Strategy & governance

AI Governance

The structure of roles, policies and processes through which an organisation decides which AI systems it uses, under what conditions, and who answers for them.

Board and senior managementrisk appetite · accountability · resourcesAI governance committeepolicy · risk classification · approval of high-risk usesBusiness units and technical teamsinventory entry · testing · monitoring · incident reportsreports and incidents go uprules and decisions come downinventorysystem ownerrisk classapprovalmonitoringA working governance starts with three things: a list of the AI in use, an owner per item, a simple risk rule.

swipe to see the whole diagram →

MEmehmeterkek.com/glossary/ai-governance

In plain terms

Every company already has rules for spending money: who may approve what, up to which amount, with which record. AI governance is the same arrangement for AI. It settles who may introduce an AI system, what has to be checked first, who owns it once it is live and what happens when it goes wrong. Without it, those questions are answered case by case, by whoever happens to be in the room.

Why it matters

Governance is what lets an organisation say yes to AI quickly and safely. Where it is missing, two things happen at once: sensible projects wait months for a decision nobody is entitled to take, and staff use unapproved tools in the meantime. The usual mistake is to start with a long policy. A working governance starts with three things: a list of the AI in use, a named owner for each item and a simple rule for sorting uses by risk. The cost is real: someone senior has to own it, and reviews take time.

Example

A bank asks every department which AI tools and models it uses. The count comes to 63, more than three times what IT had on record. Four uses touch credit or hiring decisions and go through a full review; 51 are approved in a week under a light procedure; eight are stopped because customer data was leaving the bank. Each of the 55 that remain now has a named owner and a review date.

Most often confused with

AI Governance vs. Responsible AI

AI GovernanceThe structure: who decides, checks and answers
Responsible AIThe principles that structure is meant to uphold

Responsible AI states what the organisation wants its AI to be: fair, transparent, safe, accountable. Governance is the machinery that makes it so: committees, inventories, approvals, audits. Principles without governance stay on a poster. Governance without principles turns into paperwork with no purpose.

Under the hood

Building blocks: an AI policy; an inventory of systems and use cases, including AI features inside purchased software; a risk classification that sets the depth of review; defined roles, typically an accountable executive, a cross-functional committee (business, IT, data, legal, security, compliance) and an owner per system; controls across the life cycle, namely assessment before launch, evals and red teaming, human oversight, monitoring, incident handling and retirement; third-party management, covering vendor due diligence and contract terms on data use; and staff training. Reference frameworks: the NIST AI Risk Management Framework, ISO/IEC 42001 and, for legal duties in Europe, the EU AI Act. Many organisations map the work onto the three-lines model from risk management. Useful measures: share of systems inventoried and with an owner, time from request to decision, and incidents per quarter. Agents add new items to the list: tool permissions, autonomy level and spending limits.

Written by Mehmet Erkek · Last updated: