RAI FRAMEWORK
Responsible AI, from principle to audit
HOW TO USE IT
Modular by design, start where you are
Begin with Chapter 1 to set your vision and principles, then work through governance, risk classification, and the AI lifecycle.
Chapters 5 through 7 handle the specialised work: generative AI, third-party procurement, and the culture that makes controls stick. Chapter 8 hands you the templates and tools to put it all into practice. Each chapter stands on its own, so you can adopt the parts that match where your organisation is today and add the rest as you go.
- 8 Chapters
- 5 Appendices
- 100+ Implementation Steps
- Global Compliance Ready

61%
At the strategic stage
Share of organisations that have moved responsible AI from policy into practice.
$35M
Maximum EU AI Act fine
The ceiling for non-compliance under the world's first comprehensive AI regulation.
40%
Higher ROI
Reported return advantage for organisations running a real responsible-AI program.
73%
Prompt-injection risk
Share of LLM applications carrying exposure that guardrails are meant to close.
THE FRAMEWORK
The framework, chapter by chapter
Open the full framework: 8 chapters, 5 appendicesGovernance & Structure
Risk Classification & Taxonomy
The Responsible AI Lifecycle
Generative AI & LLM Specifics
Procurement & Supply Chain
Culture, Training & Adoption
Templates & Toolkits
COMPLIANCE
Mapped to the rules you answer to
The framework synthesizes NIST AI RMF, the EU AI Act, ISO/IEC 42001, and industry practice. The table below maps it to the key regulation it references.
| Framework | What it requires |
|---|---|
| EU AI Act | The world's first comprehensive AI regulation, built on risk-based classification. High-risk obligations take effect August 2026; general-purpose AI obligations began August 2025. |
| US Executive Orders | Federal AI policy aimed at uniform national standards, with FTC oversight of deceptive AI practices. |
| NIST AI RMF | A voluntary risk-management framework organised around Govern, Map, Measure, and Manage. The Generative AI Profile was released July 2024. |
| GDPR | Data-protection requirements that apply whenever an AI system processes personal data. DPIAs are required for high-risk processing. |
ROLLOUT
A twelve-month rollout
- 01Months 1–2
Foundation
Stand up the governance structure, appoint a chief AI officer, form the AI ethics board, and complete a first inventory of every AI system in use. - 02Months 3–4
Risk Assessment
Classify every system by risk tier, run algorithmic impact assessments, and find the shadow AI nobody logged. - 03Months 5–6
Process Implementation
Deploy the lifecycle controls, put guardrails on your LLMs, and stand up monitoring. - 04Months 7–8
Training & Culture
Roll out workforce training, open feedback channels, and start change management in earnest. - 05Months 9–12
Optimization & Audit
Run internal audits, tighten the processes that need it, and prepare for external assessment.
CAPABILITY ASSURANCE
Watchman makes it verifiable
Preservation Certificates
An auditable capability-preservation certificate for every compressed model you ship.Compliance-Ready Evidence
Evidence read from the model itself, not from a benchmark run, in a form your auditors accept.Continuous Monitoring
Ongoing capability monitoring that keeps pace with the regulatory duty to watch deployed systems.Protected Fine-Tuning
Proof that the capabilities you fine-tuned in survive compression intact.

