The Reason We Do Not Need Another AI Risk Framework

Every few weeks, another framework for AI-era risk management arrives. Some come from standards bodies, some from consulting firms, and a growing number from commentators inviting the profession to build one together. Each opens with the same claim: no proven guide exists for the AI era, so here is a fresh set of principles to fill the void.

The claim is wrong, and the error is expensive. Risk, compliance, and governance leaders are not short of frameworks. They are surrounded by them. What the profession actually lacks goes by a different name, and the distinction is the reason Wheelhouse Advisors chose its vocabulary with such care.

Count What Is Already on the Shelf

Start with the record. NIST published its AI Risk Management Framework in January 2023, followed by a Generative AI Profile in 2024 and a critical infrastructure profile now in development. ISO/IEC 42001, published in December 2023, is a certifiable international standard for AI management systems; roughly 350 organizations worldwide held certificates by spring 2026, including AWS, Microsoft, KPMG, and BCG, and the pace is picking up as certification bodies build audit capacity. Financial services has its own: the Cyber Risk Institute's FS AI RMF, developed with more than 100 institutions in coordination with the Financial Services Sector Coordinating Council, aligned with NIST and operationalized through 230 control objectives mapped to adoption stages. Above all of it sits the EU AI Act, which converts voluntary practice into supervisory expectation.

None of this is early thinking. These instruments are published, recognized, and in several cases certifiable. A risk leader who claims no framework exists to govern AI has not looked at the shelf.

So why does the profession keep reporting a gap? Listen closely to the complaint. When practitioners say existing frameworks feel immature, they mean the frameworks do not tell them what to build, in what order, on what architecture, or with what groundwork in data and talent. The observation is accurate. The conclusion usually drawn from it, that the profession needs one more framework, is not. Frameworks were never designed to answer build questions.

The confusion shows up in the data. A-LIGN's 2026 Compliance Benchmark Report asked more than 1,000 compliance leaders which standards they plan to use for AI: 60% named ISO/IEC 42001, 56% said they would fold AI controls into existing assessments, and 50% pointed to self-assessments. The figures sum well past 100 because organizations are not choosing a path. They are buying every hedge on the shelf, because no framework tells them which one converts into capability.

What a Framework Was Never Built to Answer

A framework is normative. It defines requirements, controls, and obligations, and it answers a single question: what must be true for your governance to be defensible? That is essential work. It is how auditors test, how regulators examine, and how boards gain assurance. It is also where the framework's job ends.

Even the standards bodies concede the point. NIST's newly revised system planning guidance, SP 800-18r2, describes its own document based plan outlines as a starting point for organizations not yet ready for automated, data driven planning, a revision Ori Wellington examined in these pages this week. The artifact gets you to defensible. Getting anywhere beyond that is left to you.

The same benchmark data exposes the cost of stopping at defensible. More than 75% of organizations told A-LIGN in 2024 they would pursue an AI audit or certification within two years, yet by A-LIGN's own admission actual uptake stayed low. Roughly 350 ISO/IEC 42001 certificates exist worldwide against the 60% of surveyed organizations that say they plan to use the standard. That distance between stated intent and built capability is what a requirements document, adopted without an operating model, reliably produces.

A risk operating model answers the questions a framework leaves open: where does the risk function stand, what gets built first, how do the pieces fit, and how will the board know the investment paid off. Frameworks are written for compliance. Models are built for action.

Confusing the two carries real cost. An organization that adopts a framework believing it has acquired a roadmap will implement controls faithfully and wonder why capability never follows. The controls were the requirements. Nobody designed the build. Research on AI adoption keeps arriving at the same conclusion from different directions: the organizations pulling ahead are distinguished by clear strategies and mature operating models. No framework supplies either.

Why We Say Model

People sometimes ask why Wheelhouse Advisors is so rigid, some would say stubborn, about calling the IRM Navigator a risk operating model and never a framework. The answer is the diagnosis above. Organizations do not need another set of requirements. They need a map for the program and technology build that every requirement assumes and none describes.

The IRM Navigator™ Model provides that map in two dimensions. The first is architectural. Risk technology resolves into three systems: systems of record that hold the enterprise risk data, systems of engagement that connect risk to the business, and systems of action where intelligence executes within governed boundaries. Most AI disappointment in risk functions traces to one design mistake: bolting intelligence onto the record layer instead of deliberately designing the action layer.

.

The second dimension is developmental. The IRM Navigator Curve traces the maturity path from Risk Dysfunction through Foundational, Coordinated, Embedded, and Extended stages to Autonomous IRM and, at the horizon, Risk Agency. Each transition on the Curve is bridged by a specific investment, which is what makes it a map instead of a taxonomy. It tells a risk leader where the function stands today, which build comes next, and why the stages cannot be skipped.

Read the intelligence era against that map and the picture clarifies. Risk positions visible in real time, controls that monitor themselves, agents handling routine execution inside a defined appetite, experienced professionals redeployed to design, validation, and exception judgment: none of it requires a new category or a fresh acronym. It is the upper half of a maturity path the model has described all along. The AI era is not a successor to integrated risk management. It is integrated risk management arriving at the destination it has pointed toward since the category was created.

A Category Built on Research

Here is where history matters. GRC entered the market in the early 2000s as a consultant's label, and the profession spent the better part of a decade arguing over what it covered. IRM took a different path. The category was created in 2016 inside Gartner's research organization, defined from the outset with a structured scope spanning ERM, ORM, TRM, and GRC, and grounded in years of research and client inquiry data from the world's largest technology analyst firm. Buyers, vendors, and boards had a working vocabulary from day one. That is what research-backed category creation buys a market: energy spent adopting the discipline instead of debating the definition.

Every fresh label for familiar territory forfeits that advantage. New definitions get litigated, vendor claims get arbitrated, boards get re-educated, and the underlying obligations compound while everyone argues. The intelligence era moves too fast for that luxury. Category continuity lets the profession spend its effort on the climb. The arithmetic is unforgiving. Nearly all organizations already run two or more audits a year, most juggle multiple audit partners, and 99% believe consolidation would save them money while a quarter admit they do not know where to begin. Every new framework adds a line to that calendar and subtracts nothing from it.

The practical guidance follows directly. Pick a framework floor, whether NIST, ISO/IEC 42001, or a sector standard, and stop shopping, because the floors are more alike than different. Then do the harder work: locate the risk function on the maturity curve, determine which of the three systems the next investment builds, sequence accordingly, and hold each stage accountable for the value its business case promised. Compliance will confirm the program is defensible. It will never say what to build next. That is the model's job, and it is the harder one.

The complete IRM Navigator Curve research, including stage-by-stage capability requirements through Autonomous IRM, is available exclusively on The RTJ Bridge at wheelhouseadvisors.com/rtj-bridge.

John A. Wheeler

John A. Wheeler is the founder and CEO of Wheelhouse Advisors, a global risk management strategy and technology advisory firm. With over three decades of experience spanning executive management, finance, risk management, audit, and IT, John is a world-renowned expert in integrated risk management technology, executive leadership, and corporate governance.

https://www.linkedin.com/in/johnawheeler/
Previous
Previous

When Cyber Risk Becomes Enterprise Risk, Whose Job Did It Just Become?

Next
Next

The Warning to GRC Vendors Buried in NIST's New Guidance