Skip to main content

The Global Professional Body forResponsible AI Governance

RESAIA closes the gap that fragmented governance leaves open across every discipline that touches AI. One practical body of knowledge, a family of role-based certifications, and a maturity model give organisations and practitioners a coherent way to govern AI responsibly, in practice.

Five Failure Patterns

Five patterns of failure that are common to all organisations implementing AI without oversight.

Four governance teams separately assessing the same AI system.

Duplication of Effort

Risk, security, and compliance teams all build controls for the same AI system independently (typically unaware of each other). This leads to three versions of the same assessment, all incomplete.

Governance teams surrounding an AI risk with no clear owner.

Accountability Voids

Roles are on paper but not tied to the systems people work in. So, when something goes wrong, there is a policy that covers it but no one responsible for applying it.

A disconnected path between board governance and the engineering team.

Government-Execution Disconnect

Principles are approved by the boards that never reach the engineering teams who build models. The people writing policy and the people laying down code rarely operate from a common document.

Several evidence sources feeding an incomplete governance report.

Fragmented Evidence

Audit trails exist in other tools owned by teams too and have different formats. For any given system, reconstructing what actually happened takes weeks, not minutes.

Disconnected AI systems surrounding an unmonitored portfolio overview.

Portfolio Blindness

Systems are assessed one by one. No single person or team currently has a view of how many AI systems the organisation is operating, let alone what each actually does.

It is not the only gap

Orchestration is the most visible failure. Three further gaps recur

The operational-control gap

Existing frameworks name the right principles but stop short of mechanism. They establish that fairness matters without saying how to measure it, and were written for conventional IT rather than model drift, foundation-model supply chains, or agentic systems.

A principles document connected to an operational checklist.

The synthesis gap

The major governance traditions are each strong precisely where the others are weak, yet the market presents them as competing choices. Organisations are forced to pick a centre of gravity and improvise the rest.

Predictive, generative, and agentic AI compared on whether a human decides, the system acts, and state persists.

The evidence gap

No widely adopted framework makes governance traceable end to end, from board risk appetite to the audit finding that verifies it. Maturity tools score domains in isolation, missing how weakness in one undermines another.

Two governance documents separated by a traceability search.

How RESAIA closes the gaps

Five things the framework does that standards leave undone.

Orchestrates

Closes the orchestration gap

Assigns clear scope to every governance domain, defines the interfaces between them, and creates the bidirectional artefact flows that turn fourteen siloed functions into one accountable system.

AI governance functions connected through a central orchestration point.

Operationalises

Closes the operational-control gap

Carries named methodologies, artefacts, and lifecycle gates into every domain, so principles become testable controls rather than aspirations.

Governance principles connected to an operational control checklist.

Synthesises

Closes the synthesis gap

Integrates risk-based, management-system, and control-based traditions into one architecture, instead of forcing organisations to pick a centre of gravity and improvise the rest.

Governance traditions combined into one unified governance model.

Makes governance traceable

Closes the evidence gap

Connects governance end to end, from a board-level risk appetite declaration, through the controls that implement it, to the audit finding that verifies it.

Governance decisions connected through controls to verified evidence.

Governs the capability, not the model

A system-centric shift

Moves the unit of governance from the individual model to the system, and ultimately to the AI capability that spans technology, people, processes, and providers.

An AI capability composed of technology, people, processes, and providers.

The Framework

Each layer answers a question; each pillar owns a domain.

The framework brings together every discipline that touches AI into a single architecture. Governance sets the direction. Safeguard protects the work. Operate executes it. Assure verifies it. Lastly, Enable runs across all of them, providing the platform, engineering, and culture that make the architecture operational.

Resaia AIG Framework

Directives flow from each architectural layer into its governance pillars, and evidence flows back from those pillars to the layer.

Governance Foundation

Why Govern?

Directives flow from each architectural layer into its governance pillars, and evidence flows back from those pillars to the layer.

Safeguard

How Protected?

Directives flow from each architectural layer into its governance pillars, and evidence flows back from those pillars to the layer.

Operate

What Executes?

Directives flow from each architectural layer into its governance pillars, and evidence flows back from those pillars to the layer.

Assure

Is It Working?

