AI-BOK Reference Architecture
AI-BOK Reference Architecture (v1.2, June 2026)
================================================
This ArchiMate model is the architecture translation of the AI Body of Knowledge (AI-BOK) v1.2,
written by Jan Willem van Veen (ArchiXL).
The model provides a complete reference framework for AI governance and architecture,
structured according to the ArchiMate 3.2 metamodel across all layers, including the
cognition plane alongside the data, control and management planes.
Elements: 712
Relations: 1113
Views: 52 (folders 01-09: overview, business & organisation, application &
technology, motivation & principles, maturity & quality,
13 knowledge areas, failure modes, regulatory landscape, GEMMA pattern)
Source references per element are kept in dct:source properties (AI-BOK v1.2, module + section).
Full edition, templates and toolkit: https://www.ai-bok.nl (models: /architecture).
The accompanying paper was peer-reviewed at EA4AI @ CBI-EDOC 2026 (Springer LNBIP).
KA1: AI Governance
Create conditions under which AI systems deliver maximum value within acceptable risk boundaries.
High
3-Defined
Very High
High
AI-BOK v1.2, Module 1, section 1.1
KA2: AI Strategy & Portfolio Management
Maximum organisational value from AI investments through systematic selection and prioritisation.
High
3-Defined
Medium
Limited
AI-BOK v1.2, Module 1, section 2.1
KA3: AI Architecture
A coherent, repeatable and evolvable blueprint for AI capabilities.
Very High
3-Defined
High
Limited
AI-BOK v1.2, Module 1, section 3.1
KA4: AI Lifecycle Management
Predictable, repeatable and governable progress of AI initiatives.
High
3-Defined
Medium
Limited
AI-BOK v1.2, Module 1, section 4.1
KA5: Data & Semantics for AI
Reliable, traceable and semantically anchored data foundation for AI.
Very High
3-Defined
High
High
AI-BOK v1.2, Module 1, section 5.1
KA6: Model Management
Reliable, reproducible and responsible model portfolio.
Very High
3-Defined
High
High
AI-BOK v1.2, Module 1, section 6.1
KA7: AI Interaction & User Experience
AI interactions that are user-centred, reliable and inclusive.
High
2-Repeatable
Medium
Limited
AI-BOK v1.2, Module 1, section 7.1
KA8: AI Operations
Reliable, observable and cost-efficient AI operations in production.
High
3-Defined
High
Limited
AI-BOK v1.2, Module 1, section 8.1
KA9: AI Risk Management & Safety
Proactively identify, assess and mitigate AI-related risks.
Very High
3-Defined
Very High
High
AI-BOK v1.2, Module 1, section 9.1
KA10: AI Compliance & Audit
Verifiable, risk-based compliance of AI systems.
High
3-Defined
Very High
High
AI-BOK v1.2, Module 1, section 10.1
KA11: AI Ethics & Responsible AI
Ethical considerations structurally embedded in the design and deployment of AI.
High
2-Repeatable
High
High
AI-BOK v1.2, Module 1, section 11.1
KA12: AI Knowledge & Context Management
AI systems produce grounded, traceable and semantically vamemberated output.
Very High
3-Defined
High
High
AI-BOK v1.2, Module 1, section 12.1
KA13: AI Literacy & Capability Development
Build and sustain the human knowledge, skills and judgement required to develop, deploy, supervise, use and decommission AI systems responsibly. Treats AI literacy as a structural capability tied to systems in production, with role-specific competencies, refresh cycles, evidence and measurement. Anchors EU AI Act Article 4 compliance.
High
AI-BOK v1.1
Assurance & Accountability
AI-BOK v1.1, Module 1, KA13
Idee & Kans
Identify AI opportunities and assess business value.
Design
Architecture, data preparation and model selection.
Development
Training, fine-tuning, prompt engineering and evaluation.
Production
Deployment, integration, monitoring and operations.
Value
Measurable business value and continuous improvement.
AI Governance & Steering
Establishing and enforcing AI policy, principles and mandates.
High
AI-BOK v1.2, Module 1, section 1.3
AI Strategy & Portfolio Management
Selection, prioritisation and monitoring of AI initiatives.
High
AI-BOK v1.2, Module 1, section 2.3
AI Architecture Management
Designing and maintaining the AI reference architecture.
Very High
AI-BOK v1.2, Module 1, section 3.3
AI Lifecycle Management
Guiding AI initiatives through all phases of the lifecycle.
High
AI-BOK v1.2, Module 1, section 4.3
AI Data Management & Semantics
Ensuring data quality, semantic precision and knowledge sources.
Very High
AI-BOK v1.2, Module 1, section 5.3
AI Model Management
Registration, validation and version management of AI models.
Very High
AI-BOK v1.2, Module 1, section 6.3
AI Interaction Management
Design and optimisation of AI user interactions.
High
AI-BOK v1.2, Module 1, section 7.3
AI Operations Management
Deployment, monitoring and operational reliability.
High
AI-BOK v1.2, Module 1, section 8.3
AI Risk Management
Identification, assessment and mitigation of AI risks.
Very High
AI-BOK v1.2, Module 1, section 9.3
AI Compliance & Audit
Ensuring compliance with laws and regulations.
High
AI-BOK v1.2, Module 1, section 10.3
AI Ethics & Accountability
Ensuring ethical principles in AI systems.
High
AI-BOK v1.2, Module 1, section 11.3
AI Knowledge Management
Curation and governance of knowledge sources for AI grounding.
Very High
AI-BOK v1.2, Module 1, section 12.3
AI Literacy Management
AI Portfolio
Overview of all AI initiatives with status and priority.
No personal data
Confidential
5 years na afloop
AI-BOK v1.2, Module 1, section 2.4
AI Business Case
Justification of AI initiative with expected value and risks.
No personal data
Confidential
5 years na afloop
AI-BOK v1.2, Module 3, section 3.1.1
Prompt Library
Curated collection of prompt templates and strategies.
Possibly personal data
Internal
AI-BOK v1.2, Module 1, section 7.4
AI Risk Register
Register of identified AI risks with mitigation.
Possibly personal data
Confidential
Permanent
AI-BOK v1.2, Module 1, section 9.4
Algorithm Register
Public register of deployed AI systems (transparency).
No personal data
Public
Permanent (legal obligation)
Mandatory (Art. 71)
AI-BOK v1.2, Module 1, section 10.4
Knowledge Source Register
Register of authoritative knowledge sources with classification.
No personal data
Internal
AI-BOK v1.2, Module 1, section 12.4
Shadow AI Inventory
Register of unapproved AI applications in the organisation.
Possibly personal data
Confidential
AI-BOK v1.2, Module 3, section 3.1
AI Strategy Document
Multi-year AI strategy document, reviewed annually.
No personal data
Internal
AI-BOK v1.2, Module 1, section 2.4
AI Roadmap
Rolling 12-18 month roadmap for AI initiatives.
No personal data
Internal
AI-BOK v1.2, Module 1, section 2.4
AI Capacity Plan
Plan for talent, technology, data and budget.
No personal data
Confidential
AI-BOK v1.2, Module 1, section 2.6
AI Technology Radar
Semi-annual overview: adopt, trial, assess, hold.
No personal data
Internal
AI-BOK v1.2, Module 1, section 3.6
Integration Patterns Catalogue
Catalogue of integration patterns (MCP, A2A, governance hooks).
No personal data
Internal
AI-BOK v1.2, Module 1, section 3.13
Interaction Patterns Catalogue
Catalogue of AI interaction patterns and guidelines.
No personal data
Internal
AI-BOK v1.2, Module 1, section 7.4
Trusted Knowledge Sources Catalogue
Register with authority levels and metadata per knowledge source.
No personal data
Internal
AI-BOK v1.2, Module 1, section 12.4
Interaction
Een uitwisseling tussen AI-systeem en gebruiker of ander systeem.
AI-BOK v1.2, Module 3, section 3.2
Decision
Uitkomst van een AI-ondersteund of -uitgevoerd besluitvormingsproces.
AI-BOK v1.2, Module 3, section 3.2
AI Policy Framework
Organisation-wide AI policy with principles, roles and mandates.
No personal data
Internal
Permanent
AI-BOK v1.2, Module 1, section 1.2
Agent Mandate
Formal specification of autonomy boundaries and escalation rules per agent.
No personal data
Internal
Agent lifetime
AI-BOK v1.2, Module 1, section 1.5
AI Governance Charter
Formal document with AI policy, principles, roles and mandates.
No personal data
Internal
AI-BOK v1.2, Module 3, section 3.1
Data Contract
Agreement on data quality and delivery between systems.
Possibly personal data
Confidential
AI-BOK v1.2, Module 3, section 3.1
AI Reference Architecture
Blueprint for AI capabilities including Cognition Plane.
No personal data
Internal
Permanent
AI-BOK v1.2, Module 1, section 3.4
Terminology Framework
Authoritative concept framework (SKOS/NL-SBB) for AI systems.
No personal data
Public
AI-BOK v1.2, Module 1, section 5.4
Model Card
Standardised documentation of an AI model.
Possibly personal data (training data description)
Internal
Model lifetime + 5 years
Mandatory for high-risk AI
AI-BOK v1.2, Module 1, section 6.4
Dataset Specification
Documentation of dataset per Datasheets for Datasets.
Possibly personal data (dataset may contain PII)
Internal
Dataset lifetime + 5 years
AI-BOK v1.2, Module 1, section 5.13
EU AI Act Compliance Checklist
Checklist for EU AI Act compliance per risk class.
No personal data
Internal
Directly related
AI-BOK v1.2, Module 3, section 3.1
Red Team Report
Results of adversarial testing of AI systems.
Possibly personal data
Secret
5 years
Recommended
AI-BOK v1.2, Module 3, section 3.1
Bias Audit Report
Results of bias analysis and fairness assessment.
Possibly special category personal data (bias on protected groups)
Confidential
10 years
Mandatory for high-risk AI (Art. 10)
AI-BOK v1.2, Module 3, section 3.1
AI Bill of Materials
Complete inventory of components, models, data and dependencies.
No personal data
Internal
Recommended
AI-BOK v1.2, Module 3, section 3.1
Architecture Decision Record
Documentation of architecture decisions with rationale.
No personal data
Internal
AI-BOK v1.2, Module 3, section 3.1
Experiment Log
Documentation of ML experiments with parameters and results.
Possibly personal data
Internal
5 years
AI-BOK v1.2, Module 3, section 3.1
Decommissioning Report
Documentation of responsible decommissioning of AI systems.
No personal data
Internal
5 years
AI-BOK v1.2, Module 3, section 3.1
RACI Matrix for AI Roles
Matrix documenting responsibilities per AI role and KA.
No personal data
Internal
AI-BOK v1.2, Module 2, section 2.3
Architecture Conformity Report
Report on conformity to the AI reference architecture.
No personal data
Internal
AI-BOK v1.2, Module 1, section 3.8
Retraining Plan
Per model: frequency, validation criteria, approval process.
No personal data
Internal
AI-BOK v1.2, Module 1, section 4.6
Quality Gate Checklist
Checklist per lifecycle phase with criteria and deliverables.
No personal data
Internal
AI-BOK v1.2, Module 3, section 3.1
Decommissioning Protocol
Protocol for responsible decommissioning of AI systems.
No personal data
Internal
AI-BOK v1.2, Module 3, section 3.1.8
Data Lineage Documentation
Documentation of data provenance and transformations.
Possibly personal data
Confidential
AI-BOK v1.2, Module 1, section 5.6
Data Quality Report
Report on data quality per dataset.
Possibly personal data
Internal
AI-BOK v1.2, Module 1, section 5.4
Human-in-the-Loop Protocol
Protocols and escalation specifications per risk level.
No personal data
Internal
AI-BOK v1.2, Module 1, section 7.6
Drift Detection Report
Rapport bij gedetecteerde data- of conceptdrift.
Possibly personal data
Internal
AI-BOK v1.2, Module 1, section 8.6
AI Incident Report
Incidentrapport met root-cause-analyse.
Possibly personal data
Confidential
AI-BOK v1.2, Module 1, section 8.8
AI Incident Response Plan
Plan voor AI-specifieke incidentrespons.
No personal data
Confidential
AI-BOK v1.2, Module 1, section 9.6
AI Ethics Framework
Organisation-specific ethical framework and code of conduct for AI.
No personal data
Internal
AI-BOK v1.2, Module 1, section 11.4
Explainability Documentation
Per AI system and decision type.
No personal data
Internal
AI-BOK v1.2, Module 1, section 11.6
Knowledge Currency Report
Report on currency and refresh schedule of knowledge sources.
No personal data
Internal
AI-BOK v1.2, Module 1, section 12.8
Lessons Learned Document
Documentation of lessons learned during evolution or decommissioning.
No personal data
Internal
AI-BOK v1.2, Module 3, section 3.1.8
AI Board
Strategic decision-making.
AI-BOK v1.2, Module 2, section 2.5
AI Review Committee
Tactical quality gate reviews.
AI-BOK v1.2, Module 2, section 2.5
AI Ethics Committee
Advisory on ethical dilemmas.
AI-BOK v1.2, Module 2, section 2.5
AI Risk Committee
Risk overview and acceptance.
AI-BOK v1.2, Module 2, section 2.5
AI Centre of Excellence
Central knowledge centre for AI expertise, best practices and reusable components.
AI-BOK v1.2, Module 2, section 2.5
OpenAI
American AI company, creator of GPT-4 and ChatGPT.
https://www.openai.com
LLM Provider
Commercial SaaS
US
High
Yes
Anthropic
AI-veiligheidsbedrijf, maker van Claude.
https://www.anthropic.com
LLM Provider
Commercial SaaS
US
High
Yes
Meta
Technologiebedrijf, maker van open-source LLaMA-modellen.
https://ai.meta.com
LLM Provider
Open Source
US
High
Yes
Google
Technology company, creator of Gemini and TensorFlow.
https://ai.google
LLM Provider
Commercial SaaS
US
High
Yes
Google Cloud
Cloud AI-platform met Vertex AI.
https://cloud.google.com/vertex-ai
Cloud Platform
Commercial SaaS
US
High
Yes
Google PAIR
People + AI Research initiative.
https://pair.withgoogle.com
Research
Open Source
US
Medium
Nee
Cohere
Enterprise AI platform for NLP and embeddings.
https://www.cohere.com
LLM Provider
Commercial SaaS
Canada
High
Yes
Microsoft
Technologiebedrijf, Azure AI en enterprise-integratie.
https://azure.microsoft.com/ai
Cloud Platform
Commercial SaaS
US
High
Yes
Amazon (AWS)
Cloud provider with Bedrock, SageMaker and AI services.
https://aws.amazon.com/ai
Cloud Platform
Commercial SaaS
US
High
Yes
NVIDIA
GPU- en AI-infrastructuurleverancier.
https://www.nvidia.com/ai
Hardware & AI Infra
Commercial
US
High
Yes
LangChain Inc.
