{"id":184,"date":"2026-09-24T08:00:26","date_gmt":"2026-09-24T08:00:26","guid":{"rendered":"https:\/\/www.dobryakov.net\/blog\/184\/"},"modified":"2026-09-24T08:00:26","modified_gmt":"2026-09-24T08:00:26","slug":"ai-governance-operating-model","status":"publish","type":"post","link":"https:\/\/www.dobryakov.net\/blog\/184\/","title":{"rendered":"Governance Operating Model &#038; AIMS: How to Assemble a Control Plane That Survives Entropy"},"content":{"rendered":"<p>Imagine every control plane is built. PII is masked. RAG respects permissions. Guardrails block prompt injections. The audit trail writes to immutable storage. Budgets hold. Content is labeled. Quality is measured. The supply chain sits under an AIBOM. The agent sits behind a policy gate. Six months in, an ISO 42001 audit arrives \u2014 and there is nothing to prove, because ACL sync silently broke in March, the golden dataset hasn&#x27;t been refreshed since launch, the kill-switch has never been tested, and the credit module formally has no owner. The technical controls went stale. Not from an attack. From nobody having been assigned to maintain or audit them.<\/p>\n<p><!--more--><\/p>\n<p>This is the final, operating plane. The technical patterns from the earlier chapters degrade without an operating model \u2014 not from attack, but from entropy. This chapter assembles them into an AI Management System (AIMS per ISO\/IEC 42001): owners, a lifecycle, a system registry, policy-as-code, and auto-generated evidence. It delivers the capstone: the full reference architecture of Kovcheg.<\/p>\n<h2>The Business Goal<\/h2>\n<p>Turn a set of controls into a managed system that survives a specific engineer leaving and passes an audit without a scramble. Business outcomes:<\/p>\n<ol>\n<li>Every AI system has an owner, a risk class, and a lifecycle.<\/li>\n<li>Governance is expressed as code and is itself versioned and audited.<\/li>\n<li>Compliance evidence is generated automatically from live planes.<\/li>\n<\/ol>\n<h2>Driver: Regulator and Drift<\/h2>\n<p><strong>ISO\/IEC 42001<\/strong>: a certifiable AIMS is a requirement in ~40% of EU enterprise RFPs (2026).<\/p>\n<p><strong>EU AI Act<\/strong>: Art. 9 (Risk Management System), Art. 17 (Quality Management System), Art. 72 (post-market monitoring), Art. 11\u201312 (documentation and logs).<\/p>\n<p><strong>Organizational drift<\/strong>: without owners and process, controls go stale. ACL lags. The dataset ages. The kill-switch goes untested. This is a silent failure of governance.<\/p>\n<h2>Architectural Pattern<\/h2>\n<p><strong>AIMS + Policy-as-Code Control Plane.<\/strong> An operating model layered over the control plane. Policies are code and CI\/CD gates. Every AI system lives in a registry with roles and a lifecycle. Compliance evidence is generated automatically from the artifacts of the underlying planes.<\/p>\n<h3>Engineering Stack<\/h3>\n<ul>\n<li><strong>AIMS\/GRC<\/strong>: ISO 42001-aligned processes; risk and policy trackers.<\/li>\n<li><strong>Registry<\/strong>: MLflow Registry or an internal AI system registry.<\/li>\n<li><strong>Policy-as-code<\/strong>: OPA\/Rego as the shared gate language.<\/li>\n<li><strong>Evidence<\/strong>: the audit log, eval reports, AIBOM, and red-team results combined as automatic evidence.<\/li>\n<\/ul>\n<h2>Engineering Implementation<\/h2>\n<h3>Step 1. An AI System Registry<\/h3>\n<p>Every system (Kovcheg RAG, Kovcheg agent) is a record. It carries a risk class, an owner, a lifecycle status, and links to its controls and evidence.<\/p>\n<h3>Step 2. RACI Governance<\/h3>\n<p>Define who owns the risk, who approves a release, who holds the kill-switch, and who is accountable for evals. A governance board is a process with authority. An owner without the power to block a release is decorative. This is a common failure.<\/p>\n<h3>Step 3. Policy-as-Code as One Shared Layer<\/h3>\n<p>Consolidate the OPA policies into a single versioned repository. A policy change is a PR, a review, and a new version. Governance itself is under audit.