Key Takeaways
- Model risk isn’t reduced by policy documents—it’s reduced by controls that observe, enforce, and leave evidence.
- The eight controls below are what AI governance platforms actually operationalize, from inventory to kill switches.
- Each control maps to the frameworks examiners cite: the EU AI Act, NIST AI RMF, and ISO 42001.
Every enterprise has an AI policy by now. Far fewer can point to the mechanism that makes any given sentence of it true. That mechanism is a control—something that observes a system, constrains it, and records what happened. Here are the eight that do the most work in reducing model risk.
1. A Living AI Inventory
The foundational control. Not a spreadsheet updated quarterly—a continuously refreshed AI Bill of Materials covering internal models, vendor-embedded AI, agents, and the datasets behind them. Every other control is scoped by this one, which is why discovery tooling like Cranium’s CodeSensor and Detect AI comes first: an inventory built from self-reporting undercounts, always.
2. Risk Classification Tied to Use, Not Model
The same model is low-risk summarizing meeting notes and high-risk screening job applicants. Classifying by use case—the way the EU AI Act does—keeps oversight proportionate and prevents the two classic failures: strangling harmless uses and waving through dangerous ones.
3. Pre-Deployment Adversarial Testing
Before a system touches production, it should survive structured attack: prompt injection, jailbreaks, data extraction, evasion—the suites codified in MITRE ATLAS and the OWASP Top 10 for LLMs. This is what Cranium Arena automates. A model that has never been attacked by a friend will eventually be attacked by a stranger.
4. Runtime Monitoring With Retention
Model risk is a behavior, not a property—it shows up in production, under real inputs, over time. Continuous model monitoring captures prompts, responses, tool calls, and drift, with retention long enough to reconstruct an incident months later. If you can’t replay what a system did, you can’t defend what it did.
5. Enforced Data Boundaries
The control regulators ask about first: what data can this system see, and what can it emit? Inline enforcement—PII redaction with a verifiable log, blocked categories, tenant isolation—turns a data-handling policy from a promise into a property of the system.
6. Human Checkpoints Where Actions Have Consequences
Agentic systems act. The control is a defined checkpoint: which actions an agent may take autonomously, which require review, and how an approval is recorded. Responsible AI in practice is mostly this—drawing the line between assist and act, and enforcing it.
7. Change Detection on Systems You Don’t Own
Your vendor swaps their underlying model; your exposure changes with no release on your side. A change-detection control—model probing that verifies make and version, alerts on behavioral shift—keeps enterprise AI risk management honest about the AI it merely rents.
8. Evidence Generated by the Controls Themselves
The control that makes audits survivable: every control above should emit its own record. Assessments, test results, monitoring logs, and approvals compose into an exportable artifact—Cranium calls it the AI Card—so proving compliance is retrieval, not archaeology.
Controls Compound
None of these eight stands alone. The inventory scopes the classification; the classification decides the testing; the testing baselines the monitoring; the monitoring feeds the evidence. That’s why AI model governance works as a loop rather than a checklist—and why bolting on one control at a time keeps failing audits that a connected system passes quietly.
Book a demo to see all eight running against a live estate—or explore how the Govern stage of the Cranium platform enforces them continuously.
