Building a unified governance programme from scratch

A step-by-step approach to scope, controls, evidence and ongoing assurance — designed to be scalable across domains.

The iComply Team
AI Governance

Unified Governance Programme

Whether you’re setting up governance for the first time — or tidying up a jumble of spreadsheets — it’s tempting to start with a framework. Don’t do that. Start with an architecture into which all the frameworks fit. Here’s a sequence that scales.

1. Scope prior to the standards

Define what you are managing — entities, systems, data, suppliers — before choosing frameworks. The scope determines everything else and helps you avoid the classic mistake of certifying one aspect whilst leaving the real risk out of the picture.

2. Build a library of controls, not a checklist

Create a single library of operational controls. Frameworks map down to these controls; the controls map up to various frameworks. It is this decision that determines whether any duplication of work ever occurs.

3. Assign responsibility

Every control needs a person in charge and a schedule. Governance fails when controls are the responsibility of ‘everyone’. Link the people in charge to notifications so that any outstanding work is automatically highlighted.

4. Collect evidence once

Attach supporting evidence to the controls and reuse it across all frameworks that reference them. The version history is non-negotiable — auditors place greater trust in a clear audit trail than in a voluminous dossier.

5. Take risks alongside controls

Link risks to the controls that mitigate them. A risk register that exists in isolation from the controls becomes a document that nobody reads; one that guides the prioritisation of controls becomes the driving force behind the programme.

6. Ensure the guarantee remains in force

  • Out-of-date evidence speaks for itself.
  • The backlog of tasks is growing.
  • The growing risk prompts a review.
  • Audits draw on the same ongoing controls.

7. Expand by mapping, not by reconstruction

Once the architecture is in place, adding NIS2, the AI Act or ESG reporting is simply a matter of mapping. The second framework is dramatically cheaper than the first — exactly the opposite of what happens with single-standard tools.

Build the architecture first, and every framework you add will make the programme more robust rather than more cumbersome.

Here’s how iComply puts this into practice

A platform for every regulation, law and risk — focused on controls and powered by AI.

Read on

Two interconnected circles representing the relationship between the ISO 42001 standard and the European AI Regulation

A management system meets a regulation — and why you operationalise both as a single AI governance suite.

Bar chart showing salaries within a defined range, illustrating an analysis of the gender pay gap at iComply

Analysis of pay gaps, pay bands and auditable remuneration criteria — what to implement now.

One evidence document linked to three requirements from different frameworks, demonstrating evidence reuse in iComply

Stop duplicating documents. Map the supporting evidence once and let it fulfil all the requirements that refer to it.