The framework's job is to build risk management into the organization's important activities and functions, and ISO 31000:2018, 5.1 applies. Risk management gathers what the organization needs in order to decide on and deal with risk: the governing body fixes overall risk appetite and objectives and hands the work of finding, assessing and treating risk to management. ISO/IEC 38507 covers the governance questions raised when an organization builds, buys or uses AI (new opportunities, a possibly different risk appetite, new policies for responsible AI) and can sit alongside this document's processes in the iterative integration that ISO 31000:2018, 5.2 sets out.
This control maps to 47 controls across 4 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.