Framework for LLM applications, RAG and agents.
https://www.langchain.com
AI Framework
Open Source
US
Medium
Nee
CrewAI
Multi-agent orkestratie framework.
https://www.crewai.com
AI Framework
Open Source
US
Low
Nee
LlamaIndex
Data framework for LLM applications and RAG.
https://www.llamaindex.ai
AI Framework
Open Source
US
Medium
Nee
Pinecone
Managed vector database voor AI-applicaties.
https://www.pinecone.io
Vector Database
Commercial SaaS
US
High
Nee
SeMI Technologies
Maker van Weaviate open-source vector database.
https://www.weaviate.io
Vector Database
Open Source
Netherlands
Medium
Nee
Qdrant
Open-source vector zoekmachine.
https://www.qdrant.tech
Vector Database
Open Source
Germany
Medium
Nee
Chroma
Open-source embedding database.
https://www.trychroma.com
Vector Database
Open Source
US
Low
Nee
Neo4j Inc.
Marktleider in graph databases.
https://www.neo4j.com
Knowledge Graph
Commercial
Sweden/US
High
Nee
Ontotext
Semantic graph database en kennistechnologie.
https://www.ontotext.com
Knowledge Graph
Commercial
Bulgaria
Medium
Nee
Apache Foundation
Open-source softwarestichting, o.a. Jena triple store.
https://jena.apache.org
Open Source Stichting
Open Source
US
High
Nee
Stardog
Enterprise knowledge graph platform.
https://www.stardog.com
Knowledge Graph
Commercial
US
Medium
Nee
Stanford / W3C
Academic ontology editor Protege.
https://protege.stanford.edu
Academisch
Open Source
US
Medium
Nee
Triply
Netherlandss bedrijf, linked data platform TriplyDB.
https://www.triply.cc
Knowledge Graph
Commercial
Netherlands
Medium
Nee
Databricks
Unified data analytics en AI-platform.
https://www.databricks.com
Data Platform
Commercial SaaS
US
High
Nee
Snowflake
Cloud data warehouse platform.
https://www.snowflake.com
Data Platform
Commercial SaaS
US
High
Nee
MLflow (Linux Foundation)
Open-source ML lifecycle management.
https://www.mlflow.org
MLOps
Open Source
US
High
Nee
Weights & Biases
ML experiment tracking en model management.
https://www.wandb.ai
MLOps
Commercial SaaS
US
Medium
Nee
Kubeflow (Linux Foundation)
ML pipeline orkestratie op Kubernetes.
https://www.kubeflow.org
MLOps
Open Source
US
Medium
Nee
Neptune.ai
Experiment tracking voor ML-teams.
https://www.neptune.ai
MLOps
Commercial SaaS
Poland
Medium
Nee
ClearML
Open-source MLOps platform.
https://www.clear.ml
MLOps
Open Source
Israel
Medium
Nee
DVC (Iterative)
Data en model version control.
https://www.dvc.org
MLOps
Open Source
US
Medium
Nee
Hugging Face
Open-source AI-community, model hub en tooling.
https://www.huggingface.co
AI Platform
Open Source
US/France
High
Yes
Guardrails AI
Output validation and filtering for LLMs.
https://www.guardrailsai.com
AI Safety
Open Source
US
Low
Yes
Garak Project
LLM vulnerability scanning toolkit.
https://github.com/leondz/garak
AI Safety
Open Source
UK
Low
Yes
PromptFoo
LLM evaluatie en red teaming tool.
https://www.promptfoo.dev
AI Evaluation
Open Source
US
Low
Nee
RAGAS Project
RAG-evaluatie framework.
https://www.ragas.io
AI Evaluation
Open Source
India
Low
Nee
Confident AI
LLM-evaluatieplatform DeepEval.
https://www.confident-ai.com
AI Evaluation
Commercial SaaS
US
Low
Nee
TruEra
AI quality en observability platform.
https://www.truera.com
AI Observability
Commercial SaaS
US
Medium
Nee
Stanford CRFM
Center for Research on Foundation Models.
https://crfm.stanford.edu
Academisch
Open Source
US
Low
Nee
EleutherAI
Open-source AI-onderzoekslaboratorium.
https://www.eleuther.ai
Research
Open Source
US
Low
Nee
Prometheus (CNCF)
Open-source monitoring en alerting.
https://www.prometheus.io
Monitoring
Open Source
US
High
Nee
Grafana Labs
Observability platform, dashboards en logging.
https://www.grafana.com
Monitoring
Open Source
Sweden
High
Nee
Datadog
Cloud monitoring en analytics platform.
https://www.datadoghq.com
Monitoring
Commercial SaaS
US
High
Nee
Elastic
Zoek- en observability platform (ELK Stack).
https://www.elastic.co
Monitoring
Open Source
Netherlands/US
High
Nee
OpenTelemetry (CNCF)
Open-source observability framework.
https://www.opentelemetry.io
Monitoring
Open Source
US
High
Nee
Jaeger (CNCF)
Distributed tracing systeem.
https://www.jaegertracing.io
Monitoring
Open Source
US
Medium
Nee
Evidently AI
ML monitoring en data drift detectie.
https://www.evidentlyai.com
AI Monitoring
Open Source
US
Medium
Yes
WhyLabs
AI observability en data monitoring.
https://www.whylabs.ai
AI Monitoring
Commercial SaaS
US
Medium
Yes
NannyML
Post-deployment ML performance monitoring.
https://www.nannyml.com
AI Monitoring
Open Source
Belgium
Medium
Yes
Helicone
LLM observability en token tracking.
https://www.helicone.ai
AI Monitoring
Commercial SaaS
US
Low
Nee
LLMeter Project
LLM inference cost benchmarking.
https://github.com/aws-samples/llmeter
AI Monitoring
Open Source
US
Low
Nee
PromptLayer
Prompt versiebeheer en evaluatie.
https://www.promptlayer.com
Prompt Management
Commercial SaaS
US
Low
Nee
Humanloop
LLM-applicatie ontwikkelplatform.
https://www.humanloop.com
Prompt Management
Commercial SaaS
UK
Medium
Nee
Kong Inc.
API gateway en service mesh.
https://www.konghq.com
API Gateway
Open Source
US
High
Nee
LiteLLM
Unified LLM API proxy en load balancer.
https://www.litellm.ai
API Gateway
Open Source
US
Low
Nee
OpenRouter
Unified API voor meerdere LLM-providers.
https://www.openrouter.ai
API Gateway
Commercial SaaS
US
Low
Nee
Keycloak (Red Hat)
Open-source identity en access management.
https://www.keycloak.org
Identity & Access
Open Source
US
High
Nee
Okta
Enterprise identity platform.
https://www.okta.com
Identity & Access
Commercial SaaS
US
High
Nee
Open Policy Agent (CNCF)
Unified policy engine, policy-as-code.
https://www.openpolicyagent.org
Policy Engine
Open Source
US
High
Nee
Cedar (AWS)
Policy language voor autorisatielogica.
https://www.cedarpolicy.com
Policy Engine
Open Source
US
Medium
Nee
IBM
AI Fairness 360 toolkit voor biasdetectie.
https://aif360.mybluemix.net
AI Platform
Open Source
US
High
Yes
Aequitas Project
Open-source bias audit toolkit.
https://aequitas.dssg.io
AI Fairness
Open Source
US
Low
Yes
SHAP Project
SHapley Additive exPlanations voor model interpretatie.
https://shap.readthedocs.io
Explainability
Open Source
US
Medium
Yes
LIME Project
Local Interpretable Model-agnostic Explanations.
https://github.com/marcotcr/lime
Explainability
Open Source
US
Medium
Yes
Great Expectations
Data validation and documentation framework.
https://www.greatexpectations.io
Data Quality
Open Source
US
Medium
Nee
Soda
Data quality monitoring platform.
https://www.soda.io
Data Quality
Commercial SaaS
Belgium
Medium
Nee
HumanSignal
Maker van Label Studio, open-source annotatie.
https://www.humansignal.com
Annotation
Open Source
US
Medium
Nee
Explosion AI
Creator of spaCy and Prodigy annotation tool.
https://www.explosion.ai
NLP Tooling
Commercial
Germany
Medium
Nee
TensorFlow (Google)
Open-source ML framework en serving.
https://www.tensorflow.org
ML Framework
Open Source
US
High
Nee
PyTorch (Meta)
Open-source deep learning framework.
https://www.pytorch.org
ML Framework
Open Source
US
High
Nee
GitHub
Code hosting en CI/CD platform.
https://github.com
DevOps Platform
Commercial SaaS
US
High
Nee
GitLab
DevOps platform met geïntegreerde CI/CD.
https://www.gitlab.com
DevOps Platform
Open Source
US
High
Nee
Jenkins (Linux Foundation)
Open-source automation server.
https://www.jenkins.io
CI/CD
Open Source
US
High
Nee
Docker Inc.
Containerisatieplatform.
https://www.docker.com
Container Platform
Open Source
US
High
Nee
Kubernetes (CNCF)
Container orkestratie standaard.
https://www.kubernetes.io
Container Orchestratie
Open Source
US
High
Nee
Helm (CNCF)
Kubernetes package manager.
https://www.helm.sh
Package Management
Open Source
US
High
Nee
HashiCorp
Infrastructure-as-code (Terraform).
https://www.hashicorp.com
Infrastructure
Open Source
US
High
Nee
Pulumi
Infrastructure-as-code in programmeertalen.
https://www.pulumi.com
Infrastructure
Open Source
US
Medium
Nee
Atlassian
Samenwerkingsplatform, maker van Confluence.
https://www.atlassian.com
Collaboration
Commercial SaaS
Australia
High
Nee
Feast (Linux Foundation)
Open-source feature store voor ML.
https://www.feast.dev
Feature Store
Open Source
US
Medium
Nee
Tecton
Enterprise feature platform voor ML.
https://www.tecton.ai
Feature Store
Commercial SaaS
US
Medium
Nee
OpenLineage (Linux Foundation)
Open-source data lineage standaard.
https://www.openlineage.io
Data Lineage
Open Source
US
Medium
Nee
ArchiXL
Dutch architecture firm, specialist in enterprise and information architecture. Creator of WikiXL, ArchiMedes and BegrippenXL.
https://www.archixl.nl
Architecture
Commercial SaaS
Netherlands
Medium
Nee
Chief AI Officer (CAIO)
Ultimately responsible for AI strategy, governance and value creation. Chair of the AI Board and guardian of AI-BOK implementation.
Executive
0,5-1,0
AI-BOK v1.2, Module 2, section 2.2
AI Portfolio Manager
Manages the AI portfolio: selection, prioritisation and monitoring of AI initiatives based on business value and strategic fit.
Senior
0,5-1,0
AI-BOK v1.2, Module 2, section 2.2
AI Ethics Advisor
Advises on ethical aspects of AI systems: fairness, bias, transparency and societal impact. Member of the AI Ethics Committee.
Senior
0,2-0,5
AI-BOK v1.2, Module 2, section 2.2
AI Product Owner
Responsible for functional steering of an AI initiative: requirements, prioritisation and acceptance from the business perspective.
Senior
1,0
AI-BOK v1.2, Module 2, section 2.2
AI Architect
Designs the AI reference architecture: planes, ABBs, integration patterns and technology choices. Ensures coherence and reusability.
Senior
1,0-2,0
AI-BOK v1.2, Module 2, section 2.2
AI Risk Manager
Identifies, assesses and mitigates AI-related risks. Manages the AI risk register and advises on risk classification (EU AI Act).
Senior
0,5-1,0
AI-BOK v1.2, Module 2, section 2.2
AI Governance Lead
Operationalises AI governance: policy frameworks, mandates, quality gates and compliance processes. Member of the AI Review Committee.
Medior
0,5
AI-BOK v1.2, Module 2, section 2.2
AI Knowledge Manager
Curates and manages knowledge sources for AI grounding: terminology frameworks, knowledge graphs and document collections.
Senior
1,0
AI-BOK v1.2, Module 2, section 2.2
AI Engineer
Develops, trains and optimises AI models: data engineering, model training, fine-tuning, prompt engineering and evaluation.
Medior
2,0-5,0
AI-BOK v1.2, Module 2, section 2.2
AI Interaction Designer
Designs user interaction with AI systems: conversation flows, explainability, feedback mechanisms and human-in-the-loop patterns.
Medior
0,5-1,0
AI-BOK v1.2, Module 2, section 2.2
AI Operations Engineer
Responsible for deployment, monitoring and operational management of AI systems in production. Monitors SLAs and performance.
Medior
1,0-3,0
AI-BOK v1.2, Module 2, section 2.2
AI Quality Analyst
Evaluates and validates AI systems for quality: faithfulness, relevance, bias, robustness and conformity to quality gates.
Medior
0,5-1,0
AI-BOK v1.2, Module 2, section 2.2
AI Auditor
Performs independent audits on AI systems: compliance, technical conformity, data quality and governance adherence.
Senior
0,2-0,5
AI-BOK v1.2, Module 2, section 2.2
AI System Administrator
Manages the technical AI infrastructure: platforms, API gateways, model registries, monitoring tools and access control.
Junior/Medior
1,0-2,0
AI-BOK v1.2, Module 2, section 2.2
AI Trainer/Annotator
Prepares training data: labelling, annotation, quality control and validation of datasets for supervised learning.
Junior
1,0-3,0
AI-BOK v1.2, Module 2, section 2.2
AI Domain Expert
Provides domain knowledge for AI systems: output validation, curation of knowledge sources and assessment of domain-specific quality.
Senior (domein)
0,2-0,5
AI-BOK v1.2, Module 2, section 2.2
AI Change Manager
Guides organisational change in AI adoption: stakeholder management, training, communication and culture change.
Senior
0,5-1,0
AI-BOK v1.2, Module 2, section 2.2
AI Agent Governor
Manages autonomous AI agents: defines mandates, escalation rules, autonomy boundaries and monitors agent behaviour in production.
Senior
0,5-1,0
AI-BOK v1.2, Module 2, section 2.2
AI Compliance Officer
Ensures compliance with AI legislation: EU AI Act, GDPR, sector-specific requirements and reporting obligations.
Senior
0,5-1,0
AI-BOK v1.2, Module 2, section 2.2
Knowledge Engineer
Designs and manages knowledge graphs and ontologies for AI grounding.
AI-BOK v1.2, Module 2, section 2.2
RAG Architect
Designs and optimises RAG pipelines and retrieval strategies.
AI-BOK v1.2, Module 2, section 2.2
AI Fairness Engineer
Specialist in bias-detectie, fairness-metrics en debiasing-technieken.
AI-BOK v1.2, Module 2, section 2.2
Explainability Specialist
Designt en implementeert uitlegbaarheidsmechanismen (SHAP, LIME).
AI-BOK v1.2, Module 2, section 2.2
AI Security Architect
Beveiligingsarchitectuur voor AI-systemen, prompt injection preventie.
