Giving In To ‘Control’ — The Moment I Pinpointed AI Governance as My Lane (and What I Did About It.)
No one ever said a path will be straight or a pivot will be straightforward.
Giving In To ‘Control’ — The Moment I Pinpointed AI Governance as My Lane (and What I Did About It.)
No one ever said a path will be straight or a pivot will be straightforward.

3 weeks ago I realized something that I couldn’t ignore — the more I worked through my project, the more I could see that my primary concern was the risk the solution posed to the fictitious organization, and the governance and controls needed to mitigate that risk. My focus was on responsible, safe, and compliant use of the AI solutions as opposed to the actual build and implementation of those solutions — I had to ask myself “Is that even what Solutions Architects do?” — the short answer was “no”.
Put simply, Solutions Architecture is defined as:
“The practice of designing, describing, and managing a comprehensive technical solution — comprising software, hardware, processes, and services — to address specific business problems or needs.”
It’s largely designing for a pain point or opportunity that has been highlighted by an organization (or one that has been uncovered through analysis work), and creating a solution or process, underpinned by technology, that can help the organization eliminate that pain point or take advantage of that opportunity. What I was focused on was governing those solutions and making sure that they had the effective guardrails to make sure they were safe and compliant for the organization and its customers. Potentially over-simplified, yes, but the difference was evident and I had to be intentional about my next steps.
| AI Governance Deep Dive
My first step was truly understanding what AI Governance was and what a professional carrying out the work could look like. I had been rubbing shoulders with the term ‘AI Governance’ since starting AI Architecture training in 2024, the biggest difference now was my curiosity about how AI Governance was actually carried out.
Starting with the definition, AI Governance is defined as:
“The framework of policies, processes, and technical controls used to ensure that artificial intelligence systems are developed and deployed in a safe, ethical, and legally compliant manner.”
Bingo. This was exactly what I had naturally been prioritizing, but not categorizing as ‘AI Governance’.
My next step was deep diving AI Governance: the theory, the practice, the application, and the current impact. I found it simplest to break down the field by what I researched and perceived an AI Governance skills are made up of — the building blocks of an AI Governance professional. This is my opinion that I’ve established from my research into a rapidly developing field, you may not agree, and that’s okay, but this is how I have been developing based on where I see the field going.
| The Building Blocks of an AI Governance Professional
I | IT and Cybersecurity Foundations
The foundation for any technical solution is figuring out how to secure it and keep systems, data, and people safe while using it. Cybersecurity is one of the key concerns of every organization — and that is now amplified with the introduction of AI systems, not decreased.
Why it matters for AI Governance: Cyber and information security is the foundation of AI Governance and needs to be understood to effectively govern AI solutions. Guardrails and constraints are aligned to compliance that is rooted in cybersecurity concerns.
How I’m approaching it: I have taken a deep dive into cyber and information security from the cyber GRC perspective, prioritizing ISO 27001 guidelines, with sights set on certifying in the framework this month. I have also signed up for the ISC2’s Certified in Cybersecurity certification — currently offered for free as an ISC2 initiative to help more people into cybersecurity. (Sign up here by May 20th to get the training course and exam voucher for FREE). The most popular alternative I’ve come across is the Security+ by CompTIA, the choice is down to you, but the knowledge gained is the real key.
II | AI Governance and Policy
We’ve already established that AI Governance is defined as “the framework of policies, processes, and technical controls used to ensure that artificial intelligence systems are developed and deployed in a safe, ethical, and legally compliant manner” — governance is tied to policy and controls, so AI Governance is exactly what it implies, governing AI with effective policies and controls.
Why Policies and Controls matter for AI Governance: They are the methods that are used to enforce governance; creating effective organizational policies around responsible use, assessing for risk management and classification, applying ethical standards and bias mitigation, ensuring data and security protocols, providing transparency and accountability, or managing compliance and external relations (i.e. 3rd party due diligence).
