If you’d like help applying the Pathway to your specific environment, that’s exactly the kind of engagement our team works on.

Share this article