

Translating AI governance expectations into implementable, auditable, proportionate enterprise controls.
With built in Forward and Reverse mapping with Regulatory and key frameworks
88 controls with forward and reverse mapping aligned to NIST, ISO, EU AI Act and ICFR expectations

A comprehensive, framework-aligned architecture spanning the full AI governance lifecycle — from oversight and data integrity to ethics, resilience, and auditability.
Designed for progressive adoption across AI maturity stages — establishing foundational governance and use case control.
Embedding monitoring, auditability, and ICFR-aligned assurance as AI scales.
Every regulatory obligation is traceable to a control.
Every control is defensible against regulation.
GuideNet control objectives aligned to framework clauses and regulatory articles.
Regulatory obligations traceable back to specific enterprise control objectives.
The GuideNet Enterprise AI Control Architecture can:
Detailed breakdown of core control objectives across key layers:
Domain 01 - Governance and Oversight
GV 06 - Maintain AI Use Case Inventory and Risk Classification: Central register of all AI use cases and models with owner, purpose, criticality, data categories, third parties, ICFR relevance, lifecycle stage, and risk classification. Quarterly certification by owners.
Mapped to:
Domain 02 - Data Governance and Lineage
DG 01 - Ensure datasets used for training and testing have documented provenance and lineage: Maintain dataset inventory with source, owner, and purpose; evidence approvals for data ingestion; store lineage records in a central repository accessible to audit teams.
Mapped to:
Domain 03 - Model Transparency and Explainability
MT - 05 - Ensure auditability of AI decisions: Capture decision-level logs with timestamp, inputs, outputs, and model version; protect logs from alteration; provide access to auditors and regulators on request.
Mapped to:
SA 04 - Ensure AI systems have kill-switch/fail-safe protocols: Maintain kill-switch procedures for disabling compromised models; test kill-switch annually; evidence test results in governance logs.
Mapped to:
AC 08 - Ensure a formal go or no-go decision is taken before deployment: A gated readiness review checks intended purpose, acceptance criteria, pilot or sandbox results, risk and control completion, and sign-offs from product owner, risk, legal, and security. Go or no-go outcome recorded in governance minutes and evidence repository.
Mapped to:
EA 04 – Provide external stakeholders confidence in AI systems and controls: Commission external assurance for high-risk AI systems; scope aligned to NIST/ISO/AI Act; evidence assurance reports and management responses.
Mapped to:
From obligation or standard requirement to GuideNet control IDs
Govern 1.6 - Mechanisms are in place to inventory AI systems with resources aligned to priorities.
Reverse mapping to architecture controls:
Clause 8.6 - Manage data across the AI lifecycle.
Reverse mapping to architecture controls:
Article 25 - Data protection by design and default.
Reverse mapping to architecture controls:
Article 10 - Ensure training, validation, and testing datasets are relevant, representative, free of errors, and appropriately governed.
Reverse mapping to architecture controls:
Request the complete architecture, including forward
and reverse mapping.
Connect and message:
Explore more:
The content presented in this publication is provided for informational and professional development purposes only. It reflects the authors' professional judgment at the time of publication and does not constitute legal, regulatory, audit, compliance, or other professional advice.
This material may reference or draw conceptual alignment from publicly available frameworks and guidance, including but not limited to the NIST AI Risk Management Framework, ISO/IEC 42001, the EU Artificial Intelligence Act, the UK Corporate Governance Code, and other relevant standards. Such references are provided solely for context. GuideNet.ai and the authors make no representation of compliance with, endorsement by, or affiliation to any such frameworks, regulatory bodies, or standards-setting organisations.
This publication does not represent a complete or definitive set of controls for any organisation, jurisdiction, or regulatory requirement. It is not intended to be relied upon as the sole basis for governance, compliance, audit, or assurance decisions.
Users are responsible for assessing the relevance and applicability of the content in the context of their specific organisational, regulatory, legal, and operational environments. Controls and approaches should be tailored to reflect the nature, scale, and complexity of AI use cases and the existing control environment.
Any actions or decisions taken based on this material are undertaken at the user's own risk. To the fullest extent permitted by law, the authors and GuideNet.ai disclaim all liability for any loss or damage arising from reliance on or use of this publication.
All rights, including copyright and intellectual property rights, in and to this publication are reserved by the authors and GuideNet.ai. No part of this material may be copied, reproduced, distributed, adapted, or disclosed to third parties in any form or by any means without prior written consent.
