Govern
Accountability and policy lifecyclePolicies, roles and accountability for AI risk are established, assigned and maintained.
Policy authored in plain language with version history and a recorded approval before anything enforces. Roles federated from the identity provider already in use and bound directly to rules. A registry of AI systems carrying named owners and enforcement mode.
Evidence artifactPolicy definitions, approval and version history, role-binding records, registry export.