AI-BOK v1.2, Module 2, section 2.2
AI Platform Engineer
Builds and manages the AI platform (MLOps, serving, monitoring).
AI-BOK v1.2, Module 2, section 2.2
Content Curator
Selects and qualifies knowledge sources for RAG pipelines.
AI-BOK v1.2, Module 2, section 2.2
Semantic Specialist
Expert in terminologieraamwerken, SKOS, linked data voor AI.
AI-BOK v1.2, Module 2, section 2.2
AI Solution Architect
Designt concrete AI-oplossingen binnen de referentiearchitectuur.
AI-BOK v1.2, Module 2, section 2.2
Data Protection Officer
Data Protection Officer, oversight of GDPR compliance in AI.
AI-BOK v1.2, Module 2, section 2.2
AI Literacy Officer
Accountable for AI Literacy & Capability Development (KA13). Maintains competency profiles, curriculum, literacy register, Article 4 evidence file, refresh adherence, and effectiveness measurement. Reports into the AI Board.
Tactical/Cross-functional
20
AI-BOK v1.1
KA13
AI-BOK v1.1, Module 2, Role 20
Ideation & Exploration
Identification of AI opportunities, feasibility analysis and alignment with business strategy. Deliverable: validated AI business case.
Manual
Human-in-command
AI-BOK v1.2, Module 3, section 3.1.1
Design & Architecture
Architecture design, model selection, data preparation and integration patterns. Deliverable: approved architecture blueprint.
Partially automated
Human-in-command
AI-BOK v1.2, Module 3, section 3.1.2
Data Acquisition & Preparation
Collection, cleaning, labelling and validation of training and evaluation data. Deliverable: qualified datasets.
Largely automated
Human-in-the-loop
AI-BOK v1.2, Module 3, section 3.1.3
Model Development & Training
Training, fine-tuning, prompt engineering and experimentation. Deliverable: trained and validated model with model card.
Largely automated
Human-in-the-loop
AI-BOK v1.2, Module 3, section 3.1.4
Evaluation & Validation
Quality evaluation on faithfulness, bias, robustness and conformity to quality gates. Deliverable: evaluation report and go/no-go.
Automated with human review
Human-in-the-loop
AI-BOK v1.2, Module 3, section 3.1.5
Deployment & Integration
Deployment to production, integration with business processes and user acceptance. Deliverable: operational AI system.
Automated (CI/CD)
Human-on-the-loop
AI-BOK v1.2, Module 3, section 3.1.6
Monitoring & Operations
Continuous monitoring of performance, drift, costs and anomalies. Triggers retraining loop on degradation. Deliverable: operational logs and alerts.
Fully automated
Human-on-the-loop
AI-BOK v1.2, Module 3, section 3.1.7
Evolution & Decommissioning
Evaluation of continued use, knowledge transfer and responsible decommissioning. Deliverable: lessons learned and decommissioning report.
Manual met toolondersteuning
Human-in-command
AI-BOK v1.2, Module 3, section 3.1.8
TOGAF Integration
AI Architecture as 5th layer (Cognition Plane). AI Architect on Enterprise Architecture Board.
AI-BOK v1.2, Module 3, section 3.3
DAMA-DMBOK Integration
KA5/KA12 extend data governance. Terminology frameworks in metadata management.
AI-BOK v1.2, Module 3, section 3.3
COBIT/ITIL Integration
AI systems in CMDB. AI incidents via existing incident management + AI classification.
AI-BOK v1.2, Module 3, section 3.3
COSO/ISO 31000 Integration
AI risk register integrated in enterprise risk register. Three Lines of Defence with AI-specific controls.
AI-BOK v1.2, Module 3, section 3.3
GDPR Integration
DPIA for AI systems. Art. 22 right to explanation operationalised. Privacy by design.
AI-BOK v1.2, Module 3, section 3.3
Agile/SAFe Integration
Gate criteria as Definition of Done per PI. MLOps pipeline as CD Pipeline equivalent.
AI-BOK v1.2, Module 3, section 3.3
Retraining Loop
P7 → P4: Performance degradation triggers retraining.
AI-BOK v1.2, Module 3, section 3.1.9
Evaluation Loop
P5 → P4: Gezakte evaluatie keert terug naar modelontwikkeling.
AI-BOK v1.2, Module 3, section 3.1.9
Evolution Loop
P8 → P1: Fundamental changes restart the full cycle.
AI-BOK v1.2, Module 3, section 3.1.9
Data Bias Assessment
Assessment per dataset on bias and representativeness.
Possibly special category personal data
Confidential
AI-BOK v1.2, Module 1, section 5.8
Supply Chain Risk Assessment
Risk assessment of external models, datasets, services.
No personal data
Confidential
AI-BOK v1.2, Module 1, section 9.13
Gate: Business Case Approved
AI-BOK v1.2, Module 3, section 3.1.1
Gate: Architecture Review
AI-BOK v1.2, Module 3, section 3.1.2
Gate: Data Readiness
AI-BOK v1.2, Module 3, section 3.1.3
Gate: Model Validated
AI-BOK v1.2, Module 3, section 3.1.4
Gate: Production Ready
AI-BOK v1.2, Module 3, section 3.1.5
Gate: Go Live
AI-BOK v1.2, Module 3, section 3.1.6
Gate: Operations Stable
AI-BOK v1.2, Module 3, section 3.1.7
Audit Trail
Immutable log of AI decisions and interactions.
Likely personal data (decision history)
Confidential
10 years (EU AI Act)
Mandatory (Art. 12)
AI-BOK v1.2, Module 1, section 10.4
Dataset
Verzameling data voor training, evaluatie of operationeel gebruik.
AI-BOK v1.2, Module 3, section 3.2
Knowledge Source
Externe of interne bron van gestructureerde kennis (ontologie, KG, vocabulaire).
AI-BOK v1.2, Module 3, section 3.2
Prompt/Instruction
Instructie of context die het gedrag van een AI-component stuurt.
AI-BOK v1.2, Module 3, section 3.2
LLM/Foundation Model Service
Inference endpoint for language models. Provides text, image and code generation via foundation models.
Current
Cognition Plane
Commercial
SaaS / On-premise
REST API / OpenAI-compatible
99,9% (business hours)
High (prompts may contain personal data)
AI-BOK v1.2, Module 3, section 3.6.5a
Agent Orchestrator
Orchestration of autonomous AI agents, task decomposition, tool use and multi-agent coordination.
Current
Cognition Plane
Open Source
On-premise
MCP / A2A
99,9%
High (agent has access to business data)
AI-BOK v1.2, Module 3, section 3.6.5a
RAG Pipeline
Retrieval-Augmented Generation: retrieves relevant context from knowledge sources and feeds it to the LLM.
Current
Cognition Plane
Open Source
On-premise
REST API / Python SDK
99,9%
High (knowledge sources may be confidential)
AI-BOK v1.2, Module 3, section 3.6.5a
Prompt Registry
Central management of prompt templates, system messages, version control and effectiveness metrics.
Current
Cognition Plane
Commercial
SaaS / On-premise
REST API
AI-BOK v1.2, Module 3, section 3.6.5a
Guardrails Engine
Input/output filtering, content moderation, prompt injection detection and safety controls.
Current
Cognition Plane
Open Source
On-premise
Python SDK / Middleware
99,99% (kritiek)
AI-BOK v1.2, Module 3, section 3.6.5a
Evaluation Framework
Automated quality evaluation of models: faithfulness, relevance, hallucination rate.
Current
Cognition Plane
Open Source
On-premise
Python SDK
AI-BOK v1.2, Module 3, section 3.6.5a
AI Identity & Access Mgmt
Identity and authorisation for AI agents, users and systems. Agent identities (NHI).
Current
Control Plane
Commercial
SaaS
OAuth 2.0 / OIDC / SAML
99,99% (kritiek)
Very high (identity data)
AI-BOK v1.2, Module 3, section 3.6.5a
Policy Engine
Policy rules for AI authorisation, policy-as-code. Runtime governance checks for agents.
Current
Control Plane
Open Source
On-premise
REST API / Rego / Cedar
99,99% (kritiek)
AI-BOK v1.2, Module 3, section 3.6.5a
Audit Trail Service
Immutable logging of AI decisions, interactions and agent actions. Provenance and traceability.
Current
Control Plane
Open Source
On-premise
OpenTelemetry / REST API
99,999% (compliance)
High (contains decision history)
AI-BOK v1.2, Module 3, section 3.6.5a
Model Registry
Central registry of models, versions, model cards, experiments and deployments.
Current
Control Plane
Open Source
On-premise / SaaS
REST API / MLflow API
99,9%
AI-BOK v1.2, Module 3, section 3.6.5a
API Gateway
Access control, rate limiting, routing and load balancing for AI services and LLM endpoints.
Current
Control Plane
Commercial
On-premise / SaaS
REST / gRPC / GraphQL
99,99%
AI-BOK v1.2, Module 3, section 3.6.5a
Vector Database
Storage and similarity search of embeddings for RAG and semantic search.
Current
Data Plane
Commercial
SaaS / On-premise
REST API / gRPC
99,9%
High (embeddings of business data)
AI-BOK v1.2, Module 3, section 3.6.5a
Knowledge Graph
Knowledge graph for structured knowledge: entities, relations, ontologies (RDF/OWL/SKOS).
Current
Data Plane
Open Source
On-premise
SPARQL / REST API
99,9%
Medium (concepts and relationships)
AI-BOK v1.2, Module 3, section 3.6.5a
Feature Store
Standardised storage and serving of ML features for training and inference.
Current
Data Plane
Open Source
On-premise
REST API / gRPC
AI-BOK v1.2, Module 3, section 3.6.5a
Data Lake/Warehouse
Central storage for training data, evaluation data and analytics.
Current
Data Plane
Commercial
SaaS
SQL / REST API
99,9%
Very high (training data, personal data)
AI-BOK v1.2, Module 3, section 3.6.5a
Document Store
Document storage for RAG sources: policy documents, manuals, knowledge articles.
Current
Data Plane
Commercial
SaaS / On-premise
REST API / WebDAV
High (policy documents, knowledge sources)
AI-BOK v1.2, Module 3, section 3.6.5a
Monitoring & Observability
Continuous monitoring of AI systems: performance, costs, drift, anomalies and SLA monitoring.
Current
Control Plane
Open Source
SaaS / On-premise
OpenTelemetry / Prometheus
99,99%
AI-BOK v1.2, Module 3, section 3.6.5a
Bias Detection & Fairness
Detection and mitigation of bias in models and data. Fairness metrics and debiasing techniques.
Current
Cognition Plane
Open Source
On-premise
AI-BOK v1.2, Module 3, section 3.6.5a
Explainability Engine
Uitlegbaarheidsmechanismen voor AI-beslissingen: feature attribution, counterfactuals, attention maps.
Current
Cognition Plane
Open Source
On-premise
AI-BOK v1.2, Module 3, section 3.6.5a
Data Quality Framework
Geautomatiseerde datakwaliteitsValidation: volledigheid, consistentie, actualiteit, biasdetectie.
Current
Data Plane
Open Source
On-premise
AI-BOK v1.2, Module 3, section 3.6.5a
Annotation Tooling
Tooling for data annotation, labelling and curation. Support for RLHF and domain expert validation.
Current
Data Plane
Open Source
On-premise / SaaS
AI-BOK v1.2, Module 3, section 3.6.5a
CI/CD & Infrastructure
Continuous integration/delivery pipelines, containerisatie, infrastructure-as-code voor AI-workloads.
Current
Control Plane
Open Source
SaaS / On-premise
YAML / REST API
AI-BOK v1.2, Module 3, section 3.6.5a
Model Serving
Production-serving van ML-modellen: batching, caching, GPU-optimalisatie, A/B-testing.
Current
Control Plane
Open Source
On-premise
AI-BOK v1.2, Module 3, section 3.6.5a
Naive RAG
Basis retrieve-then-generate patroon.
AI-BOK v1.2, Module 1, section 3.6
Advanced RAG
Pre-retrieval optimalisatie, post-retrieval reranking.
AI-BOK v1.2, Module 1, section 3.6
Modular RAG
Modulaire pipeline met verwisselbare componenten.
AI-BOK v1.2, Module 1, section 3.6
GraphRAG
Knowledge Graph-gebaseerde retrieval met entity-relatie context.
AI-BOK v1.2, Module 1, section 3.6
Agentic RAG
Agent-driven retrieval with tool use and iterative search strategies.
AI-BOK v1.2, Module 1, section 3.6
AI System
Een gedeployd AI-systeem dat als geheel functioneert.
AI-BOK v1.2, Module 3, section 3.2
Agent
Autonome AI-component die zelfstandig redeneert en handelt binnen mandaat.
AI-BOK v1.2, Module 3, section 3.2
AI Model
Getraind ML/AI-model in deployable vorm.
AI-BOK v1.2, Module 3, section 3.2
Data Retrieval Service
Vector similarity search and document retrieval for RAG pipelines.
Data Plane
AI-BOK v1.2, Module 3, section 3.6.5
Knowledge Query Service
SPARQL and graph queries on knowledge graphs and ontologies.
Data Plane
AI-BOK v1.2, Module 3, section 3.6.5
Data Quality Service
Geautomatiseerde datakwaliteitsValidation en -rapportage.
Data Plane
AI-BOK v1.2, Module 3, section 3.6.5
Feature Serving Service
On-demand serving of ML features for training and inference.
Data Plane
AI-BOK v1.2, Module 3, section 3.6.5
Identity & Authorization Service
Agent-identiteit, autorisatie en mandaatverificatie.
Control Plane
AI-BOK v1.2, Module 3, section 3.6.5
Policy Check Service
Runtime governance checks: may this agent perform this action?
Control Plane
AI-BOK v1.2, Module 3, section 3.6.5
Audit & Logging Service
Immutable logging of decisions, interactions and agent actions.
Control Plane
AI-BOK v1.2, Module 3, section 3.6.5
Model Management Service
Modelselectie, versiebeheer en model card raadpleging.
Control Plane
AI-BOK v1.2, Module 3, section 3.6.5
API Access Service
Controlled access to AI endpoints with rate limiting and routing.
Control Plane
AI-BOK v1.2, Module 3, section 3.6.5
Monitoring & Observability Service
Continuous monitoring of performance, drift, costs and anomalies.
Control Plane
AI-BOK v1.2, Module 3, section 3.6.5
AI Inference Service
Tekstgeneratie, classificatie, embedding via foundation models.
Cognition Plane
AI-BOK v1.2, Module 3, section 3.6.5
Agent Orchestration Service
Multi-agent coördinatie, taakdecompositie en tool-gebruik.
Cognition Plane
AI-BOK v1.2, Module 3, section 3.6.5
Knowledge Retrieval Service
RAG: grounded answers based on authoritative knowledge sources.
