MAISSP framework

A lifecycle for governing change—not a one-time checklist.

Discover, Classify, Assess, Control, Monitor, and Improve connects AI decisions to an ongoing enterprise operating process.

1Discover
2Classify
3Assess
4Control
5Monitor
6Improve

Lifecycle

From visibility to continuous improvement.

01

Discover

Identify use cases, systems, vendors, data flows, and owners.

02

Classify

Group AI by purpose, impact, data sensitivity, autonomy, and exposure.

03

Assess

Evaluate material risk, control maturity, and decision context.

04

Control

Select proportionate governance, security, and operational safeguards.

05

Monitor

Track change, performance, incidents, exceptions, and control operation.

06

Improve

Use evidence and lessons learned to strengthen the program.

Context before control

The same technical capability can carry very different risk depending on purpose, affected people, data, access, autonomy, exposure, and reversibility. The lifecycle preserves that context before selecting controls.

Evidence over ceremony

Useful governance produces traceable ownership, review records, decisions, exceptions, actions, and learning—not documentation for its own sake.

Framework references

Our methodology is informed by the NIST AI Risk Management Framework, NIST AI 600-1 Generative AI Profile, relevant OWASP guidance for generative AI and LLM applications, and management-system principles found in ISO/IEC 42001.

MAISSP is independent. These references do not imply certification, formal conformance, endorsement, partnership, or affiliation. Applicability depends on organizational context, sector, jurisdiction, and risk posture.

Start with clarity

Apply the lifecycle to your environment.

Start with a clear view of current use, ownership, exposure, and priorities.

Request an AI Governance & Security Assessment