All case studies

Project 02

AI Governance Framework

An operating model for accountable AI inventory, classification, approvals, monitoring and incidents.

Objective

This independent case study proposes a proportionate operating model for an organisation adopting AI across business functions. The design connects strategic oversight to a usable delivery path, avoiding both ungoverned experimentation and approval bureaucracy with no risk value.

Governance structure

Board or executive risk oversight

Sets risk appetite, receives material AI-risk reporting and challenges whether the portfolio remains aligned with organisational purpose and obligations.

AI governance committee

Owns the framework, approves higher-risk use cases, resolves cross-functional issues and monitors incidents, exceptions and aggregate exposure. Membership should include risk, legal, privacy, security, technology, data, procurement, business ownership and relevant domain specialists.

Accountable business owner

Owns the intended outcome, appropriate use, funded controls and residual-risk decision. Technical suppliers and delivery teams provide evidence but do not replace business accountability.

Independent challenge

Risk, compliance, internal audit or another suitably independent function tests whether classification, controls and evidence are credible.

Minimum AI inventory

| Field | Purpose | |---|---| | System and owner | Establish accountability and contact point | | Intended use and users | Define the approved boundary | | Provider and model | Support third-party and change tracking | | Data categories | Trigger privacy, security and quality review | | Affected people | Identify potential rights and safety impacts | | Risk tier and rationale | Determine the governance route | | Controls and evidence | Show how risk is treated | | Approval, review and expiry | Prevent indefinite, unreviewed use | | Incidents and material changes | Support monitoring and reassessment |

Risk classification

A screening step should consider legal classification, decision consequence, affected population, autonomy, data sensitivity, scale, reversibility, external exposure and dependency on third parties. Low-risk productivity tools may follow a streamlined path; consequential or regulated uses require deeper assessment and approval.

Approval gateways

  1. Discover: register the use case before procurement or build.
  2. Classify: assign an initial tier and required reviewers.
  3. Assess: document harms, controls, testing and residual risk.
  4. Approve: record accountable acceptance, conditions and expiry.
  5. Release: verify controls and user readiness before go-live.
  6. Monitor: review performance, incidents and change triggers.
  7. Retire: manage data, dependencies, communications and evidence retention.

Human oversight standard

Every use case should define who reviews or can intervene, what information they receive, which decisions cannot be delegated, how overrides work and when escalation or shutdown is mandatory.

Incident and change management

AI incidents should connect to existing operational, cyber, privacy, conduct and safety processes. Material changes—such as a new model, new data, expanded user group or changed decision impact—trigger reassessment rather than relying on an old approval.

Management information

Useful reporting includes inventory completeness, risk-tier distribution, overdue reviews, open high-risk findings, control exceptions, incident trends, third-party concentration and material changes awaiting approval.

The framework succeeds when it creates better, traceable decisions—not when it produces the largest policy library.