Duplication of Effort
Risk, security, and compliance teams all build controls for the same AI system independently (typically unaware of each other). This leads to three versions of the same assessment, all incomplete.
RESAIA closes the gap that fragmented governance leaves open across every discipline that touches AI. One practical body of knowledge, a family of role-based certifications, and a maturity model give organisations and practitioners a coherent way to govern AI responsibly, in practice.
Five Failure Patterns
Risk, security, and compliance teams all build controls for the same AI system independently (typically unaware of each other). This leads to three versions of the same assessment, all incomplete.
Roles are on paper but not tied to the systems people work in. So, when something goes wrong, there is a policy that covers it but no one responsible for applying it.
Principles are approved by the boards that never reach the engineering teams who build models. The people writing policy and the people laying down code rarely operate from a common document.
Audit trails exist in other tools owned by teams too and have different formats. For any given system, reconstructing what actually happened takes weeks, not minutes.
Systems are assessed one by one. No single person or team currently has a view of how many AI systems the organisation is operating, let alone what each actually does.
It is not the only gap
Existing frameworks name the right principles but stop short of mechanism. They establish that fairness matters without saying how to measure it, and were written for conventional IT rather than model drift, foundation-model supply chains, or agentic systems.
The major governance traditions are each strong precisely where the others are weak, yet the market presents them as competing choices. Organisations are forced to pick a centre of gravity and improvise the rest.
No widely adopted framework makes governance traceable end to end, from board risk appetite to the audit finding that verifies it. Maturity tools score domains in isolation, missing how weakness in one undermines another.
How RESAIA closes the gaps
Closes the orchestration gap
Assigns clear scope to every governance domain, defines the interfaces between them, and creates the bidirectional artefact flows that turn fourteen siloed functions into one accountable system.
Closes the operational-control gap
Carries named methodologies, artefacts, and lifecycle gates into every domain, so principles become testable controls rather than aspirations.
Closes the synthesis gap
Integrates risk-based, management-system, and control-based traditions into one architecture, instead of forcing organisations to pick a centre of gravity and improvise the rest.
Closes the evidence gap
Connects governance end to end, from a board-level risk appetite declaration, through the controls that implement it, to the audit finding that verifies it.
A system-centric shift
Moves the unit of governance from the individual model to the system, and ultimately to the AI capability that spans technology, people, processes, and providers.
The Framework
The framework brings together every discipline that touches AI into a single architecture. Governance sets the direction. Safeguard protects the work. Operate executes it. Assure verifies it. Lastly, Enable runs across all of them, providing the platform, engineering, and culture that make the architecture operational.
Resaia AIG Framework
Directives flow from each architectural layer into its governance pillars, and evidence flows back from those pillars to the layer.
Why Govern?
Directives flow from each architectural layer into its governance pillars, and evidence flows back from those pillars to the layer.
How Protected?
Identifies and rates AI-specific risk across the portfolio.
Protects AI systems against the failure modes unique to them.
Governs the data an AI system is trained on and the data it produces.
Extends governance to vendors, model providers, and embedded AI.
Directives flow from each architectural layer into its governance pillars, and evidence flows back from those pillars to the layer.
What Executes?
Directives flow from each architectural layer into its governance pillars, and evidence flows back from those pillars to the layer.
Is It Working?
Makes clear how and why a system reached a given output.
Tracks whether a deployed system still performs as intended.
Defines what happens when an AI system fails or causes harm.
Independently verifies that governance is actually applied.
Each domain is scored on its own rather than averaged into a single number. Lifecycle gates cannot operate above the maturity of the risk assessments that feed them, so strength in one domain does not compensate for weakness in another it depends on.
Governance depends on individual initiative. No documented policy exists, and activity follows incidents rather than preceding them.
Policy is approved but covers a subset of the portfolio. Requirements are documented without being systematically enforced.
Methodology is documented, approved, and applied consistently across the portfolio.
First stable plateau
Performance is measured against defined targets. Evidence-based decision replaces judgement-based assessment.
Governance adapts to emerging capability and regulatory change before adaptation is required.
The Body of Knowledge
The Body of Knowledge is the architecture made operational. It teaches AI governance as one connected practice, across every domain that touches AI, at a depth that lets organisations plan it, implement it, and monitor it. Each chapter sets out what the discipline does, the risks it faces, the roles that hold it, the evidence it produces, the metrics that track it, and the maturity it grows into.

The Certifications
RESAIA certifications attest professional mastery of the discipline. Start with the foundational credential that spans the full architecture. Specialise into the domain that matches the work you do.

Covers the full scope of AI governance; risk, compliance, security, ethics, and legal as one connected discipline. The starting point for anyone entering or working in AI governance.

AI risk identification, assessment, treatment, and monitoring. Including risks specific to AI such as bias, drift, hallucination, and emergent behaviour in agentic systems.

Threats to AI systems, including adversarial inputs, data poisoning, prompt injection, and model extraction, and the security controls to address them across the AI lifecycle.

Independent audit of AI systems, programme design, evidence collection, compliance verification, and conformity assessment.

Data quality, lineage, privacy, and protection obligations across the AI data lifecycle, from training data through to model outputs.

AI vendor evaluation, supply chain risk, model provenance, and governance of third-party AI systems and foundation models.
Find your path
Individuals certify against the discipline they own. Organisations assess where they stand and build toward where they need to be. Both start from the same body of knowledge.
Executive committees, board directors, and policy makers responsible for AI strategy, risk appetite, and accountability at scale, plus the data scientists and ML engineers who need the full governance picture before specialising.
Chief risk officers, heads of compliance, and the teams responsible for AI risk methodology, assessment, and enterprise reporting.
CISOs, AI security engineers, and red teams defending AI systems against adversarial inputs, data poisoning, prompt injection, and model extraction.
Data protection officers, privacy leads, and data governance teams managing data quality, lineage, and protection across the AI data lifecycle.
Internal and external auditors, conformity assessment bodies, and regulators applying the same architecture as the organisations they oversee.
Procurement leads, vendor managers, and governance teams evaluating third-party AI systems, supply chain risk, and model provenance.
RESAIA exists to make that practice measurable, teachable, and accountable. It gives every discipline that touches AI a shared structure, a shared language, and a shared standard to measure against.