Cognition Plane
AI-BOK v1.2, Module 3, section 3.6.5
Guardrails & Safety Service
Input/output-filtering, Hallucinationpreventie en content moderation.
Cognition Plane
AI-BOK v1.2, Module 3, section 3.6.5
AI Evaluation Service
Geautomatiseerde kwaliteitsevaluatie: faithfulness, relevance, fairness.
Cognition Plane
AI-BOK v1.2, Module 3, section 3.6.5
Pseudonymisation Service
De-pseudonymisation only possible by authorised roles with specific task key.
AI-BOK v1.2, Module 1, section 5.10
Key Vault Pattern
Pseudonymisation layer separating personal data from content data. Task keys link pseudonymised data to tasks, not to persons.
AI-BOK v1.2, Module 1, section 5.10
OpenAI GPT-4o
Current
High
AI-BOK v1.2, Module 3, section 3.6.5a
Anthropic Claude
Current
High
AI-BOK v1.2, Module 3, section 3.6.5a
Meta LLaMA
Current
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Google Gemini
Current
High
AI-BOK v1.2, Module 3, section 3.6.5a
Cohere
Medium
AI-BOK v1.2, Module 3, section 3.6.5a
Azure OpenAI Service
High
AI-BOK v1.2, Module 3, section 3.6.5a
AWS Bedrock
High
AI-BOK v1.2, Module 3, section 3.6.5a
vLLM
Planned
Free
AI-BOK v1.2, Module 3, section 3.6.5a
TensorFlow Serving
AI-BOK v1.2, Module 3, section 3.6.5a
TorchServe
AI-BOK v1.2, Module 3, section 3.6.5a
Triton Inference Server
High
AI-BOK v1.2, Module 3, section 3.6.5a
LangGraph
Current
AI-BOK v1.2, Module 3, section 3.6.5a
CrewAI
Emerging
Free
AI-BOK v1.2, Module 3, section 3.6.5a
AutoGen
Emerging
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Semantic Kernel
Emerging
AI-BOK v1.2, Module 3, section 3.6.5a
LangChain
Current
Free
AI-BOK v1.2, Module 3, section 3.6.5a
LlamaIndex
Current
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Haystack
Emerging
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Azure AI Search
High
AI-BOK v1.2, Module 3, section 3.6.5a
Amazon Kendra
High
AI-BOK v1.2, Module 3, section 3.6.5a
PromptLayer
Low
AI-BOK v1.2, Module 3, section 3.6.5a
Humanloop
Low
AI-BOK v1.2, Module 3, section 3.6.5a
NeMo Guardrails
Current
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Guardrails AI
Emerging
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Garak
Emerging
Free
AI-BOK v1.2, Module 3, section 3.6.5a
PromptFoo
Emerging
Medium
AI-BOK v1.2, Module 3, section 3.6.5a
RAGAS
Current
Free
AI-BOK v1.2, Module 3, section 3.6.5a
DeepEval
Emerging
Free
AI-BOK v1.2, Module 3, section 3.6.5a
TruLens
Emerging
AI-BOK v1.2, Module 3, section 3.6.5a
HELM
AI-BOK v1.2, Module 3, section 3.6.5a
lm-eval-harness
AI-BOK v1.2, Module 3, section 3.6.5a
BLEU
AI-BOK v1.2, Module 3, section 3.6.5a
ROUGE
AI-BOK v1.2, Module 3, section 3.6.5a
BERTScore
AI-BOK v1.2, Module 3, section 3.6.5a
Microsoft Entra ID
Current
High
AI-BOK v1.2, Module 3, section 3.6.5a
Keycloak
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Okta
Medium
AI-BOK v1.2, Module 3, section 3.6.5a
Open Policy Agent
Current
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Cedar
Planned
AI-BOK v1.2, Module 3, section 3.6.5a
OpenTelemetry
Current
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Jaeger
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Langfuse
Emerging
Free
AI-BOK v1.2, Module 3, section 3.6.5a
OpenLineage
AI-BOK v1.2, Module 3, section 3.6.5a
MLflow
Current
Medium
AI-BOK v1.2, Module 3, section 3.6.5a
Weights & Biases
Medium
AI-BOK v1.2, Module 3, section 3.6.5a
Kubeflow
AI-BOK v1.2, Module 3, section 3.6.5a
Google Vertex AI
High
AI-BOK v1.2, Module 3, section 3.6.5a
Azure ML Model Registry
AI-BOK v1.2, Module 3, section 3.6.5a
Neptune.ai
Medium
AI-BOK v1.2, Module 3, section 3.6.5a
ClearML
Medium
AI-BOK v1.2, Module 3, section 3.6.5a
DVC (Data Version Control)
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Hugging Face Model Hub
AI-BOK v1.2, Module 3, section 3.6.5a
Model Card Toolkit
AI-BOK v1.2, Module 3, section 3.6.5a
Kong
Medium
AI-BOK v1.2, Module 3, section 3.6.5a
Apigee
High
AI-BOK v1.2, Module 3, section 3.6.5a
AWS API Gateway
AI-BOK v1.2, Module 3, section 3.6.5a
Azure API Management
AI-BOK v1.2, Module 3, section 3.6.5a
LiteLLM
Emerging
Low
AI-BOK v1.2, Module 3, section 3.6.5a
OpenRouter
Emerging
Low
AI-BOK v1.2, Module 3, section 3.6.5a
Pinecone
Current
Medium
AI-BOK v1.2, Module 3, section 3.6.5a
Weaviate
Current
Low
AI-BOK v1.2, Module 3, section 3.6.5a
Qdrant
Emerging
Free
AI-BOK v1.2, Module 3, section 3.6.5a
ChromaDB
Emerging
Free
AI-BOK v1.2, Module 3, section 3.6.5a
pgvector
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Neo4j
Current
Low
AI-BOK v1.2, Module 3, section 3.6.5a
Amazon Neptune
AI-BOK v1.2, Module 3, section 3.6.5a
GraphDB
Low
AI-BOK v1.2, Module 3, section 3.6.5a
Apache Jena
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Stardog
Low
AI-BOK v1.2, Module 3, section 3.6.5a
Protégé
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Databricks
Current
High
AI-BOK v1.2, Module 3, section 3.6.5a
Snowflake
High
AI-BOK v1.2, Module 3, section 3.6.5a
Delta Lake
AI-BOK v1.2, Module 3, section 3.6.5a
Feast
Planned
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Tecton
Planned
AI-BOK v1.2, Module 3, section 3.6.5a
SharePoint
AI-BOK v1.2, Module 3, section 3.6.5a
Confluence
AI-BOK v1.2, Module 3, section 3.6.5a
Amazon S3
AI-BOK v1.2, Module 3, section 3.6.5a
Prometheus
Current
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Grafana
Current
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Datadog
High
AI-BOK v1.2, Module 3, section 3.6.5a
Azure Monitor
AI-BOK v1.2, Module 3, section 3.6.5a
ELK Stack
AI-BOK v1.2, Module 3, section 3.6.5a
Loki
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Evidently AI
Emerging
Medium
AI-BOK v1.2, Module 3, section 3.6.5a
WhyLabs
Emerging
Medium
AI-BOK v1.2, Module 3, section 3.6.5a
NannyML
Emerging
Medium
AI-BOK v1.2, Module 3, section 3.6.5a
Helicone
AI-BOK v1.2, Module 3, section 3.6.5a
LLMeter
AI-BOK v1.2, Module 3, section 3.6.5a
Azure Cost Management
AI-BOK v1.2, Module 3, section 3.6.5a
AWS Cost Explorer
AI-BOK v1.2, Module 3, section 3.6.5a
AI Fairness 360 (IBM)
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Fairlearn (Microsoft)
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Aequitas
Free
AI-BOK v1.2, Module 3, section 3.6.5a
What-If Tool (Google)
AI-BOK v1.2, Module 3, section 3.6.5a
SHAP
Free
AI-BOK v1.2, Module 3, section 3.6.5a
LIME
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Great Expectations
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Soda
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Label Studio
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Prodigy
AI-BOK v1.2, Module 3, section 3.6.5a
GitHub Actions
Free
AI-BOK v1.2, Module 3, section 3.6.5a
GitLab CI
AI-BOK v1.2, Module 3, section 3.6.5a
Azure DevOps
AI-BOK v1.2, Module 3, section 3.6.5a
Jenkins
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Docker
Current
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Kubernetes
Current
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Helm Charts
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Terraform
Free
AI-BOK v1.2, Module 3, section 3.6.5a
Pulumi
Planned
AI-BOK v1.2, Module 3, section 3.6.5a
TriplyDB
Current
Low
AI-BOK v1.2, Module 3, section 3.6.5a
BegrippenXL
Current
Free
AI-BOK v1.2, Module 3, section 3.6.5a
WikiXL
Current
Low
AI-BOK v1.2, Module 3, section 3.6.5a
ArchiMedes
Current
Low
AI-BOK v1.2, Module 3, section 3.6.5a
EU AI Act
European regulation for AI with risk classes.
AI-BOK v1.2, Module 1, section 1.1
Digital Transformation
Organisations must leverage AI to remain competitive.
AI-BOK v1.2, Module 1, section 2.1
Trust in AI
Public trust in AI is essential for adoption.
AI-BOK v1.2, Module 1, section 11.1
Rise of Agentic AI
Autonomous AI agents require new governance mechanisms.
AI-BOK v1.2, Module 3, section 3.6.6
Technological Acceleration
Rapid development of foundation models and agentic AI.
AI-BOK v1.2, Module 3, section 3.4.8
Talent Scarcity
Labour market for AI specialists is very tight.
AI-BOK v1.2, Module 3, section 3.4.8
Organisational Culture & Change Readiness
Culture determines AI adoption pace.
AI-BOK v1.2, Module 3, section 3.4.8
Sector-specific Regulation
Additional requirements per sector (healthcare, finance, government).
AI-BOK v1.2, Module 3, section 3.4.8
Sustainability & ESG (CSRD)
AI energy consumption and CO2 emissions are reported.
AI-BOK v1.2, Module 3, section 3.4.8
Data Spaces & Supply Chain Digitisation
Federated data sharing requires interoperable AI.
AI-BOK v1.2, Module 3, section 3.4.8
Governance Framework
Het geheel van beleid, principes en mandaten dat AI-inzet stuurt.
AI-BOK v1.2, Module 3, section 3.2
KA1: Responsible AI Governance
Create conditions under which AI systems deliver maximum value within acceptable risk boundaries.
AI-BOK v1.2, Module 1, section 1.2
KA2: Maximum AI Value Creation
Maximum organisational value from AI investments through systematic selection and prioritisation.
AI-BOK v1.2, Module 1, section 2.2
KA3: Coherent AI Architecture
A coherent, repeatable and evolvable blueprint for AI capabilities.
AI-BOK v1.2, Module 1, section 3.2
KA4: Predictable AI Lifecycle
Predictable, repeatable and governable progress of AI initiatives.
AI-BOK v1.2, Module 1, section 4.2
KA5: Reliable Data Foundation
Reliable, traceable and semantically anchored data foundation for AI.
AI-BOK v1.2, Module 1, section 5.2
KA6: Manageable Model Portfolio
Reliable, reproducible and responsible model portfolio.
AI-BOK v1.2, Module 1, section 6.2
KA7: User-Centred AI Interaction
AI interactions that are user-centred, reliable and inclusive.
AI-BOK v1.2, Module 1, section 7.2
KA8: Reliable AI Operations
Reliable, observable and cost-efficient AI operations in production.
AI-BOK v1.2, Module 1, section 8.2
KA9: Proactive Risk Management
Proactively identify, assess and mitigate AI-related risks.
AI-BOK v1.2, Module 1, section 9.2
KA10: Demonstrable AI Compliance
Verifiable, risk-based compliance of AI systems.
AI-BOK v1.2, Module 1, section 10.2
KA11: Ethically Responsible AI
Ethical considerations structurally embedded in the design and deployment of AI.
AI-BOK v1.2, Module 1, section 11.2
KA12: Grounded AI Knowledge Processing
AI systems produce grounded, traceable and semantically vamemberated output.
AI-BOK v1.2, Module 1, section 12.2
Responsible AI Deployment
AI is deployed in a responsible, transparent and safe manner.
AI-BOK v1.2, Module 3, section 3.0
AI Compliance
Full compliance with EU AI Act and relevant standards.
AI-BOK v1.2, Module 3, section 3.0
KA13: AI-literate organisation
Semantic Precision
Unambiguous definitions of the concepts AI uses.
AI-BOK v1.2, Module 3, section 3.6.4
Reliable Knowledge Sources
Authoritative, curated information for grounding.
AI-BOK v1.2, Module 3, section 3.6.4
Explicit Governance
Clear rules, roles and mandates.
AI-BOK v1.2, Module 3, section 3.6.4
Responsibility is explicitly assigned
Every AI system has a designated owner responsible for functioning, impact and policy compliance.
AI-BOK v1.2, Module 1, section 1.2
Governance is proportional to risk
Governance intensity is proportional to the risk classification of the AI system.
AI-BOK v1.2, Module 1, section 1.2
Transparency about autonomy
The degree of autonomous operation is documented and visible.
AI-BOK v1.2, Module 1, section 1.2
Governance is embedded, not imposed
Governance mechanisms are part of the AI architecture, not an afterthought.
AI-BOK v1.2, Module 1, section 1.2
Human control as a design principle
Human-in-the-loop or human-on-the-loop is built in for decisions with significant impact.
AI-BOK v1.2, Module 1, section 1.2
Continuous improvement based on metrics
Governance is not static but is periodically adapted.
AI-BOK v1.2, Module 1, section 1.2
Strategic alignment over technological ambition
AI initiatives are selected based on contribution to business objectives.
AI-BOK v1.2, Module 1, section 2.2
Portfolio balance as a steering mechanism
The AI portfolio is deliberately balanced between explorative and exploitative.
AI-BOK v1.2, Module 1, section 2.2
Value realisation over activity
What counts is not the number of AI projects but the realised value.
AI-BOK v1.2, Module 1, section 2.2
Capacity planning as a precondition
AI strategy without capacity planning is a wish list.
AI-BOK v1.2, Module 1, section 2.2
Adaptive planning in a dynamic field
Strategy is reviewed annually; portfolio at least quarterly.
AI-BOK v1.2, Module 1, section 2.2
Cognition plane as a strategic layer
Strategy addresses the cognition plane as a new architecture layer.
AI-BOK v1.2, Module 1, section 2.2
Semantic precision over ambiguity
AI-systemen moeten concepten eenduidig interpreteren via terminologieraamwerken.
AI-BOK v1.2, Module 1, section 3.2
Explicit governance over implicit control
Authorities and escalation rules for AI agents are explicit in the architecture.
AI-BOK v1.2, Module 1, section 3.2
Separation of responsibilities
Architecture separates data, knowledge, logic and governance as four layers.
