AI governance requires an integrated assessment of governance, risk, technology, data, models, compliance and organisational controls across the AI lifecycle.
Our AI Governance Audit Methodology consolidates the requirements and principles of the EU AI Act, NIST AI RMF, ISO/IEC 42001 and OECD AI Principles, together with relevant Canadian AI requirements and RBI regulatory guidance, into 20 interconnected audit domains. These domains provide a structured basis for examining governance arrangements, accountability, AI risk management, data and model governance, transparency, fairness, human oversight, security, monitoring, regulatory compliance and assurance.
The methodology follows a risk-based and evidence-driven approach, identifying applicable requirements, examining policies and controls, collecting supporting evidence, assessing gaps and recommending practical remediation and improvement measures.
A summary document outlining the 20-domain AI Governance Audit Methodology and its framework alignment is provided below.

AI Governance Audit: 20 Domains Across 6 Frameworks
An overview of our risk-based, evidence-driven AI Governance Audit methodology, covering 20 interconnected governance domains aligned with six leading international and national regulatory frameworks and standards.