Objective
This independent case study proposes a proportionate operating model for an organisation adopting AI across business functions. The design connects strategic oversight to a usable delivery path, avoiding both ungoverned experimentation and approval bureaucracy with no risk value.
Governance structure
Board or executive risk oversight
Sets risk appetite, receives material AI-risk reporting and challenges whether the portfolio remains aligned with organisational purpose and obligations.
AI governance committee
Owns the framework, approves higher-risk use cases, resolves cross-functional issues and monitors incidents, exceptions and aggregate exposure. Membership should include risk, legal, privacy, security, technology, data, procurement, business ownership and relevant domain specialists.
Accountable business owner
Owns the intended outcome, appropriate use, funded controls and residual-risk decision. Technical suppliers and delivery teams provide evidence but do not replace business accountability.
Independent challenge
Risk, compliance, internal audit or another suitably independent function tests whether classification, controls and evidence are credible.
Minimum AI inventory
| Field | Purpose | |---|---| | System and owner | Establish accountability and contact point | | Intended use and users | Define the approved boundary | | Provider and model | Support third-party and change tracking | | Data categories | Trigger privacy, security and quality review | | Affected people | Identify potential rights and safety impacts | | Risk tier and rationale | Determine the governance route | | Controls and evidence | Show how risk is treated | | Approval, review and expiry | Prevent indefinite, unreviewed use | | Incidents and material changes | Support monitoring and reassessment |
Risk classification
A screening step should consider legal classification, decision consequence, affected population, autonomy, data sensitivity, scale, reversibility, external exposure and dependency on third parties. Low-risk productivity tools may follow a streamlined path; consequential or regulated uses require deeper assessment and approval.
Approval gateways
- Discover: register the use case before procurement or build.
- Classify: assign an initial tier and required reviewers.
- Assess: document harms, controls, testing and residual risk.
- Approve: record accountable acceptance, conditions and expiry.
- Release: verify controls and user readiness before go-live.
- Monitor: review performance, incidents and change triggers.
- Retire: manage data, dependencies, communications and evidence retention.
Human oversight standard
Every use case should define who reviews or can intervene, what information they receive, which decisions cannot be delegated, how overrides work and when escalation or shutdown is mandatory.
Incident and change management
AI incidents should connect to existing operational, cyber, privacy, conduct and safety processes. Material changes—such as a new model, new data, expanded user group or changed decision impact—trigger reassessment rather than relying on an old approval.
Management information
Useful reporting includes inventory completeness, risk-tier distribution, overdue reviews, open high-risk findings, control exceptions, incident trends, third-party concentration and material changes awaiting approval.
The framework succeeds when it creates better, traceable decisions—not when it produces the largest policy library.