AI-BOK v1.2, Module 1, section 3.2
Traceability as an architecture requirement
Every AI output must be traceable to sources, models and reasoning steps.
AI-BOK v1.2, Module 1, section 3.2
Interoperability through open standards
AI components communicate via MCP and A2A. Vendor lock-in is minimised.
AI-BOK v1.2, Module 1, section 3.2
Design for evolution
Architecture is modular and loosely coupled so that components are replaceable.
AI-BOK v1.2, Module 1, section 3.2
Privacy by design through pseudonymisation
Personal data is never unnecessarily exposed to AI components.
AI-BOK v1.2, Module 1, section 3.2
Phase-aware governance
Each lifecycle phase has its own quality criteria, roles and deliverables.
AI-BOK v1.2, Module 1, section 4.2
Continuous feedback loops
Production observations structurally flow back to earlier phases.
AI-BOK v1.2, Module 1, section 4.2
Reproducibility as a precondition
Every experiment, training and deployment must be repeatable.
AI-BOK v1.2, Module 1, section 4.2
Value-driven prioritisation
The lifecycle is driven by business value, not just technical feasibility.
AI-BOK v1.2, Module 1, section 4.2
Responsible decommissioning
End of lifecycle is as important as the beginning: audit trail, data retention, knowledge transfer.
AI-BOK v1.2, Module 1, section 4.2
Agentic awareness
For agentic AI, additional lifecycle requirements apply per phase.
AI-BOK v1.2, Module 1, section 4.2
Semantic precision over data volume
Data value for AI is determined by unambiguity, not by volume.
AI-BOK v1.2, Module 1, section 5.2
Grounding in authoritative sources
AI-systemen verankeren antwoorden in traceerbare, autoritatieve kennisbronnen.
AI-BOK v1.2, Module 1, section 5.2
Traceability from source to output
Every AI output is traceable to data sources and semantic definitions.
AI-BOK v1.2, Module 1, section 5.2
Data quality as a continuous process
Data quality is an ongoing process of measurement, detection and improvement.
AI-BOK v1.2, Module 1, section 5.2
Bias awareness in all data phases
Bias detection is built into every phase of the data pipeline.
AI-BOK v1.2, Module 1, section 5.2
Interoperability through open standards
Semantische modellen gebruiken SKOS, RDF, OWL, SHACL.
AI-BOK v1.2, Module 1, section 5.2
Every model is a managed asset
Every production model is registered in a central model registry.
AI-BOK v1.2, Module 1, section 6.2
Documentation as a first requirement
No model to production without a model card.
AI-BOK v1.2, Module 1, section 6.2
Reproducibility is non-negotiable
Every model version must be reproducible.
AI-BOK v1.2, Module 1, section 6.2
Bias testing is structural
Modellen worden periodiek getest op ongewenste biases.
AI-BOK v1.2, Module 1, section 6.2
Deliberate choice: foundation model vs custom model
The choice is an architecture decision with consequences.
AI-BOK v1.2, Module 1, section 6.2
Model portfolio thinking
Models are managed as a portfolio: overlap and risks are visible.
AI-BOK v1.2, Module 1, section 6.2
User first
Every AI interaction is designed from the perspective of task, context and knowledge level.
AI-BOK v1.2, Module 1, section 7.2
Trust calibration
Users form a realistic picture of what AI can and cannot do.
AI-BOK v1.2, Module 1, section 7.2
Transparency in operation
The system proactively communicates about sources and uncertainties.
AI-BOK v1.2, Module 1, section 7.2
Inclusive accessibility
AI interfaces are usable for users with diverse abilities.
AI-BOK v1.2, Module 1, section 7.2
Human autonomy
The user retains control over the decision-making process.
AI-BOK v1.2, Module 1, section 7.2
Iterative improvement
Interactionpatronen worden continu geëvalueerd en verbeterd.
AI-BOK v1.2, Module 1, section 7.2
Production reliability
AI systems function with the same reliability as business-critical applications.
AI-BOK v1.2, Module 1, section 8.2
Observability
Performance, costs, quality and deviations are continuously measured.
AI-BOK v1.2, Module 1, section 8.2
Reproducibility
Every deployment is reproducible: models, configurations and prompts are versioned.
AI-BOK v1.2, Module 1, section 8.2
Automated delivery
CI/CD pipelines for maximum automation from model to production.
AI-BOK v1.2, Module 1, section 8.2
Cost management
AI-inferentiekosten worden actief gemonitord en geoptimaliseerd.
AI-BOK v1.2, Module 1, section 8.2
Gradual rollout
New versions are rolled out in phases (canary, A/B, blue-green).
AI-BOK v1.2, Module 1, section 8.2
Risk proportionality
Risk management intensity is proportional to the risk level.
AI-BOK v1.2, Module 1, section 9.2
Proactive identification
Risico's worden vóór deployment geïdentificeerd en geadresseerd.
AI-BOK v1.2, Module 1, section 9.2
Continuous vigilance
Risk profiles change; monitoring is continuous, not one-off.
AI-BOK v1.2, Module 1, section 9.2
Safety as culture
AI safety is an organisational culture, not a checklist.
AI-BOK v1.2, Module 1, section 9.2
Legal conformity
EU AI Act risk classification is the minimum framework.
AI-BOK v1.2, Module 1, section 9.2
Transparent accountability
Risk assessments are documented and available for audit.
AI-BOK v1.2, Module 1, section 9.2
Demonstrable compliance
Compliance is only real when verifiable and reproducible.
AI-BOK v1.2, Module 1, section 10.2
Risk-based classification
Compliance effort scales with risk level.
AI-BOK v1.2, Module 1, section 10.2
Independence of audit
Audits worden uitgevoerd door functioneel onafhankelijke partijen.
AI-BOK v1.2, Module 1, section 10.2
Continuous traceability
Audittrails worden continu vastgelegd, niet achteraf gereconstrueerd.
AI-BOK v1.2, Module 1, section 10.2
Proactive transparency
Organisaties publiceren actief in het Algorithmregister.
AI-BOK v1.2, Module 1, section 10.2
Integral alignment
AI Compliance integreert met enterprise governance en informatiebeveiliging.
AI-BOK v1.2, Module 1, section 10.2
Fairness as a measurable requirement
Fairness is a testable property with standardised metrics.
AI-BOK v1.2, Module 1, section 11.2
Explainability as a right
Stakeholders have the right to an understandable explanation of AI decisions.
AI-BOK v1.2, Module 1, section 11.2
Human oversight as a fundamental principle
Human-in/on/in-command per AI system based on risk and impact.
AI-BOK v1.2, Module 1, section 11.2
Societal responsibility
Organisaties beoordelen ook bredere maatschappelijke consequenties.
AI-BOK v1.2, Module 1, section 11.2
Value alignment as a design requirement
AI systems are designed in line with organisational and societal values.
AI-BOK v1.2, Module 1, section 11.2
Ethics by design
Ethical considerations are structurally integrated into the design process.
AI-BOK v1.2, Module 1, section 11.2
Grounding over generation
AI output based on verified, authoritative sources.
AI-BOK v1.2, Module 1, section 12.2
Explicit source authority
Knowledge sources are classified by reliability and authority.
AI-BOK v1.2, Module 1, section 12.2
Hallucination prevention as a system requirement
Prevention of factually incorrect output is a hard system requirement.
AI-BOK v1.2, Module 1, section 12.2
Knowledge currency as a continuous process
Mechanisms for staleness detection are structurally embedded.
AI-BOK v1.2, Module 1, section 12.2
Semantic validation
Every knowledge source and AI output is validated against terminology frameworks.
AI-BOK v1.2, Module 1, section 12.2
Federated knowledge sharing
Knowledge is unlocked at the source and shared according to data spaces principles.
AI-BOK v1.2, Module 1, section 12.2
SKOS
W3C standard for terminology frameworks and thesauri.
AI-BOK v1.2, Module 3, section 3.3
NL-SBB (Geonovum)
Standard for Describing Concepts.
AI-BOK v1.2, Module 3, section 3.3
RDF / RDFS
W3C Resource Description Framework for linked data.
AI-BOK v1.2, Module 3, section 3.3
OWL
W3C Web Ontology Language for ontologies.
AI-BOK v1.2, Module 3, section 3.3
SHACL
W3C Shapes Constraint Language for validation.
AI-BOK v1.2, Module 3, section 3.3
SPARQL
W3C query language for RDF data.
AI-BOK v1.2, Module 3, section 3.3
DCAT 3.0
W3C Data Catalog Vocabulary for dataset metadata.
AI-BOK v1.2, Module 3, section 3.3
DCAT-AP-NL
Dutch profile for data catalogue.
AI-BOK v1.2, Module 3, section 3.3
JSON-LD
Linked data serialisation format.
AI-BOK v1.2, Module 3, section 3.3
W3C PROV-O
Provenance ontology for origin registration.
AI-BOK v1.2, Module 3, section 3.3
Dublin Core
Metadata standard for information sources.
AI-BOK v1.2, Module 3, section 3.3
ISO/IEC 42001:2023
AI Management System standard.
AI-BOK v1.2, Module 3, section 3.3
NIST AI RMF 1.0
AI Risk Management Framework.
AI-BOK v1.2, Module 3, section 3.3
EU AI Act
European regulation for AI governance.
AI-BOK v1.2, Module 3, section 3.3
AVG / GDPR
European privacy regulation.
AI-BOK v1.2, Module 3, section 3.3
ISO/IEC 25010
Software product quality characteristics.
AI-BOK v1.2, Module 3, section 3.3
IEEE P2247
Adaptive Autonomous Systems Architecture.
AI-BOK v1.2, Module 3, section 3.3
TOGAF
Enterprise Architecture framework.
AI-BOK v1.2, Module 3, section 3.3
ArchiMate 3.2
Architecture modelling language.
AI-BOK v1.2, Module 3, section 3.3
MIM
Information Modelling Metamodel (Geonovum/VNG).
AI-BOK v1.2, Module 3, section 3.3
OpenLineage
Pipeline metadata lineage standard.
AI-BOK v1.2, Module 3, section 3.3
MCP (Model Context Protocol)
Agent-tool integration protocol.
AI-BOK v1.2, Module 3, section 3.3
A2A (Agent-to-Agent)
Agent-agent communication protocol.
AI-BOK v1.2, Module 3, section 3.3
Model Cards (Mitchell et al.)
De facto standard for model documentation.
AI-BOK v1.2, Module 3, section 3.3
Datasheets for Datasets (Gebru)
Standard for dataset documentation.
AI-BOK v1.2, Module 3, section 3.3
Agent Card (A2A)
Agent metadata specification.
AI-BOK v1.2, Module 3, section 3.3
SKILL.md (Agent Skills)
Open standard for AI interaction patterns.
AI-BOK v1.2, Module 3, section 3.3
ISO/IEC 5338:2023
AI Lifecycle Processes.
AI-BOK v1.2, Module 3, section 3.3
ISO/IEC 22989:2022
AI Concepts & Terminology.
AI-BOK v1.2, Module 3, section 3.3
ISO/IEC 23894:2023
AI Risk Management.
AI-BOK v1.2, Module 3, section 3.3
ISO/IEC 25012
Data Quality Model.
AI-BOK v1.2, Module 3, section 3.3
ISO 9241-210:2019
Human-Centred Design.
AI-BOK v1.2, Module 3, section 3.3
WCAG 2.2 / EN 301 549
Accessibility standard.
AI-BOK v1.2, Module 3, section 3.3
FAIR Data Principles
Findable, Accessible, Interoperable, Reusable.
AI-BOK v1.2, Module 3, section 3.3
DMN (Decision Model & Notation)
Standard for decision models.
AI-BOK v1.2, Module 3, section 3.3
SBVR
Semantics of Business Vocabulary and Business Rules.
AI-BOK v1.2, Module 3, section 3.3
BPMN 2.0
Business Process Model and Notation.
AI-BOK v1.2, Module 3, section 3.3
ONNX
Open Neural Network Exchange format.
AI-BOK v1.2, Module 3, section 3.3
OpenAPI Specification
REST API specification standard.
AI-BOK v1.2, Module 3, section 3.3
FinOps Framework
Cloud financial management framework.
AI-BOK v1.2, Module 3, section 3.3
ISO 31000:2018
Risk Management standard.
AI-BOK v1.2, Module 3, section 3.3
EU AI Act Article 4 (AI literacy)
Obligation for providers and deployers to ensure sufficient AI literacy of staff and other persons acting on their behalf. Effective 2 February 2025.
AI-BOK v1.1
AI-BOK v1.1, Regulatory Traceability Matrix
Digital Services Act (Regulation 2022/2065)
Risk assessment, algorithmic transparency and recommender-system duties for VLOPs/VLOSEs.
AI-BOK v1.1
AI-BOK v1.1, Regulatory Traceability Matrix
Digital Markets Act (Regulation 2022/1925)
Gatekeeper obligations including interoperability and self-preferencing prohibitions.
AI-BOK v1.1
AI-BOK v1.1, Regulatory Traceability Matrix
Data Act (Regulation 2023/2854)
Rules on data access, sharing and switching that affect datasets feeding AI.
AI-BOK v1.1
AI-BOK v1.1, Regulatory Traceability Matrix
NIS2 (Directive 2022/2555)
Cybersecurity obligations for essential and important entities, applicable to AI operators in scope.
AI-BOK v1.1
AI-BOK v1.1, Regulatory Traceability Matrix
EO 14110 (US Executive Order on Safe, Secure and Trustworthy AI)
Federal direction on AI safety, civil rights, and innovation; tracked together with successor administration policy.
AI-BOK v1.1
AI-BOK v1.1, Regulatory Traceability Matrix
NIST GenAI Profile
NIST AI RMF profile addressing generative-AI-specific risks (hallucination, IP, bias, dangerous content, privacy).
AI-BOK v1.1
AI-BOK v1.1, Regulatory Traceability Matrix
Colorado AI Act (SB24-205)
Risk-management programme, consumer disclosures and impact assessments for high-risk AI systems.
AI-BOK v1.1
AI-BOK v1.1, Regulatory Traceability Matrix
UK AI White Paper and sector-regulator follow-up
Principles-based pro-innovation regulation administered through existing sector regulators.
AI-BOK v1.1
AI-BOK v1.1, Regulatory Traceability Matrix
Canada AIDA (Bill C-27)
High-impact AI system risk-management, monitoring and accountability framework.
AI-BOK v1.1
AI-BOK v1.1, Regulatory Traceability Matrix
Singapore Model AI Governance Framework v2
Voluntary internal governance, human involvement, stakeholder communication and AI Verify toolkit.
AI-BOK v1.1
AI-BOK v1.1, Regulatory Traceability Matrix
Brazil PL 2338/2023 (Marco Legal da IA)
Risk-tiered AI regulation with fundamental-rights impact assessment and ANPD oversight.
