Operational AI Governance
NIVAI-AGF
AI Governance Framework
NIVAI-AGF:2026
You have deployed AI tools across your organisation. Do you know who is using what, where your data is going, and whether your governance holds up under scrutiny?
NIVAI-AGF:2026 is the certification standard for how organisations govern their use of AI, not just how they build it.
Section I
About the Standard
NIVAI-AGF focuses specifically on the AI interaction layer: how organisations use AI tools, what data moves through those interactions, which AI providers have the right agreements in place, whether AI sessions are traceable to individual identities, and whether acceptable use policy translates into verifiable practice.
116 controls across 18 domains. Every control requires specific, verifiable evidence: collected from connected tools, uploaded documents, endpoint monitoring, or structured registers. Not questionnaire answers.
Key Principle
Governance properties, not tier labels
Whether an AI tool is on a consumer or enterprise plan is irrelevant to certification. What matters is whether session data is training-opt-out confirmed, retention is bounded, usage is identity-attributed, and the organisation has administrative visibility. A team on a free plan with those four properties in place is more governed than one on an enterprise contract with none of them enforced.
Section II
Governance Domains
Section III
Nivaya Certified
Organisations that meet all five certification gates receive the Nivaya Certified designation, countersigned by a registered NIVAI auditor.
Nivaya Certified demonstrates that an organisation's AI governance evidence is collected, verified, and auditor-ready. It does not replace certification under ISO 42001, SOC 2, or any other framework. It addresses the AI governance layer those frameworks do not cover.
Regulatory Readiness
A defensible record when regulators ask
GDPR and POPIA enforcement is accelerating around AI data transfers. Regulators are asking organisations to demonstrate where AI session data was processed, which vendors had access, and what contractual protections were in place at the time.
Organisations certified under NIVAI-AGF:2026 hold a verified evidence record covering data residency (8 controls), privacy obligations (8 controls), and vendor agreements across every AI tool in active use. That record is auditor-countersigned and time-stamped.
Not a self-assessment. Evidence collected from connected systems, reviewed by an independent registered auditor, and ready to produce on request.
Collaborate
Contribute to NIVAI-AGF
NIVAI-AGF is a living standard. We actively seek input from AI governance practitioners, compliance professionals, legal and privacy experts, and security teams working with AI tools in production environments.
If you have identified gaps in the framework, controls that do not reflect current practice, or domains that require revision, we want to hear from you. Contributions are reviewed by the NIVAI standards committee ahead of each release cycle.
Community
Join the conversation
Discuss AI governance practices, ask questions about the NIVAI-AGF standard, and connect with compliance professionals, security teams, and practitioners working through certification.
Join #ai-governanceWorkspace: nivai-community.slack.com
Enquiries
Certification & Framework Enquiries
For certification requirements, auditor registration, or to request the full NIVAI-AGF control specification: