Skip to content

AI governance overview

  • Draft
  • v0.1.0
  • Governance, risk, and compliance leads
  • Reviewed 2026-07-26

Enterprise AI governance creates decision rights, evidence, and feedback loops that keep AI use aligned with mission, law, policy, risk appetite, and public expectations.

Governance outcomes

  • Every AI system has an accountable owner, documented intended use, and risk tier.
  • A current inventory connects components, suppliers, data, approvals, and deployments.
  • Lifecycle gates require proportionate evidence before experimentation, release, material change, and retirement.
  • Affected people have appropriate notice, explanation, review, and redress mechanisms.
  • Control effectiveness and incidents change policy and architecture over time.

Governance layers

Layer Responsibility
Governing body Risk appetite, strategic oversight, consequential exceptions
Executive accountability Portfolio outcomes, resources, cross-enterprise risk
AI governance function Standards, inventory, risk tiering, lifecycle gates, reporting
Independent assurance Challenge, audit, evaluation independence, control validation
Product and service teams Design, implementation, evidence, monitoring, incident response
Data and platform stewards Shared controls, quality, security, reliability, supplier oversight

See the Operating Model, Risk Management, and Policy Framework.