Navigating AI Governance and Risk Management
A CISO’s perspective
As AI adoption accelerates across organisations, security leaders face a critical challenge:
how to govern and manage AI risks without creating entirely new frameworks. In this expert whitepaper, George Coumas, CISO at Fitzrovia IT, explores the distinction between AI governance and AI risk management, showing how organisations can extend established frameworks such as ISO/IEC 27001, ISO/IEC 27005, NIST CSF, NIST AI RMF, and the NCSC Cyber Assessment Framework to address emerging AI threats and opportunities.
Learn how to identify AI-specific risks, integrate AI oversight into existing security and risk management processes, and build practical governance structures that support innovation while maintaining assurance, compliance, and resilience. Ideal for CISOs, security leaders, risk professionals, and organisations navigating the growing complexity of AI adoption.
