The process model and workbench that puts AI governance into operation.
Control Objectives for AI Systems (AICOB) is the enterprise operating model for governing and managing artificial intelligence. It is how the organisation establishes, implements, operates, monitors, reviews, maintains and continually improves its AI ecosystem.
AICOB does not replace the definition of AI governance. It turns those outcomes into assigned processes, controls, measures and assurance.
For a South African organisation the first tests of those outcomes are King V and POPIA. The EU AI Act and international standards map onto the same spine where they apply. They do not replace that file.
Three layers, one accountability model. The governing body sets outcomes. AICOB turns those outcomes into work. A governance platform applies the model to live AI uses and keeps the evidence.
Select outcomes first, then the process model, then software. A platform without agreed outcomes implements activity with no test of success.
The AI governance framework is the set of outcomes against which the governing body holds management to account for the organisation's use of AI. It does not redefine governance. It states how the four outcomes are tested in operation.
The framework does not replace law, standards or internal policy. Those instruments are mapped onto AICOB and, where used, applied through the platform. The governing body's work is to evaluate, direct and monitor. Management's work is to align, plan, build, run and assure. Every material AI outcome should have both a governing-body role and a management owner.
An outcome is developed only when the loop is closed: policy, assigned owner, work product and review. Design factors in AICOB set how deep each process goes. The outcomes stay the same; the practices scale.
For AI to function effectively, many activities need to be identified and managed. Any activity that consumes resources to turn inputs into outputs is a process, and the output of one process is often the input to the next. AICOB treats these activities as a connected system so that policy, risk controls, delivery and oversight stay aligned.
Forty AI control objectives turn stakeholder goals into assigned processes, controls, metrics and assurance. They sit in five families:
The families cascade stakeholder goals into named processes, enforceable controls, measures and independent assurance. Design factors set how much of each process is implemented, and to what depth, so the organisation does not treat "all forty at the highest maturity" as a plan.
AICOB is the spine other instruments map onto, including King V, POPIA, the EU AI Act where the organisation is on the Union market, quality-management system requirements, security and service-management practice such as ISO/IEC 27001, and AI and IT governance frameworks including ISO/IEC 38500, ISO/IEC 38507 and ISO/IEC 42001-aligned elements.
A mapping is a claim only when it is explicit: one process-control activity named against a named article, clause or control. Individual maps are maintained in the workbench.
The forty processes are combined in the AICOB workbench: a single web application with group-based, role-restricted access, versioned signed archives, and user and administrator manuals. The workbench turns the forty AI control objectives into assigned practices, controls, measures and assurance. It is not forty separate applications.
The workbench is the process system. The AI governance platform is the runtime system for live AI uses. They are complementary: the workbench holds how the organisation governs; the platform holds what is running and whether controls fired.
Software may automate inventory, policy, runtime guardrails, monitoring and evidence. It does not replace the governing body's duty to evaluate, direct and monitor.