Why the enterprise framework doesn't transplant
Enterprise AI governance frameworks assume dedicated staff to run them. A NIST AI RMF-style program or an ISO 42001 implementation assumes a risk committee, a documented review cadence with multiple stakeholders, and someone whose full-time job is tracking AI use across the company. That's the right investment at 5,000 employees. At 200 employees, the same framework becomes a document that gets written once for a board deck and never touched again, because there's no one to run the process it describes.
The result we see constantly: a 40-page AI policy PDF sitting in a shared drive, and engineers making real decisions about model choice and data handling with no idea the document exists. A policy nobody reads provides zero actual risk reduction. It just creates a false sense that governance is handled.