United States / AI governance
AI governance
that reaches production.
For US organisations, sovereignty means enterprise control: portable architecture, explicit permissions, testable risk decisions and evidence that supports security and assurance review.
Govern. Map. Measure. Manage.
N137.AI maps a production system to the four functions of NIST AI RMF 1.0 and uses the Generative AI Profile where relevant. NIST describes the framework as voluntary; it is used here as an operational control structure, not a compliance certificate.
Connect AI evidence to enterprise assurance
AI controls are mapped to the organisation’s existing security, privacy, procurement and change-management processes. Where a SOC 2 examination or sector review is relevant, we prepare architecture facts and control evidence for the responsible auditor; N137.AI does not issue attestations.
Production control set
- AI system inventory and accountable owners.
- Data and model provenance, permissions and retention.
- Evaluation thresholds and human intervention policy.
- Prompt, tool, model and configuration change records.
- Incident, rollback and provider-exit procedures.
- State, sector and contractual requirements scoped with counsel.