Repo: ai-governance-os-eu
Focus: EU-first AI governance for SMEs (ML + GenAI + vendor AI), translated into implementable controls, templates, and evidence packs.
This is a public, operational portfolio repo — not an academic syllabus. It exists to show:
- EU AI Act → controls → evidence translation
- Decision rights + operating model (how governance actually runs)
- Minimum viable documentation (model/system cards, risk register, monitoring, incident response)
- Two end-to-end case studies (GenAI + HR/People Analytics)
If you’re an SME adopting AI (or buying AI-enabled tools), this repo helps you:
- Run intake → classification → risk assessment → approval → monitoring → incident response → retirement
- Produce an evidence pack before deployment (traceability, accountability, monitoring readiness)
- Implement EU-first controls with minimal overhead
- Evaluate vendors with governance-grade due diligence
This repo is built from primary governance sources and implementation-grade frameworks:
- EU AI Act (Regulation (EU) 2024/1689) — obligations + risk tiering (primary text)
- AI Act Service Desk — implementation-style summaries (non-binding)
- NIST AI RMF 1.0 — Govern/Map/Measure/Manage structure
- NIST GenAI Profile — GenAI-specific risk actions
- ISO/IEC 42001 — conceptual management system alignment (no certification claims)
AI governance does not operate in isolation. Every AI system depends on underlying data governance capabilities. This repo addresses both:
- Data stewardship — ownership structures, accountability, and steward onboarding
- Data quality — accuracy, completeness, consistency, timeliness, validity, and uniqueness
- Metadata management — cataloguing, classification, and discoverability of data assets
- Data lineage — tracing data from source to model to decision
- Data classification — sensitivity labelling and access control alignment
- Regulatory data obligations — GDPR data processing requirements, DMA data access obligations, SOx data integrity controls
The governance framework in this repo treats data governance as a prerequisite layer: if your data governance is immature, your AI governance will be brittle. The maturity model, readiness scorecards, and intake forms all include data governance readiness checks.
Conceptual backbone: DAMA DMBOK2 (Data Management Body of Knowledge).
0_start-here/scope.md— boundaries, SME assumptions1_framework/ai-governance-framework.md— the system (lifecycle + evidence)4_eu-ai-act/eu-ai-act-controls-map.md— translate EU AI Act obligations into specific controls, evidence, and ownership6_templates/intake-form.md— AI use case intake with data governance readiness
scope.md— what's in/out, SME assumptions, definitionshow-to-use-this-repo.md— three adoption routesglossary.md— consistent terminology
ai-governance-framework.md— lifecycle + evidence pack + decision rights + data governance foundation + regulatory alignment
eu-ai-act-controls-map.md— obligation → control → evidence → owner → cadence → data governance dependency (Articles 9–15)high-risk-requirements-checklist.md— pre-deployment yes/no checklist with 25 items + 7 post-deployment ongoing obligationsregulatory-landscape.md— EU AI Act, GDPR, DMA, DSA, SOx, DORA, NIST AI RMF, ISO 42001 at a glance
data-governance-dependency-map.md— which AI governance activities depend on which data governance capabilities (Article-by-Article + DAMA DMBOK mapping)
intake-form.md— AI use case intake form with risk classification, data governance readiness, and regulatory landscape sectionsrisk-register.md— risk register with scoring matrix, 5 financial services example entries, and governance cadence
product-brief.md— Evidence Pack Generator wedge (public concept, not implementation)mvp-workflows.md— workflow specs (inputs/steps/outputs)moat-boundary.md— what stays public vs private (defensibility)
This repo is built weekly. The repo map is updated as new artefacts ship.
This repo contains governance artefacts and reference implementations.
A separate commercial platform (automation, exports, integrations, benchmarking) is being developed privately.
This public repo intentionally excludes proprietary scoring weights, benchmark data, and production automation logic.
- Fill the intake form
- Identify obligations + controls
- Require evidence pack
- Define monitoring + incident response
- Approve, log, and review
- Adopt the framework + operating model
- Establish decision rights + cadence
- Baseline maturity and readiness
- Improve via evidence and reviews
- Run vendor due diligence
- Run a PoC with success + risk gates
- Require evidence and monitoring commitments
If you want to implement this in your SME (EU-first, evidence-based), I can support with rollout planning, workshops, and tailoring the artefacts to your org.
I'm a Product Manager with 3+ years of experience, pivoting into Data & AI Governance with a focus on the EU AI Act and responsible AI. I'm actively seeking Data & AI Governance roles in the Netherlands — including AI governance, responsible AI, compliance, and governance operations positions. If you're hiring, building a governance function, or want to discuss AI governance implementation:
LinkedIn: Let's connect (https://www.linkedin.com/in/benoyekola/)
GitHub Issues: Open a conversation
MIT