Mithun SanghaviMITHUN SANGHAVI
← All tools

AI Governance Framework

AI Baseline Control Framework

Manage & govern AI use in your organization. The AI Baseline Control Framework (AI BCF) is a free, open framework of 20 AI governance controls for organizations that deploy (use) AI. Each control is mapped to the NIST AI RMF, ISO/IEC 42001 and the EU AI Act. The AI BCF helps organizations of all sizes understand what is necessary to manage & govern AI deployment.

Who this is for

This framework is for deployers (users) of AI systems, who are looking for a practical, risk-based and understandable way to understand, manage and govern AI use within their organization. This framework can be used by CISOs, IT Directors, AI Officers and/or other relevant professionals.

Five categories

The 20 controls are grouped into five clear categories, covering AI governance from policy down to the day-to-day tracking of deployed AI systems:

Govern
Policy, roles, training and the risk management process. Ensures AI use in an organization has an owner and that a shared understanding of what is and isn't allowed exists and is understood within the organization.
Comply
The legal and regulatory obligations that follow directly from using AI: knowing which laws apply, marking AI-generated content, and the extra steps required around higher-risk uses.
Register
What AI is deployed, for what purpose, and how proportionate it is to the task. The register is what makes the rest of the framework possible to check in the first place.
Access
Access rights for AI systems themselves, not only for the people who use them. AI that acts with its own credentials or autonomously needs the same access discipline as any other account.
Track
How deployed AI actually performs once it's in use: effectiveness, internal feedback and errors, collected so the organization's understanding of AI risk and effectiveness is based on proven metrics.

Reflects EU law as of October 2026: the EU AI Act as amended by Regulation (EU) 2026/1744. This framework is not legal advice.

Three control types

There are three types of controls. The type determines whether and when it applies to your organization:

Baseline
Applies to every organization that uses AI, regardless of size or sector.
Tier II
Optional extra depth on top of the baseline. Organizations with more mature AI governance, or more exposure, may choose to adopt these for more thorough control over AI than the baseline alone provides.
Trigger
Applies only once the specific trigger condition stated in the control is true. If that condition doesn't apply to an organization, the control doesn't apply either. Check the trigger text on each control.

Controls

All controls

20 controls across five categories.

Category

Type

20 of 20 controls

Govern

Policy, roles, training and the risk management process. Ensures AI use in an organization has an owner and that a shared understanding of what is and isn't allowed exists and is understood within the organization.

Comply

The legal and regulatory obligations that follow directly from using AI: knowing which laws apply, marking AI-generated content, and the extra steps required around higher-risk uses.

Register

What AI is deployed, for what purpose, and how proportionate it is to the task. The register is what makes the rest of the framework possible to check in the first place.

Access

Access rights for AI systems themselves, not only for the people who use them. AI that acts with its own credentials or autonomously needs the same access discipline as any other account.

Track

How deployed AI actually performs once it's in use: effectiveness, internal feedback and errors, collected so the organization's understanding of AI risk and effectiveness is based on proven metrics.