Skip to main content
Governance should answer a practical question: who is responsible for each AI use case before, during and after deployment?

Minimum use-case record

For each production AI system record:
  • business owner;
  • technical owner;
  • purpose;
  • affected users;
  • data sources;
  • model/provider;
  • autonomy level;
  • human oversight;
  • material risks;
  • approval status;
  • performance KPI;
  • review date.

Decision rights

Clarify who can:
  • approve a new use case;
  • approve data access;
  • approve production release;
  • change model/provider;
  • change system prompts or tools;
  • pause the system;
  • accept residual risk.

Review cadence

Review high-impact systems more frequently than low-risk internal assistance. Trigger an additional review after material changes to model, data, workflow, regulation or user population.

Connect governance to delivery

Do not create a governance framework that nobody uses. Integrate reviews into the project lifecycle: Opportunity → risk assessment → design → test → approval → production → monitoring → periodic review

Consultant exit condition

Before handover, ensure there is an internal owner, monitoring mechanism, documentation and escalation route. A production AI system with no accountable owner is unfinished work.