<\/p>\n<h3>Step 4. Lifecycle &amp; Gates (State Machine)<\/h3>\n<pre><code class=\"language-text\">dev \u2192 risk-classification \u2192 security-gate \u2192 eval-gate\n    \u2192 release \u2192 post-market monitoring \u2192 retire<\/code><\/pre>\n<p>Every transition is an explicit, observable state, with technical documentation auto-generated from the artifacts. This is not an &quot;if&quot; buried in a CI script. It is an external status.<\/p>\n<h3>Step 5. Post-Market Monitoring, Closed Onto the Policies<\/h3>\n<p>The drift, incident, and feedback loop updates the registry, the RMS, and the policies themselves. An incident triggers a new red-team case and a new OPA rule. The registry, RMS, and policies are updated from incidents.<\/p>\n<h3>Step 6. Kovcheg&#x27;s Reference Architecture (Capstone)<\/h3>\n<p>A full diagram of the control plane: how the individual planes fit together into one request path and one evidence layer. This is the map an audit can walk through end to end.<\/p>\n<h2>Where It Breaks<\/h2>\n<ul>\n<li><strong>Governance theater at a new level.<\/strong> A registry and a board exist, but the policies aren&#x27;t enforced in production. The same &quot;PDF vs. control plane&quot; gap. The only cure is policy-as-code plus automatic evidence, not screenshots for the audit.<\/li>\n<li><strong>An owner with no authority.<\/strong> The role exists, but they can&#x27;t block a release. A decoration.<\/li>\n<li><strong>An AIMS without automatic evidence<\/strong> turns back into a manual scramble for artifacts before an audit date. The same entropy, with a folder attached.<\/li>\n<li><strong>Over-governance.<\/strong> A process too heavy kills velocity. Teams drift into Shadow AI. Governance competes with convenience; if the legal path is painful, people route around it.<\/li>\n<li><strong>A registry drifting from reality<\/strong> without auto-discovery of systems.<\/li>\n<\/ul>\n<h2>Standards and Mapping<\/h2>\n<ul>\n<li><strong>ISO\/IEC 42001<\/strong>: the whole standard (AIMS, Annex A).<\/li>\n<li><strong>EU AI Act<\/strong>: Art. 9 (RMS), Art. 17 (QMS), Art. 72 (post-market), Art. 11\u201312.<\/li>\n<li><strong>NIST AI RMF<\/strong>: Govern.<\/li>\n<li>The output is the &quot;requirement \u2192 control \u2192 evidence&quot; matrix.<\/li>\n<\/ul>\n<h2>Maturity Checklist<\/h2>\n<ul>\n<li><strong>L1<\/strong>: an AI system registry and assigned owners exist.<\/li>\n<li><strong>L2<\/strong>: policy-as-code gates in CI, a lifecycle with statuses, automatic evidence from audit\/eval\/AIBOM.<\/li>\n<li><strong>L3<\/strong>: a certifiable AIMS, post-market monitoring closed onto the policies, a compliance matrix with live evidence, governance itself versioned and audited, auto-discovery of systems.<\/li>\n<\/ul>\n<h2>The Capstone Artifact<\/h2>\n<p>Assemble Kovcheg&#x27;s reference architecture: a registry of two systems with risk classes and owners, RACI, a single policy-as-code repository, lifecycle gates in CI, and auto-generated technical documentation. The course&#x27;s final artifact is the Kovcheg AIMS dossier \u2014 one folder an audit can be walked through from: classification, controls, evidence, owners, the incident process.<\/p>\n<h2>What&#x27;s Next<\/h2>\n<p>The course delivered the control plane and the operating model on top of it. Next: cross-organizational governance: provenance and trust between agents from different companies, verifiable credentials for AI agents, industry codes of practice layered on top of the AI Act. That is outside this course&#x27;s enterprise perimeter.<\/p>\n<h2>Sources<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.konfirmity.com\/blog\/iso-42001\">ISO 42001 guide 2026 (Konfirmity)<\/a><\/li>\n<li><a href=\"https:\/\/www.eccouncil.org\/cybersecurity-exchange\/responsible-ai-governance\/eu-ai-act-nist-ai-rmf-and-iso-iec-42001-a-plain-english-comparison\/\">ISO 42001 vs NIST AI RMF vs EU AI Act (EC-Council)<\/a><\/li>\n<li><a href=\"https:\/\/gaicc.org\/blog\/ai-governance-comparison-eu-ai-act-nist-iso-42001\/\">Global AI Governance Comparison 2026 (GAICC)<\/a><\/li>\n<\/ul>\n<p>Every control plane you build will eventually assemble into one operating model \u2014 an AIMS plus policy-as-code. The engineering leader who owns governance end to end is the one who decides whether that assembly happens by design on a Tuesday, or by scramble the night before an audit.