FORTHCOMING · WILEY FINANCE · 12 NOVEMBER 2026
The practitioner's book behind the framework. How to govern the AI you keep: strategically, operationally, and when things go wrong.
Written for the people who have to make AI governance work under live regulatory scrutiny: boards, risk officers, auditors, and regulators. Not a compliance checklist. A working method.

Wiley Finance · ISBN 978-1-394-44647-6 · Hardback and e-book · Foreword by Tobias Adrian (IMF) and Professor Tshilidzi Marwala (Under-Secretary-General of the United Nations)
Waiting for perfect clarity is not a governance position.
It is a governance failure.
Enterprise-wide AI Risk Management (EW-AiRMTM) - A Practical Framework for Managing AI Risk In Any Organisation.
What is Inside the Book?
Part 1
Chapters 1 - 3
Before you can govern AI, you need to agree on what counts as AI in the first place. Part I opens with sixteen precise, working definitions, from traditional machine learning through to agentic AI, foundation models, shadow AI and device-embedded AI, so a boardroom conversation about "AI risk" is finally about the same thing for everyone in the room. It then turns an honest, unflinching eye on the frameworks you already have: exactly where COSO, ISO 31000 and the standard ERM toolkit hold up against AI risk, and exactly where they don't. Part I closes by laying out the EW-AiRM™ architecture itself, three layers, six pillars, one ethical filter, as the blueprint everything that follows is built from.
Part 2
The largest part of the book, and the one most organisations skip. Six chapters, one pillar each: whether a deployment is genuinely necessary, whether the organisation is actually ready to govern it (including a full AI literacy requirement by role, and a governance culture maturity model), whether the data and technology stack can support it (with dedicated coverage of quantum resilience in your AI cryptographic stack, years before most risk functions are thinking about it), how risk appetite and prioritisation actually get decided, and how accountability holds up under pressure, including a named table of Governance Theatre Warning Signs for spotting the difference between governance that looks right and governance that works. It closes with the KXI methodology for monitoring an AI system through its entire lifecycle, not just at deployment.
Part 3
The chapter that turns "ethical AI" from an aspiration into something you can actually assess. Each of HAiPECR's seven dimensions, Human oversight, Accountability, inclusivity, Privacy, Ethics, Conduct risk and Rights, gets its own cross-layer assessment table, mapped explicitly to UNESCO's 2021 Recommendation on the Ethics of Artificial Intelligence and the wider regulatory doctrine behind it. This is the shortest part in the book and the one doing the most structural work: HAiPECR doesn't sit beside the three layers, it runs through all of them, and this is where you see exactly how.
Part 4
The engine room. Chapter 11 works through the MIT AI Risk Repository's seven domains and twenty-four subdomains one by one, each with its own risk profile and EW-AiRM™ governance augmentation. Chapter 12 builds the enhanced control framework across four quadrants, including a fully worked example (hallucination risk, taken step by step through the four-step control-to-risk mapping methodology) so the method is demonstrated, not just described. Chapter 13 is where the framework meets the calendar: the five non-negotiable requirements with their specific failure modes, the three-tier implementation model from SME to enterprise, a five-stage roadmap (Assess, Enhance, Build, Implement, Sustain), and six named implementation pitfalls with how to prevent each one before it costs you.
Part 5
The most dramatic chapter in the book, and the most operational. Eight categories of AI Black Swan, from emergent capability and systemic foundation-model concentration through to multi-agent emergence and the coming quantum cryptographic transition, each with its own governance response, not just a description of the danger. A full multi-agent containment architecture. A complete incident classification taxonomy with severity tiers, regulatory notification obligations and a Severity 1 critical incident response protocol you could hand to a crisis team on the worst day of the year. It closes with the post-incident learning cycle, because resilience isn't just surviving the black swan, it's institutionalising what you learned from it.
Part 6
The book's closing argument, and its safeguard against its own obsolescence. A jurisdiction-by-jurisdiction map of the global regulatory landscape, and the business case for early compliance as competitive advantage rather than cost. Then the part that sets EW-AiRM™ apart from a framework frozen at publication: the Taxonomy Governance Protocol, the mechanism that keeps the framework's evidence base current as the field moves, plus a ranked hierarchy of four alternative sources should the MIT AI Risk Repository itself ever become unavailable. This is the chapter that answers the question every serious reader eventually asks: what happens to this framework in three years?
Who is the Book for?
What to ask, what to sign off, and what a defensible AI risk posture looks like.
A method that produces artefacts that risk and compliance professionals can easily put into daily practice and that a regulator or auditor will recognise.
The enterprise-side counterpart to regulatory work on products/services with embedded AI systems and other Digital technologies.
A documented, publicly grounded framework suitable for teaching and research.
EW-AiRM™ is not a pandemic-era whiteboard exercise. It is the culmination of a documented line of governance instruments: the Global Conduct Risk Paradigm (GCRP, 2015), the Universal Conduct Risk Paradigm (UCRP, presented at UNECE in 2017 and published on the UNECE website), and HAiPECR™ (listed on the OECD AI Policy Observatory since 2023). The framework was developed alongside the author's role as project lead for the UNECE Common Regulatory Arrangement on products/services with embedded AI systems and other digital technologies, adopted across 56 member states.
The book and the free companion tools on this site are built from the same canonical reference base: When the framework updates, both update together.

ABOUT THE AUTHOR
Board portfolio executive, AI governance practitioner, and author. Founder of De-Risking Solutions Ltd and the Human-Ai.Institute. Independent Non-Executive Director on the Supervisory Council of Revolut Bank UAB since 2017. Honorary Professor at the University of Stirling. Clinical Professor of Practice at Woxsen University. Author of UNECE ECE/TRADE/486 (Common Regulatory Arrangement, 2024). Member of the EU AI Office DG CNECT Expert Group, GPAI Code of Practice plenary participant, UNESCO I4T Network founding member, ForHumanity Certified Auditor. HAIPECR has been listed on the OECD AI Policy Observatory since April 2023.
Full bio →One email when the book is published. Optionally, the quarterly framework update. No other use of your address.
The Human-Ai.Institute é um Think/Do Tank independente que promove o diálogo multilateral e multissetorial sobre governação de IA. O Instituto colabora com a ONU, a UNESCO, a OCDE, a Comissão Europeia e governos de todo o mundo.
Sede de EW-AiRM™ — a estrutura aberta de três camadas para a gestão de riscos de IA a nível empresarial, fundamentada em normas licenciadas publicamente e alinhada com a UNESCO, UNECE, NIST, ISO e o Regulamento de IA da UE.
Serviços comerciais de consultoria, formação e aconselhamento são prestados por De-Risking Solutions Ltd. e RiskAi.Ai
SOLUÇÕES DE IA E TECNOLOGIA
IA, ferramentas agênticas e soluções tecnológicas são fornecidas por Human-Ai.Solutions.
The Human-Ai.Institute
é executado e mantido por
De-Risking Solutions Ltd.
E-mail:
contact [at] human-ai.institute
Listado no Observatório de Políticas de IA da OCDE · Membro fundador da Rede de IA da Universidade das Nações Unidas · Alinhado com a UNESCO, UNECE WP.6, NIST e ISO 42001
EW-AiRM™ e HAiPECR™ são marcas comerciais da De-Risking Solutions Ltd., registadas em Inglaterra e no País de Gales (Número de Empresa 09900565). Todos os direitos reservados.
© 2026 The Human-Ai.Institute.