How I’m approaching it: I’ve approached AI Governance by getting to the root of what it is, how it’s applied in practice, and what the AI lifecycle consists of. Over the summer I will be sitting the AIGP, the emerging ‘gold-standard’ for AI Governance, this exam covers the full landscape and is offered by the IAPP.
III | AI System Management
AI System Management addresses maintaining an AI system throughout its lifecycle: the development, deployment, and operation of an AI system.
Why it matters for AI Governance: AI systems degrade — models drift, hallucinations occur, and the overall performance can take a dip. This can negatively affect operational efficiency, regulatory compliance, and overall trust. Formally, AI system management comes in with prescriptive frameworks that break down managing an AI system into key pillars — helping organizations manage AI systems as governed entities.
How I’m approaching it: I’ve gotten familiar with NIST AI RMF for risk identification and ISO/IEC 42001 for modeling an AI Management System, with plans of certification.
IV | Technical Controls and GRC Engineering
Technical controls are the specifications that a system has to adhere to in order to remain compliant, while GRC engineering is the actual Infrastructure as Code (IaC) programming of compliance controls (defined by prescriptive frameworks) into business systems to digitally enforce cybersecurity, information assurance, and AI policies. Technical controls are the “what”, GRC engineering is the “how” — both allow an organization to take the most direct action to automating system compliance enforcement and producing auditable records.
Why it matters for AI Governance: Technical controls and GRC engineering make system governance real-time, repeatable, easily auditable, and as accurate as operationally possible. This reduces manual effort and increases the effectiveness of the governance overall.
How I’m approaching it: I’m training in GRC engineering and preparing for the **Certified GRC Engineer — Practitioner certification with the [GRC Engineering Club](https://grcengclub.com/learn/grc-engineering-101)**. I have been building my foundation in cloud and Infrastructure as Code, so layering on Compliance as Code, Policy as Code, and evidence pipelines feels like natural progression. Of course there is a learning curve, but it feels approachable — especially with the support to learn.
V | Framework Fluency
‘Fluency’ may be a strong word here, but it feels more accurate than ‘familiarity’. Compliance is compliance, so getting acquainted with regulations and frameworks that affect business is key. My focus has been reviewing ISO 27001, ISO/IEC 42001, NIST AI RMF, EU AI ACT, NIST 800–53, and other frameworks, control-by-control.
Why it matters for AI Governance: Knowing the frameworks that shape AI governance and how their controls map to business systems underpins the practice of governance. The understanding helps with writing company policies, designing governance programs, and exchanges with auditors.
How I’m approaching it: I’m reading the frameworks and regulations, there’s no way around it. I have simplified the process by creating study packs with Claude (happy to share, drop me a message on LinkedIn), but “the work is the work”.
Everything I’ve outlined above is permissible to IT and cybersecurity GRC. I chose to speak directly about AI Governance because that is my destination, but I am learning across the board because there isn’t much separation.
So what now? There is plenty on my plate and I’m having a ball working through it all. I have redefined my projects and will be sharing them soon. In the meantime, I am looking forward to more inspiring conversations, study sessions, and gaining my first few certifications.
If this resonates or if you are already on a GRC or AI focused path — **let’s connect**! I have met so many amazing people across the fields over the past few weeks, I’m looking forward to making more connections.
메타데이터
- post_id
- 69c2f2bf83bb
- slug
- giving-in-to-control-the-moment-i-pinpointed-ai-governance-as-my-lane-and-what-i-did-about-it-69c2f2bf83bb
- url
- https://medium.com/@mercedes-edwards/giving-in-to-control-the-moment-i-pinpointed-ai-governance-as-my-lane-and-what-i-did-about-it-69c2f2bf83bb
- canonical_url
- https://medium.com/@mercedes-edwards/giving-in-to-control-the-moment-i-pinpointed-ai-governance-as-my-lane-and-what-i-did-about-it-69c2f2bf83bb
- author_url
- https://medium.com/@mercedes-edwards
- status
- ok
- fetched_at
- 2026-06-09 15:37:30