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Technical controls degrade without an operating model. Here is how to assemble every plane into an AI Management System with policy-as-code and auto-generated evidence.<\/p>\n","protected":false},"author":0,"featured_media":183,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[147],"tags":[182,154,184,183,185],"class_list":["post-184","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-governance","tag-aims","tag-iso-42001","tag-operating-model","tag-policy-as-code","tag-reference-architecture"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.10 - aioseo.com -->\n\t<meta name=\"description\" content=\"Assemble AI governance controls into an ISO 42001 AIMS with policy-as-code, a system registry, and auto-generated compliance evidence.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.dobryakov.net\/blog\/184\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.10\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Grigoriy Dobryakov - IT+AI Blog - Grigoriy Dobryakov&#039;s blog: management, development and testing\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"AI Governance Operating Model &amp; AIMS Reference Architecture\" \/>\n\t\t<meta property=\"og:description\" content=\"Assemble AI governance controls into an ISO 42001 AIMS with policy-as-code, a system registry, and auto-generated compliance evidence.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.dobryakov.net\/blog\/184\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-09-24T08:00:26+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-24T08:00:26+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"AI Governance Operating Model &amp; AIMS Reference Architecture\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Assemble AI governance controls into an ISO 42001 AIMS with policy-as-code, a system registry, and auto-generated compliance evidence.\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/184\\\/#blogposting\",\"name\":\"AI Governance Operating Model & AIMS Reference Architecture\",\"headline\":\"Governance Operating Model &#038; AIMS: How to Assemble a Control Plane That Survives Entropy\",\"author\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/author\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ai-governance-operating-model.jpg\",\"width\":1200,\"height\":630,\"caption\":\"Governance Operating Model & AIMS: How to Assemble a Control Plane That Survives Entropy\"},\"datePublished\":\"2026-09-24T08:00:26+00:00\",\"dateModified\":\"2026-09-24T08:00:26+00:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/184\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/184\\\/#webpage\"},\"articleSection\":\"AI Governance, AIMS, iso-42001, operating model, policy-as-code, reference architecture\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/184\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/category\\\/ai-governance\\\/#listItem\",\"name\":\"AI Governance\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/category\\\/ai-governance\\\/#listItem\",\"position\":2,\"name\":\"AI Governance\",\"item\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/category\\\/ai-governance\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/184\\\/#listItem\",\"name\":\"Governance Operating Model &#038; AIMS: How to Assemble a Control Plane That Survives Entropy\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/184\\\/#listItem\",\"position\":3,\"name\":\"Governance Operating Model &#038; AIMS: How to Assemble a Control Plane That Survives Entropy\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/category\\\/ai-governance\\\/#listItem\",\"name\":\"AI Governance\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/#organization\",\"name\":\"Grigoriy Dobryakov - IT+AI Blog\",\"description\":\"Grigoriy Dobryakov's blog: management, development and testing\",\"url\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/184\\\/#webpage\",\"url\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/184\\\/\",\"name\":\"AI Governance Operating Model & AIMS Reference Architecture\",\"description\":\"Assemble AI governance controls into an ISO 42001 AIMS with policy-as-code, a system registry, and auto-generated compliance evidence.