AI Governance

A policy document is not an operating model.

Operational AI governance converts principles and obligations into known systems, accountable owners, proportionate controls and defensible evidence.

What an operating model needs to cover

Good governance helps organisations adopt AI with greater confidence. It gives executives visibility, gives teams a consistent pathway, and gives assurance functions the evidence they need.

  • strategy and policy
  • executive accountability
  • use case ownership
  • AI inventory
  • impact assessment
  • risk management
  • privacy and security
  • data governance
  • copyright
  • procurement
  • human oversight
  • technical assurance
  • monitoring
  • incident management
  • transparency
  • training
  • reporting
  • continuous improvement

Layered model

Six layers of operational AI governance

Layer 1

Direction

Strategy, principles, policies and risk appetite.

Layer 2

Accountability

Accountable executive, governance committee, system owner, use case owner and control owner.

Layer 3

Process

Discovery, assessment, approval, deployment, monitoring, review and retirement.

Layer 4

Controls

Data, privacy, security, fairness, transparency, human oversight and supplier assurance.

Layer 5

Evidence

Assessments, approvals, testing, decisions, incidents, monitoring and review history.

Layer 6

Assurance

Dashboards, audits, executive reporting, customer reporting and regulator readiness.