Enterprise AI governance requires more than policy documents — it needs technical controls enforced at the workflow level. This guide covers five functional areas: model lifecycle controls, risk tiering, access controls and data lineage, audit trails, and governance review gates. It addresses how GenAI and agentic AI introduce new risk categories (prompt injection, hallucination, output unpredictability) on top of traditional ML governance requirements. Industry-specific compliance contexts are covered including SR 11-7 and SR 26-2 for financial services, FDA 21 CFR Part 11 for life sciences, and NIST AI RMF for public sector. The core argument is that governance must be embedded in the platform infrastructure — enforced at execution time — rather than maintained as a separate manual process.