AI-BOK v1.1
AI-BOK v1.1, Regulatory Traceability Matrix
China Interim Measures for Generative AI Services
Pre-deployment security assessments, content moderation and algorithm filings.
AI-BOK v1.1
AI-BOK v1.1, Regulatory Traceability Matrix
ISO/IEC 23894:2023
AI risk management — guidance aligned with ISO 31000 applied to AI systems.
AI-BOK v1.1
AI-BOK v1.1, Regulatory Traceability Matrix
ISO/IEC 5338:2023
AI system life cycle processes — process reference model for AI.
AI-BOK v1.1
AI-BOK v1.1, Regulatory Traceability Matrix
ISO/IEC 38507:2022
Governance implications of the use of AI by organizations.
AI-BOK v1.1
AI-BOK v1.1, Regulatory Traceability Matrix
VNG AI Governancekader (2025/2026)
Dutch municipal AI governance framework: process, roles, knowledge bank, project register.
AI-BOK v1.1
AI-BOK v1.1, Regulatory Traceability Matrix
BZK Algoritmekader 2.0 (2026)
Dutch central-government operational reference for algorithm and AI governance.
AI-BOK v1.1
AI-BOK v1.1, Regulatory Traceability Matrix
AI Impact Assessment
Assessment of impact and risks per AI system.
Possibly personal data
Confidential
10 years
Mandatory for high-risk AI
AI-BOK v1.2, Module 1, section 9.4
Level 1: Initial
Ad hoc, no structured AI governance.
AI-BOK v1.2, Module 3, section 3.4
Level 2: Repeatable
Basic processes and roles defined.
AI-BOK v1.2, Module 3, section 3.4
Level 3: Defined
Organisation-wide standards and procedures.
AI-BOK v1.2, Module 3, section 3.4
Level 4: Managed
Quantitatively managed, continuous monitoring.
AI-BOK v1.2, Module 3, section 3.4
Level 5: Optimised
Continuous improvement, innovation-driven.
AI-BOK v1.2, Module 3, section 3.4
Dimension: Governance
Policy, decision structures, responsibilities.
AI-BOK v1.2, Module 3, section 3.4
Dimension: Process
Lifecycle processes, quality gates, feedback loops.
AI-BOK v1.2, Module 3, section 3.4
Dimension: People
Roles, competencies, training, culture.
AI-BOK v1.2, Module 3, section 3.4
Dimension: Technology
Tooling, platforms, infrastructure, automation.
AI-BOK v1.2, Module 3, section 3.4
Dimension: Culture
AI Literacy, innovation mindset, ethical awareness.
AI-BOK v1.2, Module 3, section 3.4
AI Maturity Assessment
Assessment of AI maturity across 5 dimensions and 5 levels.
No personal data
Confidential
AI-BOK v1.2, Module 3, section 3.1
FRIA (Fundamental Rights Impact Assessment)
Assessment of impact on fundamental rights.
Likely personal data (fundamental rights assessment)
Confidential
10 years
Mandatory (Art. 27)
AI-BOK v1.2, Module 3, section 3.1
DPIA for AI
Data Protection Impact Assessment specifically for AI systems.
Likely personal data (DPIA)
Confidential
10 years (AVG)
Mandatory (GDPR Art. 35)
AI-BOK v1.2, Module 3, section 3.1
AI Quality Scorecard
Quality score across 5 dimensions per AI system.
No personal data
Internal
AI-BOK v1.2, Module 3, section 3.1
Risk Profile
Beoordeling van risico's verbonden aan een AI-systeem.
AI-BOK v1.2, Module 3, section 3.2
FM01 Prompt Injection (direct)
Adversary inserts instructions in user input that override system instructions or extract privileged content. Mitigation: instruction-hierarchy enforcement; policy-consultation before privileged tool use.
AI-BOK v1.1
Agentic AI failure mode
AI-BOK v1.1, Failure-mode catalogue
FM02 Indirect Prompt Injection (data-borne)
Malicious instructions hidden in retrieved content treated as instructions. Mitigation: treat retrieved content as data; trust-graded knowledge sources.
AI-BOK v1.1
Agentic AI failure mode
AI-BOK v1.1, Failure-mode catalogue
FM03 Tool Misuse
Agent invokes legitimate tool with illegitimate parameters. Mitigation: per-tool capability gating; impact-threshold gates; policy-as-code evaluation.
AI-BOK v1.1
Agentic AI failure mode
AI-BOK v1.1, Failure-mode catalogue
FM04 Unauthorised Delegation
Agent spawns sub-agent with inappropriate inherited or escalated privileges. Mitigation: explicit minted sub-mandates; chain-of-custody in authority register.
AI-BOK v1.1
Agentic AI failure mode
AI-BOK v1.1, Failure-mode catalogue
FM05 Multi-agent Coordination Conflict
Overlapping or contradictory mandates produce inconsistent state or oscillation. Mitigation: single-writer rule; mandate-intersection check at grant time.
AI-BOK v1.1
Agentic AI failure mode
AI-BOK v1.1, Failure-mode catalogue
FM06 Memory Poisoning
False or biased content inserted into persistent memory becomes ground truth. Mitigation: write-controls; trust-tiered memory; provenance and re-validation.
AI-BOK v1.1
Agentic AI failure mode
AI-BOK v1.1, Failure-mode catalogue
FM07 Context-Window Saturation
Hostile content fills context, pushing system instructions out of effective attention. Mitigation: instruction re-injection at decision boundaries; structural separation.
AI-BOK v1.1
Agentic AI failure mode
AI-BOK v1.1, Failure-mode catalogue
FM08 Function-Call Abuse
Malformed or malicious arguments to structured function calls. Mitigation: strict schemas; tenant-scope enforcement; function-side validation.
AI-BOK v1.1
Agentic AI failure mode
AI-BOK v1.1, Failure-mode catalogue
FM09 Goal Drift
Effective objective diverges from stated goal over a long-running task. Mitigation: immutable objective binding; re-confirmation gates; alignment scoring.
AI-BOK v1.1
Agentic AI failure mode
AI-BOK v1.1, Failure-mode catalogue
FM10 Sycophancy and Confidence Inflation
Agent agrees with user assertions despite counter-evidence; humans accept without scrutiny. Mitigation: calibration; uncertainty channels; counter-evidence tests; KA13 literacy.
AI-BOK v1.1
Agentic AI failure mode
AI-BOK v1.1, Failure-mode catalogue
FM11 Jailbreak Persistence
Successful jailbreak establishes session/memory state that outlives the trigger. Mitigation: state reset on safety transitions; quarantined memory.
AI-BOK v1.1
Agentic AI failure mode
AI-BOK v1.1, Failure-mode catalogue
FM12 NHI Credential Leak or Theft
NHI credentials extracted via logs, prompts or compromised storage and reused. Mitigation: short-lived context-bound tokens; secret scanning; rotation.
AI-BOK v1.1
Agentic AI failure mode
AI-BOK v1.1, Failure-mode catalogue
FM13 Sandbox / Capability Escape
Agent escapes execution sandbox to acquire capabilities outside its mandate. Mitigation: capability-based sandbox; deny-by-default network; ephemeral envs.
AI-BOK v1.1
Agentic AI failure mode
AI-BOK v1.1, Failure-mode catalogue
FM14 Autonomy Creep
Mandate gradually expanded across reviews without cumulative-risk re-assessment. Mitigation: full mandate review on change; cumulative-risk metric.
AI-BOK v1.1
Agentic AI failure mode
AI-BOK v1.1, Failure-mode catalogue
FM15 Capability Inheritance via Tool Chaining
Composite effects beyond any single tool's mandate. Mitigation: sequence-level policy evaluation; composite-mandate definitions.
AI-BOK v1.1
Agentic AI failure mode
AI-BOK v1.1, Failure-mode catalogue
FM16 Hallucinated Authority
Agent asserts approval/authority that does not exist; downstream actors trust. Mitigation: downstream verification of signed policy-consultation artefacts.
AI-BOK v1.1
Agentic AI failure mode
AI-BOK v1.1, Failure-mode catalogue
FM17 Sensor Spoofing (operational)
Adversary injects false sensor readings into operational AI. Mitigation: cross-sensor consistency; trust scoring at ingestion.
AI-BOK v1.1
Agentic AI failure mode
AI-BOK v1.1, Failure-mode catalogue
FM18 Actuator Hijack (cyber-physical)
Control plane breach actuates physical equipment outside cognition-plane scope. Mitigation: actuation-side authentication and rate-limiting; safe-state envelope.
AI-BOK v1.1
Agentic AI failure mode
AI-BOK v1.1, Failure-mode catalogue
FM19 Closed-loop Drift (cyber-physical)
Model and physical system co-drift; symptoms only visible after long horizons. Mitigation: bounded-deviation envelopes; ground-truth re-validation.
AI-BOK v1.1
Agentic AI failure mode
AI-BOK v1.1, Failure-mode catalogue
FM20 Sample-rate Mismatch (operational)
Deployment sample rate differs from training; subtle in control loops. Mitigation: rate metadata; deployment-time validation.
AI-BOK v1.1
Agentic AI failure mode
AI-BOK v1.1, Failure-mode catalogue
FM21 Connectivity-induced Policy Bypass (edge)
Extended disconnection lets cached permissive policy outlive a revocation. Mitigation: mandate freshness budget; degraded mode.
AI-BOK v1.1
Agentic AI failure mode
AI-BOK v1.1, Failure-mode catalogue
FM22 Hardware Degradation (operational)
Sensor/accelerator drift; model accepts degraded inputs. Mitigation: hardware health telemetry; degradation-aware fallback.
AI-BOK v1.1
Agentic AI failure mode
AI-BOK v1.1, Failure-mode catalogue
Data Quality
Completeness, currency, representativeness, labelling, bias, semantic consistency.
AI-BOK v1.2, Module 3, section 3.7
Model Quality
Accuracy, robustness, reproducibility, generalisability, fairness.
AI-BOK v1.2, Module 3, section 3.7
Interaction Quality
Task success, user satisfaction, trust calibration, Hallucinationpercentage.
AI-BOK v1.2, Module 3, section 3.7
Operational Quality
Availability, reliability, scalability, drift detection speed, costs.
AI-BOK v1.2, Module 3, section 3.7
Governance Quality
Compliance ratio, auditability, transparency, ethical review coverage.
AI-BOK v1.2, Module 3, section 3.7
Policy-as-code Governance
Governance rules must be machine-readable and runtime-evaluable.
Not Started
Must Have
Yes
Immutable Audit Trail
All AI decisions and interactions must be immutably logged.
Not Started
Must Have
Yes
Agent Authorisation and Mandate
Agents must be authorised at runtime based on explicit mandates.
Not Started
Must Have
Yes
Input/Output Guardrails
AI output must be filtered for safety, correctness and ethics.
Not Started
Must Have
Yes
Continuous Observability
AI systems must be continuously monitored for performance, drift and costs.
Not Started
Must Have
Yes
Semantic Anchoring
AI systems must interpret concepts via authoritative terminology frameworks.
Not Started
Must Have
Yes
End-to-end Traceability
Every AI output must be traceable to sources, models and reasoning steps.
Not Started
Must Have
Yes
Central Model Management
All production models must be registered with model cards and versions.
Not Started
Must Have
Yes
Structural Bias Detection
Models must be periodically tested for undesirable biases.
Not Started
Must Have
Yes
Explainability of decisions
Stakeholders have the right to an understandable explanation of AI decisions.
Not Started
Must Have
Yes
Privacy by design
Personal data is never unnecessarily exposed to AI components.
Not Started
Must Have
Yes
Grounding in Authoritative Sources
AI output must be based on verified, traceable knowledge sources.
Not Started
Must Have
Yes
Open standards and interoperability
AI components communicate via standardised protocols (MCP, A2A).
Not Started
Must Have
Yes
Automated Delivery Pipeline
Model-to-production must be maximally automated via CI/CD.
Not Started
Must Have
Yes
User-centred Prompt Design
AI interactions are designed from the perspective of task, context and knowledge level.
Not Started
Must Have
Yes
Continuous Data Quality Monitoring
Data quality is an ongoing process of measurement and improvement.
Not Started
Must Have
Yes
Board of Directors
Strategic decision-making on AI deployment and risk acceptance.
CIO / CDO
Responsible for IT/data strategy and AI integration.
Business Owner
Owner of the business process supported by AI.
End User
Employee who works with AI systems daily.
Citizen / Customer
Person affected by AI decisions.
Regulator
External party overseeing AI Compliance (e.g. DPA, ACM).
AI Team
Multidisciplinary team of AI specialists.
AI
A technology that, for explicit or implicit purposes, infers how to generate outputs based on received input (such as data). Outputs include predictions, content, recommendations and/or decisions. The technology can learn, reason and perform tasks in a way that normally requires human intelligence.
AI (Artificial Intelligence) refers to the broader concept of artificial intelligence - the science and technology that enables machines to mimic human cognitive tasks such as learning, reasoning and problem-solving. This includes techniques such as machine learning, neural networks and natural language processing.
https://www.rijksoverheid.nl/documenten/publicaties/2025/04/22/overheidsbrede-handreiking-generatieve-ai
kunstmatige intelligentie
AI (artificial intelligence) is a technology where computers perform tasks normally done by humans, such as learning, thinking and problem-solving. AI can recognise faces, understand text or drive a car autonomously. This is done with smart programs that process large amounts of data and learn from them.
AI-systeem
A machine-based system designed to operate with varying levels of autonomy that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments.
Examples of AI systems are machine learning, Natural Language Processing (NLP) and computer vision (classifiers).
https://minbzk.github.io/Algorithmkader/overhetAlgorithmkader/definities/
kunstmatige intelligentie
An AI system encompasses not only the model but also the entire infrastructure around it. This includes hardware, software, data processing, input and output interfaces, and all components needed to make the model work effectively. Examples are ChatGPT, Google Gemini and Co-Pilot.
https://www.rijksoverheid.nl/documenten/publicaties/2025/04/22/overheidsbrede-handreiking-generatieve-ai
Algorithm
A set of rules and instructions that a computer automatically follows when making calculations to solve a problem or answer a question.
https://www.rekenkamer.nl/binaries/rekenkamer/documenten/rapporten/2021/01/26/aandacht-voor-Algorithms/Aandacht+voor+Algorithms.pdf
By algorithm we mean a set of rules and instructions that a computer executes, with goals such as solving problems, answering questions, executing tasks or making decisions.
A recipe for solving a computer science problem from a given initial state to an intended end goal, consisting of a finite sequence of unambiguously defined instructions or rules.
Model
A program trained to recognise patterns in data and make predictions.
concept
For example, predicting weather, recognising cats.
A model is a simplified representation of something from the real world. It helps to better understand, investigate or predict something.
