Leanpub Header

Skip to main content

Trustworthy AI

Risk Governance under NIST AI RMF and ISO/IEC 42001

Trustworthy AI

Fragment 1 — Chapter 1, "Introduction": why AI governance is a governance question, not an engineering one

When an organization first faces a decision to deploy an AI system — whether a credit-scoring model, an automated resume-screening tool, or a customer-support chatbot — the most common governance mistake is to treat that decision like an ordinary IT project: define the requirements, select a vendor, implement, and hand the system over to operations. Artificial intelligence technologies do rely on software and computing infrastructure, and in that sense they resemble any other IT initiative. But they differ in how they generate risk, and that difference calls for a distinct governance approach rather than a simple extension of familiar project management.

Risk-oriented AI governance starts from a different premise: before discussing rollout timelines, budgets, or functional requirements, an organization has to answer the question "what adverse consequences could this system cause, for whom, with what likelihood, and how severe would they be" — and, alongside it, "how much of that harm are we willing to tolerate for the expected benefit."

Fragment 2 — Chapter 3, "Trustworthy AI: Seven Characteristics of Trust": why explainability and interpretability are not synonyms

Consider an AI system that automatically sorts incoming support tickets by priority. Explainability answers the "how" question: which features of the incoming text (keywords, tone, customer history) contributed to the computed priority score and with what weight — a technical account of the computation mechanism. Interpretability answers the "why" question for this particular ticket in the context of the system's business purpose — that is, whether a high priority score means "this customer is losing money right now" or "this customer is statistically likely to cancel," and whether that meaning matches how a support agent should act on it. The two characteristics support each other but serve different governance needs: explainability matters more to the engineer debugging the model, interpretability matters more to the agent or manager who must act on the system's output without understanding its internal mechanics.

Fragment 3 — Chapter 18, "The Running Case": where ISO and NIST illuminate each other's blind spots

Precisely because NIST explicitly requires, in its own standalone subcategory, a designated authority to deactivate a system, and no direct equivalent exists in Annex A of ISO, an organization that implements only ISO/IEC 42001 without checking it in parallel against the AI RMF risks missing this requirement altogether — it dissolves between the adjacent, but not identical, controls A.6.2.5 (release criteria) and A.3.2 (roles and responsibilities). This is a compelling, concrete example of the argument the book already made back in Chapter 1: the two frameworks do not compete but mutually illuminate each other's blind spots.

Fragment 4 — Chapter 18, the book's closing paragraph

AI risk management, as this book has shown it, never concludes with a signed document. It concludes — and immediately begins again — with the next MAP cycle, the next internal audit, the next policy review, the next model version, which has to be brought into operation just as thoroughly documented, traceable, and responsibly managed as the one before it.

Minimum price

$19.99

$24.99

You pay

Author earns

$

Also available for 1 book credit with a Reader Membership

PDF
EPUB
About

About

About the Book

Short Description

More and more organizations worldwide are deploying artificial intelligence systems — and running into the same question from a board, a regulator, or a customer with increasing frequency: "how do you manage AI risk?" Enthusiasm for the technology alone is no longer an adequate answer: two leading, widely recognized frameworks compete for organizations' attention — the American NIST AI Risk Management Framework (AI RMF 1.0) and the international standard ISO/IEC 42001 — and executives are left to work out which one to choose. Trustworthy AI answers that question by refusing the premise: don't choose. The book shows that both frameworks describe essentially the same risk-management program in two complementary languages, and walks the reader through both in sequence, so that the result is a single working AI risk-management system rather than two parallel, poorly reconciled sets of documents.

What sets this book apart is not a survey of "what's out there" but a chapter-by-chapter working method for building one functioning system: starting from a shared vocabulary of risk and AI actors, moving through all four functions of the NIST Core (GOVERN, MAP, MEASURE, MANAGE), and arriving at the architecture of an ISO/IEC 42001 AI management system together with the operational detail of Annex A. A running example — CreditPlus, a fintech company with a credit-scoring model — carries the reader from Part III through to the final chapter, turning the requirements of both standards into concrete, fully worked working documents for a single organization.

About the Book

The book is organized into five parts and eighteen chapters.

Part I. Foundations of Risk-Based AI Governance (Chapters 1–4) lays the shared groundwork: why AI risk management is a governance matter rather than a purely engineering one; a typology of the potential harm AI systems can cause; the seven characteristics of trustworthy AI (valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed); and the GOVERN function as the cross-cutting foundation.

Part II. The NIST AI RMF Core in Practice (Chapters 5–8) works systematically through the MAP, MEASURE, and MANAGE functions and the concept of AI RMF Profiles (Current and Target state) for gap analysis.

