In the McKinsey State of AI 2025 survey, only around one in six organizations place oversight of AI governance at board level, even though roughly half report at least one negative AI incident in the past year. That gap between intent and control is what an operating model closes. An AI governance operating model is the way an organization arranges people, processes, and structures so that its AI governance actually runs day to day, rather than living in a policy document. It sits across five layers, mandate and principles, governance bodies and roles, policies and standards, processes and controls, and assurance and reporting, and it is held together by an AI management system. The AI Governance Certification Institute (AIGCI) teaches this model as the bridge between governance intent and a certifiable system.

An AI governance operating model is the arrangement of people, processes, and structures that turns an organization's AI governance intent into day to day practice, held together by an AI management system structured to ISO/IEC 42001.

Key facts at a glance

Attribute

Detail

What it is

The operating structure that makes AI governance run in practice

The five layers

Mandate and principles, governance bodies and roles, policies and standards, processes and controls, assurance and reporting

Held together by

An AI management system (AIMS)

Standard behind it

ISO/IEC 42001

Core outcome

Clear accountability, repeatable processes, and evidence you can audit

Who needs one

Any organization that builds, buys, or deploys AI at scale

Why an operating model, not just a policy

A policy states what an organization intends. An operating model makes that intention happen, and keeps it happening. The difference matters because standards and regulators now expect structure, not statements. ISO/IEC 42001 Clause 5.3 on roles, responsibilities, and authorities requires top management to assign, communicate, and authorize the roles that run the AI management system, so that accountability is designed in rather than assumed. The NIST AI Risk Management Framework makes the same point through its Govern function: effective AI risk management begins with leadership commitment, clear structures, and a risk-aware culture, not with a single document. An operating model is how those expectations become an everyday reality.

The five layers of the operating model

Each layer answers a different question, and each depends on the one above it. Read from the top: direction, then accountability, then rules, then execution, then the check that everything is working.

Figure 1. The five layers of the AI governance operating model, structured as an AIMS and reviewed in a continual loop.

Mandate and principles set the direction

Everything starts with a clear mandate from leadership and a short set of principles the organization will hold to. This is where responsible-AI values, risk appetite, and accountability are stated. The OECD AI Principles, including their principle on accountability, are a common reference point, because they give organizations a shared, internationally recognised set of values to anchor to.

Governance bodies and roles create accountability

Direction means little without someone answerable for it. This layer defines the bodies that govern AI, such as an oversight committee, and the roles that own the management system day to day. Its job is to remove ambiguity about who decides, who implements, and who reports, which is exactly what Clause 5.3 of the standard asks for.

Policies and standards turn principles into rules

Here principles become concrete rules: an AI policy, an acceptable-use standard, and the internal requirements that teams must follow. Good policies are specific enough to guide a decision and stable enough to audit against, so they act as the reference the rest of the model points back to.

Processes and controls put the rules to work

This is where governance meets the AI lifecycle. Risk assessments, impact assessments, lifecycle approval gates, monitoring, and incident response all live here. These processes are what actually reduce risk, and they generate the records that later prove the system worked.

Assurance and reporting close the loop

Finally, the organization checks itself. Internal audits, performance metrics, and management review confirm that the model is doing its job, and feed findings back up to the mandate so the whole system improves. Without this loop an operating model slowly drifts out of date.

How the model is structured as an AIMS

The five layers need something to hold them together, and that something is a management system. An operating model becomes durable when it is expressed as the AIMS it is structured as, because a management system gives every layer a defined place, a set of records, and a rhythm of review. The ISO 42001 standard provides that structure off the shelf: its clauses cover leadership, planning, support, operation, evaluation, and improvement, and its Annex A sets out controls an organization can adopt. In other words, the operating model is what you run, and the AIMS is the frame that keeps it coherent and certifiable.

Putting the operating model to work

In practice, most organizations already have fragments of this model. A policy here, a risk review there, an informal owner somewhere. What stalls them is that the fragments are not connected, so accountability is unclear and evidence is scattered when an auditor or a regulator asks. The value of naming the five layers is that it shows the gaps immediately: usually a missing governance body, or an assurance loop that never closes. The McKinsey State of AI 2025 finding that board-level oversight is still the exception is a symptom of exactly this, a top layer that has not yet been built out.

A simple way to start is to place your existing practices onto the five layers, find the thinnest one, and strengthen it before moving on. The operating model gives you the structure; the management system gives you the discipline; and ISO/IEC 42001 gives you a recognised standard to aim the whole thing at.

Frequently asked questions

What is the difference between AI governance and an AI governance operating model?

AI governance is the overall practice of directing and controlling how an organization uses AI. The operating model is the concrete structure, the layers, bodies, roles, and processes, that makes that governance actually run.

Do we need an operating model if we already have an AI policy?

Usually yes. A policy is one layer of the model. Without governance bodies, processes, and an assurance loop around it, a policy tends to sit unused and cannot be audited effectively.

How does the operating model relate to ISO 42001?

ISO/IEC 42001 gives the operating model a management-system structure. The standard's clauses map closely to the five layers, which is why organizations often build their operating model directly against it.

Who should own the operating model?

Ownership sits with top management, who set the mandate, and with a named role or committee that runs the AIMS day to day. Clause 5.3 of ISO 42001 requires those roles and authorities to be assigned and communicated.

Is this only for large enterprises?

No. A smaller organization can run all five layers in a lighter form, with fewer people wearing more hats. The layers still apply; only the scale changes.

Build your operating model on a recognised standard

The most reliable way to turn these five layers into a certifiable system is to build them against ISO/IEC 42001. AIGCI's ISO 42001 training and certification walks practitioners through each layer, from leadership and roles to controls and audit, so the operating model you design is the one an assessor will recognise. To see how the institute approaches this, read more about the institute.