AI-model
An AI model is the result of training an algorithm on data. An algorithm is a set of instructions, and the model is the specific result of following that set of instructions based on certain data.
concept
A model is trained on a task, for example classifying documents. GPT-4 is an example of an AI model.
https://www.rijksoverheid.nl/documenten/publicaties/2025/04/22/overheidsbrede-handreiking-generatieve-ai
Machine Learning
The way computers learn new things without explicit programming, by learning from labelled data to make predictions.
ML
Self-learning algorithms are algorithms that train themselves. This process is called machine learning. This allows computers to learn from data without explicit programming. This is a very common form of AI.
https://minbzk.github.io/Algorithmkader/overhetAlgorithmkader/soorten-Algorithms/#zelflerende-Algorithms
Supervised Learning
Machine learning process where a model learns from labelled examples (input-output pairs), comparable to a teacher-student scenario.
gecontroleerd leren
Your algorithm learns from data you label with information. For example, you offer photos with labels: this is a cat, this is not a cat.
https://minbzk.github.io/Algorithmkader/overhetAlgorithmkader/soorten-Algorithms/#zelflerende-Algorithms
Unsupervised Learning
Machine learning proces waarbij AI zelf verborgen patronen in ongelabelde data zoekt zonder expliciete begeleiding.
You let the algorithm discover patterns and structures itself in unstructured data without labels.
https://minbzk.github.io/Algorithmkader/overhetAlgorithmkader/soorten-Algorithms/#zelflerende-Algorithms
Reinforcement Learning
The algorithm learns through punishment and reward. The goal is to score as high as possible in as little time as possible.
For example, you give points when the algorithm sorts photos that look like cats. In reinforcement learning, the AI model learns autonomously. You can also choose to deploy the model frozen.
https://minbzk.github.io/Algorithmkader/overhetAlgorithmkader/soorten-Algorithms/#zelflerende-Algorithms
bekrachtiginsleren
Validation
Step in machine learning to verify model performance using a separate dataset (validation set) not used for training.
Neural Networks
An advanced form of AI that recognises complex patterns in data via layered neural networks, useful for image recognition, speech processing and language understanding.
deeplearning
CNN (Convolutional)
Vooral gebruikt bij beeldherkenning.
Convolutional Neural Networks
RNN (Recurrent)
Suitable for sequence data such as text and speech.
Recurrent Neural Networks
Transformers
Backbone of modern NLP models such as GPT and BERT.
Generative AI
A form of artificial intelligence that can produce (generate) content (text, images and/or varied content such as music) based on the data it is trained on.
GenAI
An example is generating synthetic data and providing programming assistance.
https://datanorth.ai/nl/blog/agentic-ai-begrijpen-definitie-en-toepassingen-in-de-praktijk
Generative AI, often used by large language models such as GPT-4o and DALL-E 3, focuses on creating new content based on patterns learned from enormous datasets.
Large Language Model
A specialised type of generative AI model trained on large volumes of text to understand existing content and generate textual content.
Large Language Model
https://www.rijksoverheid.nl/documenten/publicaties/2025/04/22/overheidsbrede-handreiking-generatieve-ai
Type of AI trained on large amounts of text data, capable of creating human-sounding text, answering questions, etc.
GPT
A type of neural network, pre-trained on large text data, that generates clear and relevant text based on prompts.
Generative Pre-trained Transformer
An example is ChatGPT.
RAG
A technique within artificial intelligence that combines the power of generative AI with information retrieval. This means an AI model not only generates text based on pre-trained data, but can also retrieve relevant information from external knowledge sources to provide more accurate and current answers.
Retrieval Augmented Generation
Prompt Engineering
The process of carefully choosing and adapting the input (prompt) for a machine learning model to get the best possible output.
prompten
Examples of prompt engineering: asking clear questions, adding specific instructions for style, creating creative prompts for interesting ideas or designs.
https://www.mckinsey.com/featured-insights/mckinsey-explainers/what-is-prompt-engineering
Prompt engineering is the art of smartly formulating instructions for an AI system. By using the right words and structure, an AI can give better and more accurate answers.
Token
The basic unit of text (a word or part of a word) processed by LLMs.
Temperature
The degree of randomness in the output of an LLM.
Hallucination
Output from generative AI that is factually incorrect or does not match reality, despite appearing semantically correct.
Bias
In the context of AI, bias refers to the assumptions an AI system makes to simplify the learning process and task execution. AI researchers try to minimise bias, as it can lead to poor results or unexpected outcomes.
Bias in the context of AI refers to systematic errors or prejudices in an algorithm arising from biased training data. This can lead to unfair or inaccurate results. Bias can take various forms: Sample Bias, Measurement Bias, Algorithmic Bias.
vooringenomenheid
Natural Language Processing
The way computers learn new things without explicit programming, by learning from labelled data to make predictions.
Natural Language Processing
NLP
Named Entity Recognition
Identifying names, locations and concepts in text.
Named Entity Recognition
Sentiment Analysis
Interpreting whether a text is positive, negative or neutral.
AI-agent
An AI agent is a software entity that autonomously executes tasks and makes decisions based on observations, rules and machine learning algorithms.
zelflerende bot
AI agents can vary in complexity, from simple bots to advanced self-learning systems.
https://news.microsoft.com/source/features/ai/ai-agents-what-they-are-and-how-theyll-change-the-way-we-work/
An AI agent is a computer program that can independently make decisions and take actions to achieve a goal. It uses AI to gather information, learn and adapt to changes.
Agentic AI
Agentic AI gives the AI system the ability to act autonomously, for example to create files.
An example of Agentic AI is a digital assistant that not only answers questions but also independently plans a trip, books tickets and reserves a hotel based on preferences.
https://datanorth.ai/nl/blog/agentic-ai-begrijpen-definitie-en-toepassingen-in-de-praktijk
Agentic AI refers to artificial intelligence that can independently make decisions and take actions without direct human intervention. This type of AI goes beyond traditional AI systems. Agentic AI can plan, execute and adapt based on changing circumstances.
Autonomous Agent
These can independently execute complex tasks, such as self-driving cars that analyse traffic conditions and act without direct human control.
Reactive Agent
These react directly to input without long-term memory. For example, a chess computer that only analyses the current move.
Multi-agent System
These are multiple AI agents collaborating, for example robots in a factory jointly optimising a production process.
EU AI Act
The European AI Act is one of the world's first comprehensive laws specifically for artificial intelligence (AI). The AI Act establishes frameworks and requirements for both governments and businesses regarding the development and use of AI systems.
https://www.digitaleoverheid.nl/overzicht-van-alle-onderwerpen/nieuwe-technologieen-data-en-ethiek/artificiele-intelligentie-ai/ai-verordening/
AI Act
The purpose of the law is that AI systems used by organisations within the EU are safe and respect fundamental rights. AI systems are divided into different risk categories with corresponding rules.
The AI Act is a European law that sets rules for the development and use of AI systems. The law also grants rights to citizens who come into contact with AI systems.
AI Literacy
Skills, knowledge and understanding enabling providers, deployers and affected persons, taking into account their respective rights and obligations under the AI Act, to make informed use of AI systems and to become more aware of the opportunities and risks of AI and the potential harm it can cause.
https://minbzk.github.io/Algorithmkader/overhetAlgorithmkader/definities/
AI Detector
An AI Detector is a tool designed to detect when a piece of text (or sometimes an image or video) has been created by AI tools (such as ChatGPT and DALL-E). These detectors are not 100% reliable, but they can provide an indication of the likelihood that a text was generated by AI.
AI Detectors work with similar large language models (LLMs) as the tools they try to detect. They look for low levels of perplexity and burstiness. AI Detectors can be used by universities and other institutions to identify AI-generated content.
https://www.scribbr.nl/ai-tools-gebruiken/ai-termen-begrippenlijst/
Deepfake
AI-generated or manipulated image, audio or video material that resembles existing persons, objects, places, entities or events, and would be wrongly perceived by a person as authentic or truthful.
https://minbzk.github.io/Algorithmkader/overhetAlgorithmkader/definities/
Algorithm Impact Assessment
An Algorithm Impact Assessment is a tool for making trade-off decisions when deploying algorithms and artificial intelligence.
https://www.rijksoverheid.nl/documenten/publicaties/2025/04/22/overheidsbrede-handreiking-generatieve-ai
Examples of Algorithm Impact Assessments are the IAMA and the AIIA.
AIIA
Algorithm Register
A register with descriptions of algorithmic applications that directly or indirectly have a societal and/or economic effect on citizens or society as a whole.
http://begrippen.kadaster.nl/ar/id/concept/AlgorithmRegister
Cognition Plane
The architecture layer where AI systems reason, interpret and make decisions. Distinguished from the data and control planes by non-deterministic, context-dependent behaviour.
The cognition plane is the core architecture innovation of the AI-BOK. It requires its own governance mechanisms such as mandates and reasoning boundaries.
AI-BOK v1.2, Module 3, section 3.6
Grounding
Anchoring AI output in verified, authoritative sources so that answers are factually correct and traceable.
Grounding is one of the three foundations of the cognition plane. Without grounding, an LLM produces answers based on training data that may be outdated or incorrect.
AI-BOK v1.2, Module 3, section 3.6.4
Semantic Precision
Unambiguous, formally defined concepts that enable AI systems to interpret concepts correctly.
First foundation of the cognition plane. Requires authoritative terminology frameworks (SKOS/NL-SBB).
AI-BOK v1.2, Module 3, section 3.6.4
AI Governance
The entirety of policy frameworks, decision structures, responsibilities and mandates with which an organisation governs AI systems.
KA1 is the central knowledge area of the AI-BOK. AI Governance is embedded, not imposed - mechanisms are part of the architecture.
AI-BOK v1.2, Module 1, section 1.1
Shadow AI
Unapproved use of AI tools and services by employees outside the view of IT and governance.
Shadow AI poses a growing risk. The AI-BOK recommends channeling (providing safe alternatives) over prohibiting.
AI-BOK v1.2, Module 1, section 1.13
Drift Detection
Monitoring shifts in data or model behaviour that degrade the performance of an AI system in production.
Distinction between data drift (input distribution changes) and concept drift (input-output relationship changes). Trigger for the retraining loop.
AI-BOK v1.2, Module 1, section 8.6
Guardrail
Programmable boundaries on the input and output of AI models that prevent undesirable behaviour.
Guardrails are architecturally anchored in the cognition plane. They form an additional security layer on top of model training.
AI-BOK v1.2, Module 1, section 6.8
Agent Mandate
Formal specification of the autonomy boundaries, escalation rules and context restrictions within which an AI agent may operate.
Agent mandates are the governance instrument for agentic AI. They specify what an agent may do, may not do, and when a human must intervene.
AI-BOK v1.2, Module 1, section 1.5
Quality Gate
Formal decision point in the AI lifecycle where an AI initiative is assessed against quality criteria before proceeding to the next phase.
Each quality gate has specific criteria, responsible roles and deliverables. Comparable to TOGAF ADM quality reviews.
AI-BOK v1.2, Module 3, section 3.1
Model Card (begrip)
Standardised documentation format describing what an AI model does, for whom, with what limitations and what performance.
Based on Mitchell et al. (2019). Each model card contains: purpose, owner, training data, evaluation results, limitations, fairness assessment.
AI-BOK v1.2, Module 1, section 6.4
Human-in-the-loop
Design pattern where a human is actively involved in the decision-making process of an AI system and assesses every output before it is executed.
HITL, menselijke controle
Three variants: human-in-the-loop (every decision), human-on-the-loop (sampling), human-in-command (policy/strategy).
AI-BOK v1.2, Module 1, section 11.6
Knowledge Graph
A graph structure representing entities and their interrelationships as a knowledge base for AI systems.
Knowledge Graph, KG
Knowledge graphs form a core component of the data plane. They are used for GraphRAG, entity resolution and semantic search functions.
AI-BOK v1.2, Module 1, section 5.7
Embedding
A numerical vector representation of text, image or other data that captures semantic meaning in a continuous vector space.
Embeddings are the foundation of RAG pipelines and semantic search. Embedding quality determines retrieval effectiveness.
AI-BOK v1.2, Module 1, section 5.5
Fine-tuning
Further training a foundation model on domain-specific data to improve performance for a specific task.
Alternative to RAG when domain knowledge must be structurally incorporated into the model. More expensive and complex than prompting.
AI-BOK v1.2, Module 1, section 6.6
Responsible AI
The practice of designing, developing and deploying AI systems in a manner that is ethical, transparent, fair and responsible.
Verantwoorde AI
Responsible AI encompasses fairness, explainability, privacy, safety and human oversight. It is the overarching theme of KA11.
AI-BOK v1.2, Module 1, section 11.1
Responsible AI Value Creation
Measurable business value from AI systems within acceptable risk boundaries.
Level 1: AI as Tool
AI supports individual tasks, no autonomy. User initiates and controls fully.
AI-BOK v1.2, Module 3, section 3.6.6
Level 2: AI in Workflows
AI is integrated into business processes, automated steps with human supervision.
AI-BOK v1.2, Module 3, section 3.6.6
Level 3: Digital Assistant
AI conducts conversations, answers questions, assists with decisions. Limited autonomy.
AI-BOK v1.2, Module 3, section 3.6.6
Level 4: Orchestration
Multiple AI agents collaborate, coordinated by an orchestrator. High governance intensity.
AI-BOK v1.2, Module 3, section 3.6.6
Level 5: Autonomous Agents
AI agents act independently within mandates. Very high governance requirements.
AI-BOK v1.2, Module 3, section 3.6.6
Level 6: Federated Collaboration
Agents from different organisations collaborate. Maximum governance complexity.
AI-BOK v1.2, Module 3, section 3.6.6
Phase 1: Quick Wins (0-3 months)
Inventory existing AI initiatives, assemble AI Board, classify risk, create awareness.
AI-BOK v1.2, Module 3, section 3.5
Phase 2: Foundation (3-12 months)
Governance framework operational, lifecycle established, first models in registry, basic monitoring.
AI-BOK v1.2, Module 3, section 3.5
Phase 3: Scale-up (12-24 months)
Organisation-wide rollout, cognition plane operational, multi-agent pilots, full compliance.
AI-BOK v1.2, Module 3, section 3.5
Phase 4: Optimisation (24+ months)
Continuous improvement, federated collaboration, AI-driven innovation, maturity level 4-5.
AI-BOK v1.2, Module 3, section 3.5
Gap: Geen → Quick Wins
Difference between current situation and first quick wins.
Gap: Quick Wins → Fundament
Difference between ad-hoc and structured.
Gap: Fundament → Opschaling
Difference between basic and organisation-wide rollout.
Semantic Precision + Reliable Knowledge Sources + Explicit Governance zijn alle drie nodig.
Cognition Plane
Reasoning, interpretation, decision-making by AI.
AI-BOK v1.2, Module 3, section 3.6.1
Control Plane
Identity, authorisation, logging, audit.
AI-BOK v1.2, Module 3, section 3.6.1
Data Plane
Data, knowledge, vector stores, knowledge graphs.