Assessment shows which domain to strengthen next

Each domain is scored on its own rather than averaged into a single number. Lifecycle gates cannot operate above the maturity of the risk assessments that feed them, so strength in one domain does not compensate for weakness in another it depends on.

  1. Initial

    Governance depends on individual initiative. No documented policy exists, and activity follows incidents rather than preceding them.

  2. Developing

    Policy is approved but covers a subset of the portfolio. Requirements are documented without being systematically enforced.

  3. Defined

    Methodology is documented, approved, and applied consistently across the portfolio.

    First stable plateau

  4. Quantitatively Managed

    Performance is measured against defined targets. Evidence-based decision replaces judgement-based assessment.

  5. Optimising

    Governance adapts to emerging capability and regulatory change before adaptation is required.

The Body of Knowledge

The RESAIA AI Governance Body of Knowledge

The Body of Knowledge is the architecture made operational. It teaches AI governance as one connected practice, across every domain that touches AI, at a depth that lets organisations plan it, implement it, and monitor it. Each chapter sets out what the discipline does, the risks it faces, the roles that hold it, the evidence it produces, the metrics that track it, and the maturity it grows into.

The RESAIA AI Governance Body of Knowledge book cover.

The Certifications

One foundation.Five specialisations.One body of knowledge

RESAIA certifications attest professional mastery of the discipline. Start with the foundational credential that spans the full architecture. Specialise into the domain that matches the work you do.

Level: Foundational

AI Governance Professional (AIGP)

Covers the full scope of AI governance; risk, compliance, security, ethics, and legal as one connected discipline. The starting point for anyone entering or working in AI governance.

Anyone entering or working in AI governanceSelf-study from the BOK
View Certification
Level: Specialized

AI Risk Management Professional (ARMP)

AI risk identification, assessment, treatment, and monitoring. Including risks specific to AI such as bias, drift, hallucination, and emergent behaviour in agentic systems.

Risk Managers, Compliance TeamsSelf-study from the BOK
View Certification
Level: Specialized

AI Security Professional (AISP)

Threats to AI systems, including adversarial inputs, data poisoning, prompt injection, and model extraction, and the security controls to address them across the AI lifecycle.

Security professionals, AI engineersSelf-study from the BOK
View Certification
Level: Specialized

AI Audit & Assurance Professional (AAAP)

Independent audit of AI systems, programme design, evidence collection, compliance verification, and conformity assessment.

Auditors, compliance officers, regulatorsSelf-study from the BOK
View Certification
Level: Specialized

AI Privacy & Data Governance Professional (APGP)

Data quality, lineage, privacy, and protection obligations across the AI data lifecycle, from training data through to model outputs.

Privacy officers, DPOs, data governance leadsSelf-study from the BOK
View Certification
Level: Specialized

AI Procurement Professional (AIPP)

AI vendor evaluation, supply chain risk, model provenance, and governance of third-party AI systems and foundation models.

Procurement leads, vendor managers, governance teamsSelf-study from the BOK
View Certification

Find your path

Wherever you sit in the architecture,there is a way in

Individuals certify against the discipline they own. Organisations assess where they stand and build toward where they need to be. Both start from the same body of knowledge.

Boards, Executives & Policy Makers

Executive committees, board directors, and policy makers responsible for AI strategy, risk appetite, and accountability at scale, plus the data scientists and ML engineers who need the full governance picture before specialising.

Risk & Compliance Leaders

Chief risk officers, heads of compliance, and the teams responsible for AI risk methodology, assessment, and enterprise reporting.

Security Professionals & AI Engineers

CISOs, AI security engineers, and red teams defending AI systems against adversarial inputs, data poisoning, prompt injection, and model extraction.

Privacy, Data & Governance Leads

Data protection officers, privacy leads, and data governance teams managing data quality, lineage, and protection across the AI data lifecycle.

Auditors & Regulators

Internal and external auditors, conformity assessment bodies, and regulators applying the same architecture as the organisations they oversee.

Procurement & Vendor Management

Procurement leads, vendor managers, and governance teams evaluating third-party AI systems, supply chain risk, and model provenance.

Responsible AI is not an aspiration It is a practice

RESAIA exists to make that practice measurable, teachable, and accountable. It gives every discipline that touches AI a shared structure, a shared language, and a shared standard to measure against.