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/184\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/author\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/author\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ai-governance-operating-model.jpg\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/184\\\/#mainImage\",\"width\":1200,\"height\":630,\"caption\":\"Governance Operating Model & AIMS: How to Assemble a Control Plane That Survives Entropy\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/184\\\/#mainImage\"},\"datePublished\":\"2026-09-24T08:00:26+00:00\",\"dateModified\":\"2026-09-24T08:00:26+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/\",\"name\":\"Grigoriy Dobryakov - IT+AI Blog\",\"description\":\"Grigoriy Dobryakov's blog: management, development and testing\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"AI Governance Operating Model & AIMS Reference Architecture","description":"Assemble AI governance controls into an ISO 42001 AIMS with policy-as-code, a system registry, and auto-generated compliance evidence.","canonical_url":"https:\/\/www.dobryakov.net\/blog\/184\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/www.dobryakov.net\/blog\/184\/#blogposting","name":"AI Governance Operating Model & AIMS Reference Architecture","headline":"Governance Operating Model &#038; AIMS: How to Assemble a Control Plane That Survives Entropy","author":{"@id":"https:\/\/www.dobryakov.net\/blog\/author\/#author"},"publisher":{"@id":"https:\/\/www.dobryakov.net\/blog\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.dobryakov.net\/blog\/wp-content\/uploads\/2026\/09\/ai-governance-operating-model.jpg","width":1200,"height":630,"caption":"Governance Operating Model & AIMS: How to Assemble a Control Plane That Survives Entropy"},"datePublished":"2026-09-24T08:00:26+00:00","dateModified":"2026-09-24T08:00:26+00:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.dobryakov.net\/blog\/184\/#webpage"},"isPartOf":{"@id":"https:\/\/www.dobryakov.net\/blog\/184\/#webpage"},"articleSection":"AI Governance, AIMS, iso-42001, operating model, policy-as-code, reference architecture"},{"@type":"BreadcrumbList","@id":"https:\/\/www.dobryakov.net\/blog\/184\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.dobryakov.net\/blog#listItem","position":1,"name":"Home","item":"https:\/\/www.dobryakov.net\/blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.dobryakov.net\/blog\/category\/ai-governance\/#listItem","name":"AI Governance"}},{"@type":"ListItem","@id":"https:\/\/www.dobryakov.net\/blog\/category\/ai-governance\/#listItem","position":2,"name":"AI Governance","item":"https:\/\/www.dobryakov.net\/blog\/category\/ai-governance\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.dobryakov.net\/blog\/184\/#listItem","name":"Governance Operating Model &#038; AIMS: How to Assemble a Control Plane That Survives Entropy"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.dobryakov.net\/blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.dobryakov.net\/blog\/184\/#listItem","position":3,"name":"Governance Operating Model &#038; AIMS: How to Assemble a Control Plane That Survives Entropy","previousItem":{"@type":"ListItem","@id":"https:\/\/www.dobryakov.net\/blog\/category\/ai-governance\/#listItem","name":"AI Governance"}}]},{"@type":"Organization","@id":"https:\/\/www.dobryakov.net\/blog\/#organization","name":"Grigoriy Dobryakov - IT+AI Blog","description":"Grigoriy Dobryakov's blog: management, development and testing","url":"https:\/\/www.dobryakov.net\/blog\/"},{"@type":"WebPage","@id":"https:\/\/www.dobryakov.net\/blog\/184\/#webpage","url":"https:\/\/www.dobryakov.net\/blog\/184\/","name":"AI Governance Operating Model & AIMS Reference Architecture","description":"Assemble AI governance controls into an ISO 42001 AIMS with policy-as-code, a system registry, and auto-generated compliance evidence.