Part III. ISO/IEC 42001 and AI Risk Management (Chapters 9–11) moves to the formal, certifiable AI management system (AIMS): the standard's harmonized structure, risk assessment and treatment, the Statement of Applicability, and a detailed methodology for mapping between the two frameworks.

Part IV. Operational Maturity (Chapters 12–17) details Annex A of the standard at the level of an organization's day-to-day practice: the AI system lifecycle, resources and responsible use, data, third parties and suppliers, policies and documentation, internal audit, and continual improvement.

Part V. Running Case and Synthesis (Chapter 18) brings all of the preceding chapters together into one integrated risk-management system built around the CreditPlus example, and closes the book.

Who This Book Is For

Chief AI Officers (CAIOs), both current and aspiring; risk managers and compliance professionals; product managers and executives deploying AI-based solutions; IT leaders; and AI governance consultants. No technical background is required.

What Sets This Book Apart

  • Both frameworks at once, not an either-or choice. Most existing material treats the NIST AI RMF and ISO/IEC 42001 as competing options to choose between. This book consistently shows how to build one system and describe its results in the language of both standards, including a detailed mapping methodology (Chapter 11) and a mapping table narrowed down to a specific industry case (Chapter 18).
  • A single running case, not scattered examples. CreditPlus, the book's running fintech example, runs through eight chapters (Chapters 10, 12–18), accumulating a resource register, a data-provenance log, a Statement of Applicability, a third-party responsibility-allocation matrix, and an internal-audit record — all of the documents interlock around one model version, the way they would in a real organization.
  • A practical treatment of ISO/IEC 42001, not a paraphrase of the standard. The book never reproduces the text of the commercial standard verbatim or in close paraphrase — every clause and control is explained in the author's own original wording, with the author's own examples and illustrative cases, giving readers a practical understanding of the requirements without infringing the standard publisher's copyright.
  • Terminology aligned with the primary sources, not improvised. The terminology of both frameworks is consistently aligned with the official English text of NIST AI 100-1 — the original, not a translation — and with the established English terminology of ISO/IEC 42001, and consolidated into a single alphabetical glossary at the end of the book.

Share this book

Author

About the Author

Andrii Bogdanovych

Andrii BOGDANOVYCH combines senior public-service management experience with engineering expertise in artificial intelligence — a combination rare in the Ukrainian market, and one that directly shapes this book's approach: discussing AI governance in language equally accessible to public-sector officials, corporate boards, and technical teams.

Deputy Head for Digital Development, Digital Transformation, and Digitalization (CDTO) of the State Energy Supervision Inspectorate of Ukraine (since 2022); he previously held the equivalent position at the State Ecological Inspectorate of Ukraine, and the position of Deputy Head of the Kherson Regional State Administration — in both roles leading digitalization, cybersecurity, and critical-infrastructure protection efforts, respectively at the level of a central executive authority and at the regional level.

He is the author of four training programs: "AI Management and Governance in the Organization: NIST AI RMF 1.0 and ISO/IEC 42001," data governance for executives, data governance for technical practitioners, and building organizational cybersecurity under NIST CSF 2.0 and ISO/IEC 27001.

A practicing Python/AI developer, he designs RAG systems and autonomous agentic solutions built on LLM APIs, publishes and maintains open-source libraries on PyPI, and administers his own server infrastructure. He holds a Master's degree in Public Administration (Taras Shevchenko National University of Kyiv), a Master's degree in Law (Academy of Advocacy of Ukraine), and a Bachelor's degree in Computer Science (Vadym Hetman Kyiv National Economic University).

The Leanpub 60 Day 100% Happiness Guarantee

Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.

See full terms...

Earn $8 on a $10 Purchase, and $16 on a $20 Purchase

We pay 80% royalties on purchases of $7.99 or more, and 80% royalties minus a 50 cent flat fee on purchases between $0.99 and $7.98. You earn $8 on a $10 sale, and $16 on a $20 sale. So, if we sell 5000 non-refunded copies of your book for $20, you'll earn $80,000.

(Yes, some authors have already earned much more than that on Leanpub.)

In fact, authors have earned over $15 million writing, publishing and selling on Leanpub.

Learn more about writing on Leanpub

Free Updates. DRM Free.

If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).

Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.

Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.

Learn more about Leanpub's ebook formats and where to read them

Write and Publish on Leanpub

You can use Leanpub to easily write, publish and sell in-progress and completed ebooks and online courses!

Leanpub is a powerful platform for serious authors, combining a simple, elegant writing and publishing workflow with a store focused on selling in-progress ebooks.

Leanpub is a magical typewriter for authors: just write in plain text, and to publish your ebook, just click a button. (Or, if you are producing your ebook your own way, you can even upload your own PDF and/or EPUB files and then publish with one click!) It really is that easy.

Learn more about writing on Leanpub