AI governance overview¶
Enterprise AI governance creates decision rights, evidence, and feedback loops that keep AI use aligned with mission, law, policy, risk appetite, and public expectations.
Governance outcomes¶
- Every AI system has an accountable owner, documented intended use, and risk tier.
- A current inventory connects components, suppliers, data, approvals, and deployments.
- Lifecycle gates require proportionate evidence before experimentation, release, material change, and retirement.
- Affected people have appropriate notice, explanation, review, and redress mechanisms.
- Control effectiveness and incidents change policy and architecture over time.
Governance layers¶
| Layer | Responsibility |
|---|---|
| Governing body | Risk appetite, strategic oversight, consequential exceptions |
| Executive accountability | Portfolio outcomes, resources, cross-enterprise risk |
| AI governance function | Standards, inventory, risk tiering, lifecycle gates, reporting |
| Independent assurance | Challenge, audit, evaluation independence, control validation |
| Product and service teams | Design, implementation, evidence, monitoring, incident response |
| Data and platform stewards | Shared controls, quality, security, reliability, supplier oversight |
See the Operating Model, Risk Management, and Policy Framework.