Guide

How to measure AI governance against a framework

A guide to measuring your AI governance against a recognised framework, choosing the reference, mapping your practice and reading the findings.

How do you measure AI governance against a framework?

Measuring AI governance against a framework means comparing what your organisation actually does to a recognised reference, so you can see where you stand and what is missing. You do it by choosing the framework that fits your obligations and ambition, mapping each of its requirements to your current practice, marking plainly where you meet it, where you partly meet it and where you do not, then reading the findings as the work to do. The measurement is only useful if it reflects practice rather than intention, so it turns on evidence, not on a self-flattering account. This guide sets out how to run that measurement, anchored to ISO/IEC 42001, the NIST AI Risk Management Framework and Australia's Voluntary AI Safety Standard. It is written for the owner who has to report where the program stands, the CRO, the chief audit executive or the governance lead.

Choose the framework that fits

The frameworks answer different questions, so choose by what you need the measurement for. ISO/IEC 42001 is a certifiable management-system standard, so measuring against it suits an organisation heading toward certification or wanting the discipline of a management system. The NIST AI Risk Management Framework, built around its Govern, Map, Measure and Manage functions, is voluntary and outcome-focused, and suits an organisation wanting a risk lens without pursuing a certificate. Australia’s Voluntary AI Safety Standard, with its ten guardrails, is the local reference and maps closely to what an Australian regulator or customer expects to see. Many organisations measure against more than one, because the frameworks overlap heavily and a strong practice satisfies several at once.

Map each requirement to your practice

Measurement is a mapping exercise, so build the map. Take each requirement, guardrail or control of the chosen framework and set against it what your organisation actually does, and crucially the evidence that shows it. A requirement met in practice but unevidenced is not met for the purpose of an outside reader, so record both the practice and the record behind it. Work through the framework in full rather than sampling the parts you are confident about, because the measurement is most valuable exactly where you would rather not look, and a map with the inconvenient parts left off it is not a measurement, it is a reassurance.

Mark plainly and read the findings

For each requirement, mark where you stand, met and evidenced, partly met or not met. Resist the pull toward the generous mark, because the point of the measurement is to find the work, not to feel finished. The findings are the output. Read them for pattern, whether they cluster in scope, in evidence, in the management-system machinery or in lifecycle maintenance, because a cluster tells you where to concentrate. A measurement that produces a tidy result with nothing material to report usually means the marking was soft, not that the program is complete.

Measure again, not once

A single measurement is a snapshot, and a program and its framework both move. Systems change, new AI is adopted and the frameworks themselves are revised. Set a cadence to measure again, so you can show not only where you stand but that you are closing findings over time, which is what a board and an auditor actually want to see. ISO/IEC 23894 frames AI risk management as an ongoing activity across the lifecycle, and the same holds for measurement, a program that measures itself once and files the result is not managing its governance, it is describing a moment.

What a useful measurement produces

  • A clear reference, the framework chosen and why it fits the organisation.
  • Each requirement mapped to current practice and to the evidence behind it.
  • A plain mark against each, met and evidenced, partly met or not met.
  • The findings read for pattern, so the work concentrates where it matters.
  • A cadence to measure again, so progress over time is visible.

Frequently asked questions

Which framework should we measure against? The one that fits your obligations and your ambition. An organisation heading for certification measures against ISO/IEC 42001. One wanting a risk lens without a certificate uses the NIST AI Risk Management Framework. An Australian organisation answering local regulators and customers measures against the Voluntary AI Safety Standard. Because the frameworks overlap, measuring against one usually covers much of another.

Do we need to score our governance to measure it? No, and a single score can hide more than it shows. A measurement is more useful as a map of where you meet each requirement and where you do not, with the evidence beside each, than as a number. The findings, not the score, are what you act on.

How is this different from ISO 42001 readiness? Readiness is a measurement against one specific framework, ISO/IEC 42001, aimed at certification. Measuring against a framework is the general practice, which you can run against any recognised reference and for reasons other than certification, such as board reporting or customer assurance.

Does Aicura score or rate your governance? No. Aicura surfaces the AI footprint and holds the evidence a measurement draws on. It does not score your governance, rate your maturity or decide whether you meet a framework. The measurement is your judgment, and the mark against each requirement is one your people make and own.

Where Aicura fits

Aicura is your AI Register, so a measurement starts from a real and current population of AI systems rather than a partial list, which is where framework mappings most often go wrong. Impact Assessments, the agent records in the AI Register and Incidents hold the practice a measurement maps against, the risk decisions, the agent records and the incident handling, each with the evidence beside it and attributed to its owner.

The Evidence Vault means the evidence behind each mark can be shown unchanged since capture, evidence you don’t have to trust us for, cryptographically anchored and verifiable without Aicura in the loop, so a measurement you report to a board or an auditor rests on records they can confirm. The Trust Centre lets you share that basis, and Attestation lets an owner sign against it. Aicura surfaces the footprint and holds the evidence. It does not score your governance, rate your maturity or decide whether you meet a framework. You make the measurement and own the marks.

For the related work, read ISO 42001 readiness and what is AI assurance. For the practice a measurement maps against, see how to run an AI impact assessment. The AI governance software overview sets out what Aicura supports.

Sources

  • ISO/IEC 42001:2023, AI management system, International Organization for Standardization, iso.org
  • AI Risk Management Framework (AI RMF 1.0), National Institute of Standards and Technology, nist.gov
  • Voluntary AI Safety Standard, Department of Industry, Science and Resources, industry.gov.au
  • ISO/IEC 23894:2023, AI risk management guidance, International Organization for Standardization, iso.org

A note on this page

This guide is general information on how to measure AI governance against a recognised framework. It is not legal advice and it does not tell you whether your organisation meets a particular framework or obligation. For how a framework applies to your organisation, read the primary sources above and take your own professional advice.

When you need to show your work

Aicura is your AI Register, and Pro adds the assurance layer, meaning impact assessments, incident records, attestation and the Evidence Vault, which seals each record so it can be verified without taking anyone's word for it, ours included. Pro is sales-led, so the best next step is a conversation and a walkthrough.