Most organizations asking "how do we govern AI?" already have an answer to a nearly identical question sitting on the shelf: their IT governance program. So is AI governance a new discipline that needs its own charter, budget, and reporting line — or is it just IT governance catching up to a new kind of technology? The honest answer is both, and knowing where the line actually falls is core Domain 1 material for AAISM.
One Program, or Two?
IT governance, built around frameworks like COBIT, exists to make sure any technology investment — an ERP rollout, a cloud migration, an AI model — is directed and monitored in a way that serves enterprise goals, manages risk, and has clear accountability. That scope was never AI-specific; COBIT governs the relationship between business objectives and IT delivery in general.
What's genuinely new with AI is the risk surface underneath that governance layer. Model bias and fairness, training-data provenance, explainability, drift over time, and systems that make or influence decisions autonomously aren't problems a generic IT control framework was built to catch on its own. That's the gap a dedicated AI risk framework like the NIST AI Risk Management Framework (AI RMF) is designed to fill — not by replacing IT governance, but by giving it a risk-specific vocabulary for AI systems specifically.
What Each Framework Actually Does
COBIT operates at the enterprise level. Its five governance and management domains — Evaluate/Direct/Monitor, Align/Plan/Organize, Build/Acquire/Implement, Deliver/Service/Support, and Monitor/Evaluate/Assess — apply to any technology investment, AI included. Underneath those domains, COBIT defines seven "enablers" that make governance concrete: processes, organizational structures, policies and procedures, culture and ethics, information, people and skills, and the services/infrastructure/applications themselves. ISACA's own 2025 guidance on the topic explicitly frames these enablers as the structure organizations should extend to cover AI, rather than duplicate with a standalone AI governance framework.
NIST AI RMF operates one layer down, at the system level. It's organized around four functions — Govern, Map, Measure, and Manage — that walk an organization through establishing accountability for an AI system (Govern), identifying its specific risks in context (Map), tracking those risks (Measure), and acting on them (Manage). The Govern function is the connective tissue: it's the point where AI-specific accountability is supposed to plug into whatever governance structure — COBIT or otherwise — the organization already runs everything else through.
In short: COBIT answers who's accountable and how a technology system gets directed and monitored across its whole lifecycle. NIST AI RMF answers what can specifically go wrong with an AI system and how that risk gets tracked. ISACA positions the two as complementary layers, not competing choices — the same relationship AAISM candidates should expect between enterprise governance and any domain-specific risk framework.
What This Looks Like in Practice
The pattern shows up in how mature organizations have actually structured AI oversight. Reporting on responsible-AI programs at Microsoft, Google, and IBM describes each company building AI review into governance structures it already had, rather than standing up an isolated AI-only track: Microsoft folds fairness, safety, and security reviews into its existing product-release gates; Google routes model risk review through its established oversight committees; IBM's AI ethics reviews run through a cross-functional board that already includes privacy, compliance, and product representatives. None of the three built AI governance as a separate reporting line from scratch.
- Extend accountability, don't duplicate it — route AI risk decisions through the same ownership and escalation structure already used for IT risk, adding AI-specific expertise into it, rather than creating a second governance track that has to be reconciled with the first.
- Let Govern do the connecting — NIST AI RMF's Govern function is explicitly the layer meant to interface with an organization's broader governance framework; treating it as a standalone checklist instead of a bridge is a common implementation mistake.
- Watch for the ownership gap — many existing IT governance charts have no named owner for model risk or algorithmic accountability yet. That gap, not a missing framework, is usually the real finding in an AI governance assessment — and a scenario AAISM exam questions are built to probe.
Want to go deeper on how this domain is tested on the AAISM exam? The AI Security Management Prep App covers this and 300 other practice scenarios, offline.
Explore the App — $9.99Related Reading
For the full exam breakdown, see the AAISM Certification Study Guide. For a related look at what happens when governance structures lag AI adoption entirely, see Shadow AI Governance Gap: What the 2026 Data Shows.
Sources
ISACA — Leveraging COBIT for Effective AI System Governance
NIST — AI Risk Management Framework
Knostic — Real AI Governance Examples You Need to Know