AI-BOK v1.2, Module 3, section 3.6.1
1st Line: Execution
AI Engineers, AI Operations Engineers — dagelijkse operatie en eerste kwaliteitscontrole.
AI-BOK v1.2, Module 3, section 3.3.4
2nd Line: Oversight
AI Risk Manager, AI Compliance Officer — onafhankelijke controle en risicobewaking.
AI-BOK v1.2, Module 3, section 3.3.4
3rd Line: Assurance
AI Auditor - independent audit of governance and systems.
AI-BOK v1.2, Module 3, section 3.3.4
LLM Providers
Agent & RAG
Guardrails & Safety
Evaluation & Fairness
Prompt Management
Identity & Access
Policy Engines
MLOps & Registry
API Gateways
Monitoring
CI/CD & Infra
Model Serving
Vector Databases
Knowledge Graphs
Data Platforms
Data Quality
Feature Stores
Annotation
Document Storage
Data Lineage
Cloud & Research
Architecture
Management Plane
Management plane: configuration, deployment, monitoring, model registry, lifecycle and resourcing of AI systems. Added in line with the EA4AI paper (CBI-EDOC 2026, Springer LNBIP), which positions the cognition plane alongside the data, control and management planes.
establishes governance frameworks for
defines architecture principles
determines gate criteria
sets risk tolerance
mandates compliance
anchors ethics
sets knowledge source requirements
provides architecture requirements
determines initiatives
formulates data requirements
prioritises model development
determines operational capacity
defines lifecycle blueprint
specifies data access
defines infrastructure requirements
specifies interaction patterns
provides target architecture
specifies RAG architecture
provides lifecycle framework
provides systems for deployment
provides training/evaluation data
provides concept frameworks
provides bias analyses
provides data lineage
provides bias detection
provides semantic building blocks
provides vamemberated models
escalates model risks
provides model cards
provides fairness assessments
provides interaction patterns
provides monitoring data
escalates incidents
provides operational logs
provides risk input
shares risk-ethics interface
shares FRIA assessment
provides context specifications
provides source references
provides hallucination prevention
provides traceability
chairperson
member
member
member
member
Retraining loop
Evaluation loop
Evolution loop
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
involved in
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
supported by
primary
primary
primary
primary
primary
primary
primary
primary
primary
primary
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
requires
requires
requires
requires
requires
requires
requires
requires
requires
requires
requires
requires
requires
requires
requires
requires
requires
requires
requires
requires
requires
requires
requires
leads
has interest in
has interest in
has interest in
has interest in
has interest in
has interest in
has interest in
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
applies to
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
provides
trained on
receives
consults
results in
has
falls under
generates
contains
governs
governs
governs
governance
governance
governance
governance
governance
governance
governance
governance
performance degradation
retrain
evaluation failed
retrain
fundamental change
restart cycle
has as concept
has as concept
has as concept
has as concept
has as concept
has as concept
has as concept
has as concept
has as concept
has as concept
has as concept
has as concept
has as concept
has as concept
has as concept
has as concept
has as concept
has as concept
has as concept
has as concept
has as concept
reports into and informs
Introduced in AI-BOK v1.1 (KA13).
anchors Article 4 evidence in
Introduced in AI-BOK v1.1 (KA13).
co-owns ethical-use content with
Introduced in AI-BOK v1.1 (KA13).
derives supervision literacy from
Introduced in AI-BOK v1.1 (KA13).
paired with (human grounding ↔ machine grounding)
Introduced in AI-BOK v1.1 (KA13).
supplies a documented control to
Introduced in AI-BOK v1.1 (KA13).
accountable for
AI Literacy Officer is the accountable role for KA13.
registered in
cognition-plane binding
registered in
cognition-plane binding
registered in
cognition-plane binding
registered in
cognition-plane binding
registered in
cognition-plane binding
registered in
cognition-plane binding
registered in
cognition-plane binding
registered in
cognition-plane binding
registered in
cognition-plane binding
registered in
registered in
cognition-plane binding
registered in
registered in
cognition-plane binding
registered in
cognition-plane binding
registered in
cognition-plane binding
registered in
cognition-plane binding
registered in
cognition-plane binding
registered in
cognition-plane binding
registered in
cognition-plane binding
registered in
cognition-plane binding
registered in
cognition-plane binding
registered in
cognition-plane binding
requires compliance through
AI Act Article 4 is operationalised by KA13.
sector implementation layer of
sector implementation layer of
standard anchor for
standard anchor for
policy consultation / audit trail
access control / lineage
configure / monitor
configure / monitor
configure / monitor
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
ai-act-risk-class
automation-level
availability-sla
business-value
category
compliance-relevance
confidentiality
cost-indication
data-sensitivity
dct:source
deployment-model
enterprise-readiness
eu-ai-act-relevance
eu-ai-act-relevant
fte-indication
gdpr-classification
governance-intensity
human-oversight
implementation-status
integration-protocol
introduced-in
ka-ring
license-model
lifecycle-phase
maturity-level
origin
plane
priority
raci-default-for
rdfs:comment
retention-period
role-number
seniority-level
skos:altLabel
skos:closeMatch
skos:notation
skos:scopeNote
url
vendor-dependency
vendor-type
01.01 AI Capability Map (13 Knowledge Areas)
Source: AI-BOK v1.2, Module 1, KA1 to KA13
AI-BOK v1.2, Module 1, KA1 to KA13
01.02 Layered View (all layers)
Source: AI-BOK v1.2, Module 3, section 3.6
AI-BOK v1.2, Module 3, section 3.6
01.00 AI-BOK Overview - Why, What, How & Who
Source: AI-BOK v1.2, Module 1, KA1 to KA13
AI-BOK v1.2, Module 1, KA1 to KA13
02.01 AI Role Model (20 Roles)
Source: AI-BOK v1.2, Module 2, section 2.2
AI-BOK v1.2, Module 2, section 2.2
02.02 AI Lifecycle Management (TOGAF ADM style)
Source: AI-BOK v1.2, Module 1, section 4
AI-BOK v1.2, Module 1, section 4
02.03 Process Model with Quality Gates
Source: AI-BOK v1.2, Module 1, section 4
AI-BOK v1.2, Module 1, section 4
02.04 RACI Matrix (Roles x Knowledge Areas)
02.05 Business Functions & Business Objects (52 objects)
Source: AI-BOK v1.2, Module 1, KA1 to KA13
AI-BOK v1.2, Module 1, KA1 to KA13
02.06 Function Model with ABBs
Source: AI-BOK v1.2, Module 3, section 3.6.5a
AI-BOK v1.2, Module 3, section 3.6.5a
02.10 AI Value Stream
Source: AI-BOK v1.2, Module 3, section 3.5
AI-BOK v1.2, Module 3, section 3.5
02.07 Three Lines of Defence
Source: AI-BOK v1.2, Module 3, section 3.3.4
AI-BOK v1.2, Module 3, section 3.3.4
02.08 Sub-roles and Specialisations
Source: AI-BOK v1.2, Module 2, section 2.2
AI-BOK v1.2, Module 2, section 2.2
02.09 Business Objects per Knowledge Area
Source: AI-BOK v1.2, Module 1, KA1 to KA13
AI-BOK v1.2, Module 1, KA1 to KA13
03.00 Planes Overview (incl. Management Plane)
The four architectural planes: the cognition plane (mandates, reasoning boundaries, grounding) alongside the control plane (policy, audit), data plane (sources, RAG) and management plane (configuration, monitoring, lifecycle). Grounding is the assurance relation between reasoning and its sources; the sources themselves reside in the data plane. Detailed ABBs per plane: views 03.01 to 03.04.
03.01 Planes Architecture (ABBs + Services)
Source: AI-BOK v1.2, Module 3, section 3.6.1 See 03.00 for the planes overview including the management plane.
AI-BOK v1.2, Module 3, section 3.6.1
03.02 SBBs Cognition Plane
Source: AI-BOK v1.2, Module 3, section 3.6.1
AI-BOK v1.2, Module 3, section 3.6.1
03.03 SBBs Control & Management Plane
Source: AI-BOK v1.2, Module 3, section 3.6.1
AI-BOK v1.2, Module 3, section 3.6.1
03.04 SBBs Data Plane
Source: AI-BOK v1.2, Module 3, section 3.6.1
AI-BOK v1.2, Module 3, section 3.6.1
03.05 AI Meta-model (Data Model)
Source: AI-BOK v1.2, Module 3, section 3.2
AI-BOK v1.2, Module 3, section 3.2
03.06 Application Cooperation (Data Flows)
Source: AI-BOK v1.2, Module 3, section 3.6.5
AI-BOK v1.2, Module 3, section 3.6.5
03.07 RAG Architecture Variants
Source: AI-BOK v1.2, Module 1, section 12.6
AI-BOK v1.2, Module 1, section 12.6
03.08 Privacy Architecture (Key Vault Pattern)
Source: AI-BOK v1.2, Module 1, section 5.10
AI-BOK v1.2, Module 1, section 5.10
03.09 Vendor Landscape
Source: AI-BOK v1.2, Module 3, section 3.6.1
AI-BOK v1.2, Module 3, section 3.6.1
04.01 AI Governance Structure
Source: AI-BOK v1.2, Module 1, section 1.2
AI-BOK v1.2, Module 1, section 1.2
04.00 Stakeholder Analysis
Source: AI-BOK v1.2, Module 2, section 2.3
AI-BOK v1.2, Module 2, section 2.3
04.02 Principles Detail (KA1 Governance + KA3 Architecture)
Source: AI-BOK v1.2, Module 1, section 1.2, 3.2
AI-BOK v1.2, Module 1, section 1.2, 3.2
04.03 All Principles Overview (72+)
Source: AI-BOK v1.2, Module 1, KA1 to KA13
AI-BOK v1.2, Module 1, KA1 to KA13
04.08 Requirements Realisation (Principle → Requirement → ABB)
Source: AI-BOK v1.2, Module 3, section 3.6.5a
AI-BOK v1.2, Module 3, section 3.6.5a
04.04 Standards & Constraints (with ABB mappings)
Source: AI-BOK v1.2, Module 3, section 3.3
AI-BOK v1.2, Module 3, section 3.3
04.05 AI Concepts in Context
Source: AI Thesaurus (AI-BOK appendix)
AI Thesaurus (AI-BOK bijlage)
04.07 Additional Standards & Environmental Factors
Source: AI-BOK v1.2, Module 3, section 3.3
AI-BOK v1.2, Module 3, section 3.3
04.06 Governance Integration (TOGAF/DAMA/COBIT/GDPR)
Source: AI-BOK v1.2, Module 3, section 3.3
AI-BOK v1.2, Module 3, section 3.3
04.09 All AI Concepts (Thesaurus)
Source: AI Thesaurus (AI-BOK appendix)
AI Thesaurus (AI-BOK bijlage)
05.01 Agent Maturity Spectrum (6 levels)
Source: AI-BOK v1.2, Module 3, section 3.6.6
AI-BOK v1.2, Module 3, section 3.6.6
05.02 Maturity Model (5x5 with Roadmap & Agent Maturity)
Source: AI-BOK v1.2, Module 3, section 3.4
AI-BOK v1.2, Module 3, section 3.4
05.03 AI Quality Framework (5 dimensions)
Source: AI-BOK v1.2, Module 3, section 3.7
AI-BOK v1.2, Module 3, section 3.7
05.04 Implementation Roadmap (4 phases with Gaps)
Source: AI-BOK v1.2, Module 3, section 3.5
AI-BOK v1.2, Module 3, section 3.5
06.01 KA1: AI Governance
Source: AI-BOK v1.2, Module 1, section 1
AI-BOK v1.2, Module 1, section 1
06.02 KA2: AI Strategy & Portfolio Management
Source: AI-BOK v1.2, Module 1, section 2
AI-BOK v1.2, Module 1, section 2
06.03 KA3: AI Architecture
Source: AI-BOK v1.2, Module 1, section 3
AI-BOK v1.2, Module 1, section 3
06.04 KA4: AI Lifecycle Management
Source: AI-BOK v1.2, Module 1, section 4
AI-BOK v1.2, Module 1, section 4
06.05 KA5: Data & Semantics for AI
Source: AI-BOK v1.2, Module 1, section 5
AI-BOK v1.2, Module 1, section 5
06.06 KA6: Model Management
Source: AI-BOK v1.2, Module 1, section 6
AI-BOK v1.2, Module 1, section 6
06.07 KA7: AI Interaction & User Experience
Source: AI-BOK v1.2, Module 1, section 7
AI-BOK v1.2, Module 1, section 7
06.08 KA8: AI Operations
Source: AI-BOK v1.2, Module 1, section 8
AI-BOK v1.2, Module 1, section 8
06.09 KA9: AI Risk Management & Safety
Source: AI-BOK v1.2, Module 1, section 9
AI-BOK v1.2, Module 1, section 9
06.10 KA10: AI Compliance & Audit
Source: AI-BOK v1.2, Module 1, section 10
AI-BOK v1.2, Module 1, section 10
06.11 KA11: AI Ethics & Responsible AI
Source: AI-BOK v1.2, Module 1, section 11
AI-BOK v1.2, Module 1, section 11
06.12 KA12: AI Knowledge & Context Management
Source: AI-BOK v1.2, Module 1, section 12
AI-BOK v1.2, Module 1, section 12
06.13 KA13: AI Literacy & Capability Development
KA13 capability with AI Literacy Officer (Role 20), the related KAs (KA1, KA10, KA11, KA3, KA12, KA9) and the EU AI Act Article 4 anchor. Introduced in AI-BOK v1.1.
AI-BOK v1.1
07.01 Agentic AI Failure-Mode Catalogue
Sixteen agentic AI failure modes (FM01-FM16) plus six operational/cyber-physical variants (FM17-FM22), with their primary KA anchors (KA9 Risk, KA3 Architecture). Cognition-plane bindings per pattern documented in the v1.1 failure-mode catalogue. Introduced in AI-BOK v1.1.
AI-BOK v1.1
08.01 Regulatory Landscape (multi-jurisdiction)
Standards and constraints since v1.1: EU adjacent instruments (DSA, DMA, Data Act, NIS2), non-EU regimes (US, UK, Canada, Singapore, Brazil, China), ISO companions (23894, 5338, 38507), and Dutch sector instruments (VNG, BZK). Mapped to KA1/KA9/KA10/KA13 in the v1.1 regulatory traceability matrix. Introduced in AI-BOK v1.1.
AI-BOK v1.1
09.01 GEMMA-style Local Register Pattern
Pattern for embedding AI-BOK reference objects in a municipality/government core information-architecture register, alongside GEMMA application reference-components. Each AI system in the local algoritmeregister references the AI-BOK metamodel objects (AI System, AI Model, Dataset, Prompt, Interaction, Decision, Knowledge Source, Agent, Governance Framework, Risk Profile). Introduced in AI-BOK v1.1.
AI-BOK v1.1