The AI governance platform is how a governance framework and the Control Objectives for AI Systems (AICOB) are applied to live AI uses. It is selected after the outcomes and the process model are defined. See the framework and the AICOB process model.
For a South African organisation the first duties on those uses are King V and POPIA. The platform is software that helps the organisation apply responsible-AI practice, internal policy, POPIA and the organisation's risk framework to every AI use - models, applications, agents, and third-party or embedded AI. It is a central repository that links governing-body oversight to runtime trust, risk and security controls.
It helps those accountable for internal AI policy show that requirements are translated into technical controls and enforced while systems run. The EU AI Act only adds provider or deployer duties where the organisation is on the Union market. Those duties sit on the same stack. They do not replace the POPIA file.
The same platform is built as a layered architecture. It is built to move beyond documentation to enforceable, verifiable controls. Board-level oversight, lifecycle management, quality and regulatory processes, and runtime control sit in one traceable stack.
The platform is able to
- register AI use cases and services, including applications, agents, models and software-as-a-service with embedded AI, together with ownership, purpose, data sources, version history, stage and supporting documentation;
- catalogue, classify, assess and help mitigate AI-specific risk against law, frameworks, standards and organisational policy;
- manage policy centrally and enforce it at runtime through guardrails (acceptable use, access, safety, privacy, security, fairness), with remediation and compliance reporting;
- score and observe production behaviour so owners can see drift, unreliability and non-compliance over time, with alerts and history;
- collect evidence of assessments, tests, validation and remediation;
- exchange data with other systems rather than exist as an island;
- automate intake, risk review, third-party review, approval, testing and the path from detection to remediation, with structured sign-off; and
- retain an audit trail of platform actions and, where applicable, lifecycle activity.
This is more than policy packs and workflow templates. The organisation can register products across the estate, attach requirements to running systems, observe or enforce controls in production, and produce evidence. Enforcement on the platform remains a delegated control. Accountability for the use of AI stays with the governing body.
How the layers map to ISO/IEC 38500 and ISO/IEC 38507
ISO/IEC 38500 gives governing bodies principles for effective, efficient and acceptable use of IT: responsibility, strategy, performance, conformance and human behaviour. ISO/IEC 38507 extends that guidance to AI. Those standards sit comfortably with King V. They do not replace it.
- Layer 1 (AI Governance). Board and executive accountability, strategic direction, risk optimisation and stakeholder transparency. Governance is structurally separated from operations.
- Layers 2-4. Operational lifecycle management, quality management and regulatory compliance, and pervasive processes: traceability, review and approval, corrective and preventive action, and change management.
- Evidence integrity. Cryptographic signing, immutable retention and conformity exports support conformance and human oversight with records that can be defended.
How the layers map to the EU AI Act
This mapping applies where the organisation is a provider or a deployer on the Union market. It is additional work. It is not the first file for a South African responsible party.
For high-risk systems the Act requires a documented quality management system, risk management, technical documentation, transparency, human oversight, post-market surveillance and record-keeping. The platform's EU AI Act QMS maps to those duties:
- Single AI system register - inventory, classification and lifecycle traceability.
- Risk management system - identification, analysis, mitigation and residual-risk documentation (Article 9).
- Product realisation and technical documentation - Annex IV-aligned records, design controls, data governance, verification and validation.
- Human oversight, transparency, accuracy and robustness - measures in the running system, instructions for use, and cybersecurity controls.
- Post-market surveillance - monitoring, incident reporting, CAPA and feedback.
- Pervasive QMS processes - traceability, reviews, nonconformity handling and change management, with immutable snapshots and exportable evidence.
That mapping is intended as a quality system that generates verifiable evidence, rather than a checklist of clauses. It supports both provider and deployer obligations where those apply.
Layer 5: runtime control for production and agentic AI
The Control Layer addresses systems that act after they are released, including agents:
- pre-execution gates, an agent registry with shadow detection, compound risk-pattern detection, and least-privilege policies;
- telemetry, drift detection, human-oversight queues and automated escalation;
- support across design-time, pre-execution, runtime, review and evidence stages.
This is the shift from descriptive policy to operational control. Policy on the platform remains a delegated control. The governing body still evaluates, directs and monitors.
What the combined stack is built to cover
- Governance and oversight. King V at the governing body, with ISO/IEC 38500 and 38507 as method. Board-level separation sits in Layer 1, not only in a policy pack.
- Personal information. POPIA still applies to every use that processes personal information. The platform does not replace a PIIA or an operator contract.
- Regulatory compliance (EU AI Act). The QMS mapping applies where the organisation is on the Union market.
- Operational and technical controls. Runtime enforcement and the agentic controls in Layer 5 are what distinguish the platform from a document store.
- Evidence and assurance. Signed, retained, exportable records are the proof that work was done.
Taken together, the layers are one architecture: governance, management, compliance, process and real-time control, with a single register and an audit trail.