AI Lifecycle GRC Integration
Unlock the complete study guide + 1,040 practice questions across 16 full exams.
Bundled into the existing CompTIA SecAI+ premium course — no separate purchase.
14-day money-back guarantee — no questions asked.
Included in this chapter:
- Where governance attaches to the AI lifecycle
- Who owns what before any artefact exists
- The AI inventory and use-case register
- Assessing AI risk and recording the decision
- TEVV and the gates it feeds
- Third-party models, data and suppliers
- Re-approval when the model or its inputs change
- Post-deployment duties, from monitoring to retirement
- Internal audit, management review and evidence
- Exam-pattern recognition
What each AI RMF function contributes to the governance loop
| Aspect | GOVERN | MAP | MEASURE | MANAGE |
|---|---|---|---|---|
| Question it answers | Who decides, under which policy, with what authority? | What is this system, where is it used, and what could go wrong? | How good is it, against which criteria, judged by whom? | What do we do about the risks that were found? |
| When it runs | Continuously, around the other three | At intake, and again whenever the system or its context changes | Before release and continuously in production | After MAP and MEASURE, and on every incident |
| Artefact it produces | Policy, accountability chart, risk tolerance statement, inventory mechanism | Register entry: intended purpose, context, affected people, impact and likelihood | Test sets, metrics, evaluation records, monitoring output | Treatment decision, owner sign-off, residual-risk record, incident and retirement actions |
| Who typically owns it | Senior leadership and the AI governance committee | The model owner, with domain, privacy and legal input | Evaluators who did not build the system | The named risk owner |
| What breaks if you skip it | Decisions carry no authority and no consistent line | Unlisted systems and unknown use cases, which is shadow AI | Approval rests on opinion instead of measured evidence | Findings pile up with nobody accountable for closing them |
Decision tree
Cheat sheet
Unlock with Premium — includes all practice exams and the complete study guide.
Also tested in
References
- AI Risk Management Framework (AI RMF 1.0, NIST AI 100-1) Whitepaper
- AI RMF Core: the GOVERN, MAP, MEASURE and MANAGE functions with their categories and subcategories Whitepaper
- NIST AI 100-1: Artificial Intelligence Risk Management Framework (AI RMF 1.0), full text Whitepaper
- EU AI Act Article 9: Risk management system
- EU AI Act Article 72: Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems
- EU AI Act Article 17: Quality management system
- NIST AI RMF Playbook: GOVERN function suggested actions and documentation Whitepaper
- LLM AI Cybersecurity and Governance Checklist, version 1.1 Whitepaper
- NIST IR 8286Ar1: Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management (supersedes IR 8286A) Whitepaper
- EU AI Act Article 73: Reporting of serious incidents
- ISO/IEC 42001:2023, Information technology - Artificial intelligence - Management system Whitepaper