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.dobryakov.net\/blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.dobryakov.net\/blog\/184\/#breadcrumblist"},"author":{"@id":"https:\/\/www.dobryakov.net\/blog\/author\/#author"},"creator":{"@id":"https:\/\/www.dobryakov.net\/blog\/author\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.dobryakov.net\/blog\/wp-content\/uploads\/2026\/09\/ai-governance-operating-model.jpg","@id":"https:\/\/www.dobryakov.net\/blog\/184\/#mainImage","width":1200,"height":630,"caption":"Governance Operating Model & AIMS: How to Assemble a Control Plane That Survives Entropy"},"primaryImageOfPage":{"@id":"https:\/\/www.dobryakov.net\/blog\/184\/#mainImage"},"datePublished":"2026-09-24T08:00:26+00:00","dateModified":"2026-09-24T08:00:26+00:00"},{"@type":"WebSite","@id":"https:\/\/www.dobryakov.net\/blog\/#website","url":"https:\/\/www.dobryakov.net\/blog\/","name":"Grigoriy Dobryakov - IT+AI Blog","description":"Grigoriy Dobryakov's blog: management, development and testing","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.dobryakov.net\/blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"Grigoriy Dobryakov - IT+AI Blog - Grigoriy Dobryakov's blog: management, development and testing","og:type":"article","og:title":"AI Governance Operating Model &amp; AIMS Reference Architecture","og:description":"Assemble AI governance controls into an ISO 42001 AIMS with policy-as-code, a system registry, and auto-generated compliance evidence.","og:url":"https:\/\/www.dobryakov.net\/blog\/184\/","article:published_time":"2026-09-24T08:00:26+00:00","article:modified_time":"2026-09-24T08:00:26+00:00","twitter:card":"summary_large_image","twitter:title":"AI Governance Operating Model &amp; AIMS Reference Architecture","twitter:description":"Assemble AI governance controls into an ISO 42001 AIMS with policy-as-code, a system registry, and auto-generated compliance evidence."},"aioseo_meta_data":{"post_id":"184","title":"AI Governance Operating Model & AIMS Reference Architecture","description":"Assemble AI governance controls into an ISO 42001 AIMS with policy-as-code, a system registry, and auto-generated compliance evidence.","keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":"AI Governance Operating Model & AIMS Reference Architecture","og_description":"Assemble AI governance controls into an ISO 42001 AIMS with policy-as-code, a system registry, and auto-generated compliance evidence.","og_object_type":"default","og_image_type":"default","og_image_custom_url":null,"og_image_custom_fields":null,"og_image_url":null,"og_image_width":null,"og_image_height":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_image_url":null,"twitter_title":"AI Governance Operating Model & AIMS Reference Architecture","twitter_description":"Assemble AI governance controls into an ISO 42001 AIMS with policy-as-code, a system registry, and auto-generated compliance evidence.","schema_type":"default","schema_type_options":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"limit_modified_date":false,"ai":null,"breadcrumb_settings":null,"seo_analyzer_scan_date":null,"created":"2026-09-24 08:00:43","updated":"2026-09-24 08:00:43"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.dobryakov.net\/blog\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.dobryakov.net\/blog\/category\/ai-governance\/\" title=\"AI Governance\">AI Governance<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tGovernance Operating Model &amp; AIMS: How to Assemble a Control Plane That Survives Entropy\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.dobryakov.net\/blog"},{"label":"AI Governance","link":"https:\/\/www.dobryakov.net\/blog\/category\/ai-governance\/"},{"label":"Governance Operating Model &#038; AIMS: How to Assemble a Control Plane That Survives Entropy","link":"https:\/\/www.dobryakov.net\/blog\/184\/"}],"_links":{"self":[{"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/posts\/184","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/comments?post=184"}],"version-history":[{"count":0,"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/posts\/184\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/media\/183"}],"wp:attachment":[{"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/media?parent=184"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/categories?post=184"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/tags?post=184"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}