AI Governance Library

The 12 Essential Questions for Responsible AI Governance: Unifying EU AI Act & NIST AI RMF

A TechBetter white paper that distils the EU AI Act and the NIST AI Risk Management Framework into four governance pillars and 12 essential questions, each mapped to the relevant articles and RMF items, with a five-level maturity model.
Cover of The 12 Essential Questions for Responsible AI Governance: Unifying EU AI Act & NIST AI RMF

⚡ Quick Summary

Published by TechBetter, this white paper by Ravit Dotan presents a simplified governance framework that unifies the EU AI Act and the NIST AI Risk Management Framework (AI RMF). Its premise is that both instruments, and especially the combination, confront practitioners with dozens or hundreds of items that are hard to implement, and that distilling them into 12 questions keeps the essential guidance while making it tractable.

The framework is layered. Level 1 sets four pillars aligned with NIST AI RMF governance areas: Discovery, Measurement, Mitigation and Accountability. Level 2 expands each pillar into three questions, covering system definition, identifying impacts and requirements, proactive measuring and monitoring, a measurement strategy, risk mitigation, incident handling, policies and structures, compliance and assessments, and transparency and notifications. Level 3, available only in the full version, adds recommended actions. Each question cites the relevant NIST AI RMF items and EU AI Act articles, for example MEASURE 2.11 for fairness and bias, Article 5 for prohibited applications and Article 53 for GPAI provider obligations.

The document also sets out five maturity levels, from no activities to adaptive activities, based on NIST's implementation tiers for privacy with adjustments, so organisations can locate their current position.

🧩 What’s Covered

  • Introduction and background (pp. 5–7): Frames the problem of proliferating AI governance frameworks and introduces the distillation approach; summarises the EU AI Act as the EU's flagship regulation that recently passed into law and the NIST AI RMF as voluntary US guidance with global influence.
  • Purpose and application: Two named audiences — AI developers and deployers, who use the questions to evaluate and improve their own governance, and AI buyers and investors, who use them during due diligence, procurement and investment.
  • A layered approach: Level 1 presents four pillars (Discovery, Measurement, Mitigation, Accountability); Level 2 expands each into three questions; Level 3, in the full version, adds recommended actions grounded in both instruments.
  • NIST AI RMF overview (p. 7): The four functions MAP, MEASURE, MANAGE and GOVERN with the RMF's own definitions, plus the example of category MEASURE 2 and subcategory MEASURE 2.11 on fairness and bias.
  • EU AI Act overview (pp. 8–11): Roles in scope under Article 3.2-8 (provider, deployer, importer, distributer, authorised representative, product manufacturer) and Article 25; influence in scope under Article 2.1; definitions of AI (Article 3.1), GPAI (Article 3.63), GPAI with systemic risk (Article 51) and high-risk systems (Article 6); requirements grouped as use case, GPAI and special transparency; and the staged timeline from entry into force on 1 August 2024 to 2 August 2027.
  • The 12 questions (pp. 13–17): Three questions per pillar with short prompts and references, for example System Definition (MAP 1.3, 1.4, 2.1, 3.1, 3.3), Proactive Measuring (MEA 2.3, 2.6-2.12; Articles 9, 17) and Compliance & Assessments (Articles 11, 13, 16b and Annexes IV, V, VIII).
  • Maturity levels (p. 18): Five levels from No Activities and Ad hoc Activities through Some Structure and High Structure to Adaptive Activities.
  • Additional resources (pp. 20–22): The AI Ethics Game workshops, implementation support, further reading on the Act and RMF, and profiles of TechBetter and the author.

💡 Why it matters?

Organisations that must show responsible AI governance face a crowded field of overlapping obligations. This resource offers a single question set that maps onto both the EU AI Act and the NIST AI RMF, so an assessment carried out once can be traced back to specific articles and RMF items. The maturity levels support proportionate target-setting, and the due-diligence use case matters to buyers and investors assessing vendors and portfolio companies. Because each question cites its sources, the framework also helps teams organise documentation for the Act's high-risk and transparency obligations.

❓ What’s Missing

The 12 questions are prompts rather than controls or acceptance criteria, and the recommended actions for each question appear only in the full version, not here. The maturity levels are described qualitatively, with no scoring method or evidence requirements. The document does not address sector-specific duties, enforcement practice, or interaction with regimes beyond the two it unifies. It is dated to August 2024 while the AI Act timeline runs to August 2027, so later amendments and guidance are not reflected. References are given in shorthand, such as MEA 2.6-2.12, without restating the underlying requirements.

👥 Best For

Best for AI governance leads and compliance teams that need a starting structure for assessing their organisation against the EU AI Act and the NIST AI RMF, for procurement and investment analysts running vendor or portfolio due diligence, and for consultants and trainers designing workshops or custom governance frameworks.

📄 Source Details

The 12 Essential Questions for Responsible AI Governance: Unifying EU AI Act & NIST AI RMF, by Ravit Dotan, published by TechBetter in August 2024 and described as the third iteration of the framework. 22 pages, licensed under Creative Commons Attribution-NonCommercial 4.0 International with a note that no AI training on the document is allowed. The extracted text covered all 22 pages, including the foreword, contents, introduction, the 12 questions and the additional-resources pages. No URL for the document itself is printed.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.