AI Governance Due Diligence: What to Look For
As companies race to ship AI, a new diligence question has become unavoidable: does this company govern its AI responsibly, or is it one incident away from a regulatory, reputational or safety disaster? AI governance due diligence assesses the maturity of a company's responsible-AI practices — and unlike a lot of "AI risk" hand-waving, there are now real frameworks to measure against.
The three reference points
Three frameworks anchor the conversation. The NIST AI Risk Management Framework is a voluntary U.S. standard for identifying and managing AI risk across a system's lifecycle. ISO/IEC 42001 is the first certifiable management-system standard for AI — the ISO 27001 equivalent for responsible AI. And the EU AI Act is the first comprehensive AI law, classifying systems by risk and imposing hard obligations on high-risk uses. A company's stance toward these three tells you how seriously it takes the problem.
Governance: who owns AI risk?
The first thing to look for is whether anyone is actually accountable. Is there a defined AI governance function, a review process for new models or use cases, published principles that go beyond platitudes? Companies that treat AI governance as real have named owners, documented processes and a way to say no to a risky deployment. Companies that don't have a values page and nothing behind it.
Transparency and testing
Mature AI practice shows its work. Look for model or system documentation (model cards, system cards), disclosure of known limitations, and evidence of safety testing — red-teaming, bias and fairness evaluations, pre-deployment review. A company that publishes what its models can't do, and how it tests them, is demonstrating a maturity that a company making only capability claims is not.
Where the AI Act bites
If a company operates in or sells into the EU, the AI Act's risk tiers matter concretely. High-risk systems carry obligations around risk management, data governance, transparency, human oversight and accuracy — with real penalties for non-compliance. Understanding which tier a company's systems fall into, and whether it's preparing for the obligations that follow, is now part of assessing its regulatory exposure.
An emerging field, assessed honestly
AI governance is young, standards are still settling, and public disclosure is uneven — so this assessment is about maturity and direction more than pass/fail. Use it to understand how a company thinks about AI risk and where the obvious gaps are, then probe the high-stakes systems directly. This is general guidance, not legal advice, and AI regulation is changing quickly.