In this lesson you will learn to
- Describe the parts of an AI governance framework and what each decides
- Give the framework builder context specific enough to draft from
- Generate a council charter, RACI matrix, risk appetite statement and approval lifecycle
- Review a RACI so that each activity has one accountable owner
- Check the draft's regulatory references against the Act
Before you start
- The first lesson in this path, so the framework has systems to govern
A governance framework answers three questions before any AI system reaches production: who decides, at which points, and against what level of risk the organisation will accept. The EU AI Act does not prescribe one, but every obligation in it needs someone accountable, and a framework is where that is written down.
VDF AI Compliance drafts a framework from a canvas and a paragraph of context. This lesson drafts one for Example Ltd, the synthetic company from the earlier lessons, and then reviews it the way a governance lead would.
Step 1: Know the four building blocks
Open Framework Builder in the Compliance sidebar. The node palette on the left has four kinds of node:
- Council: a decision-making body, such as an AI governance council or an ethics board.
- Approval Gate: a sign-off checkpoint an AI system must pass before it advances.
- RACI Cell: who is responsible, accountable, consulted and informed for an activity.
- Risk Threshold: a threshold that triggers escalation.

The canvas starts with one of each: an AI Governance Council, an Intake Approval gate, a Risk Owner RACI cell and a High-risk Tier threshold. Add or remove nodes to match how your organisation actually decides, and connect them by choosing the small arrow on a node and then the node it leads to. We kept the starting four.
Step 2: Describe your organisation
Below the palette, Organisation Context is passed to the writers when you generate. Its own guidance says the more concrete the sector, headcount, number of high-risk systems and deadlines, the more specific the documents. We wrote:
Example Ltd is a UK professional services company with 450 employees that also recruits in the EU. It has four AI systems in its register, one of them high-risk: a CV screening assistant used in recruitment (Annex III, employment). A risk committee already meets monthly. The first EU AI Act obligations for the high-risk system must be met before the next recruitment cycle in January.

The context is not kept when you leave the page, so keep it in a document with your other governance notes.
Step 3: Generate the framework
Choose Generate Framework. Ours finished in about 50 seconds with four documents under Generated Artifacts: a Council Charter, a RACI Matrix, an AI Risk Appetite Statement and an AI System Approval Lifecycle. Each opens with its execution ID and offers Copy, PDF and Word.

The context shows in the result. The charter’s purpose names the CV screening assistant and the January recruitment cycle, its scope lists the high-risk system and excludes ordinary software without algorithmic decisions, and the council has a chair from legal, a risk owner from HR for high-risk systems, an IT lead, a compliance officer, a business representative and an external legal expert consulted when needed.
Step 4: Review who is accountable
Open the RACI Matrix. It covers nine activities, from system intake and risk classification to incident response, vendor onboarding and training.

Read the Accountable column first. In ours, the AI Governance Council was accountable for eight of the nine activities; only vendor onboarding had a single owner. A committee cannot be held to a due date or called about an incident at night. Rewrite the column so that each activity has one named role, and let the council decide at its gates. For Example Ltd, the Head of Talent Acquisition, the owner in the register, is the natural accountable role for the CV screening assistant’s risk classification and monitoring.
Step 5: Check every article reference
Under the matrix, the notes list regulatory anchors. Two were right: Article 6 for high-risk criteria and Article 4 for AI literacy training, alongside GDPR Articles 35 and 33 for impact assessments and breach notification. Three were wrong:
| The draft said | The Act says |
|---|---|
| Article 10(2): fundamental rights impact assessment | Article 27 covers the fundamental rights impact assessment; Article 10 is data governance |
| Article 14: risk management system | Article 9 is the risk management system; Article 14 is human oversight |
| Article 15: post-market monitoring | Article 72 is post-market monitoring; Article 15 is accuracy, robustness and cybersecurity |
A governance document with the wrong article numbers sends every reader to the wrong obligation. Check each reference against the text of the Act before anyone relies on it.
Step 6: Proofread and approve
Finally, read each document as its approver would. Our charter still carried an [Date of Approval] placeholder, a stray non-English word in the “Review” line and typos in its own summary table, such as “High-R Risk Risk Assessment”. None of them is hard to fix, and all of them would undermine the document if it went out unchanged.
When the framework has been corrected and approved, export it with PDF or Word, store it with your controlled documents and bring it to the first council meeting. Revisit it whenever the register gains a high-risk system.
Check your understanding
What was wrong with our generated RACI matrix?
The AI Governance Council was accountable for eight of the nine activities. A committee cannot be woken at night or held to a date; each activity needs one named role accountable for it, with the council deciding at its gates.
Which of the RACI's regulatory anchors were wrong?
It cited Article 10(2) for the fundamental rights impact assessment, Article 14 for the risk management system and Article 15 for post-market monitoring. Those are Articles 27, 9 and 72; Article 14 is human oversight and Article 15 is accuracy, robustness and cybersecurity.
Why does the organisation context matter so much?
It is the only thing the writers know about you. Sector, size, the systems in scope and your deadlines turned a generic charter into one that named the CV screening assistant and the January recruitment cycle.
Reference
Build it in VDF AI
Follow along in your own workspace. The Starter plan is free, with no credit card.
Try VDF AI freeSee it on your own data
Walk through this with a VDF AI engineer, on your infrastructure and your use case.
Book a demoGo deeper with an instructor
Platform Administration and Governance: four live half-days, free for customers and partners.
See the course