This document is a guide that outlines the AI governance framework and risk management processes integrated into the PrivIQ platform. It explains the challenges organizations face in governing AI, including the gap between AI usage and the ability to provide evidence for compliance to boards and regulators. The guide details the fiduciary duties of boards regarding ethical AI oversight and the increasing regulatory pressures that organizations must navigate. It describes the NIST AI Risk Management Framework (RMF) as the foundation for the AI governance program, which includes four key components: Govern, Map, Measure, and Manage. Each component is designed to address specific aspects of AI risk management, from establishing a culture and policy for AI governance to conducting quantitative and qualitative risk assessments. The guide emphasizes the importance of accountability and audit readiness, providing organizations with tools to manage third-party risks and ensure compliance with privacy regulations.