Skip to content

AI Baseline Control Framework

Manage & govern AI use in your organization

The AI Baseline Control Framework (AI BCF) is a free, open framework of 20 AI governance controls for organizations that deploy (use) AI. Each control is mapped to the NIST AI RMF, ISO/IEC 42001 and the EU AI Act. The AI BCF helps organizations of all sizes understand what is necessary to manage & govern AI deployment.

Who this is for

This framework is for deployers (users) of AI systems, who are looking for a practical, risk-based and understandable way to understand, manage and govern AI use within their organization. This framework can be used by CISOs, IT Directors, AI Officers and/or other relevant professionals.

Five categories

The 20 controls are grouped into five clear categories, covering AI governance from policy down to the day-to-day tracking of deployed AI systems:

Govern

Policy, roles, training and the risk management process. Ensures AI use in an organization has an owner and that a shared understanding of what is and isn't allowed exists and is understood within the organization.

Comply

The legal and regulatory obligations that follow directly from using AI: knowing which laws apply, marking AI-generated content, and the extra steps required around higher-risk uses.

Register

What AI is deployed, for what purpose, and how proportionate it is to the task. The register is what makes the rest of the framework possible to check in the first place.

Access

Access rights for AI systems themselves, not only for the people who use them. AI that acts with its own credentials or autonomously needs the same access discipline as any other account.

Track

How deployed AI actually performs once it's in use: effectiveness, internal feedback and errors, collected so the organization's understanding of AI risk and effectiveness is based on proven metrics.

Reflects EU law as of October 2026: the EU AI Act as amended by Regulation (EU) 2026/1744. This framework is not legal advice.

Three control types

There are three types of controls. The type determines whether and when it applies to your organization:

Baseline

Applies to every organization that uses AI, regardless of size or sector.

Tier II

Optional extra depth on top of the baseline. Organizations with more mature AI governance, or more exposure, may choose to adopt these for more thorough control over AI than the baseline alone provides.

Trigger

Applies only once the specific trigger condition stated in the control is true. If that condition doesn't apply to an organization, the control doesn't apply either. Check the trigger text on each control.