What Is AI Governance?

AI governance is the system of ownership, policies, controls and evidence used to manage AI decisions and risks throughout their lifecycle.

AI governance is the system of ownership, policies, controls and evidence used to manage AI systems and their risks throughout the lifecycle. It connects business accountability, data, models, vendors, security, legal requirements and human oversight. A policy without an inventory or operating controls is not complete governance.

What does AI governance cover?

  • Use-case inventory, purpose and accountable owner
  • Data sources, permissions, quality and retention
  • Model and vendor assessment
  • Testing, approval and release controls
  • Human review, appeal and escalation
  • Monitoring, incidents, changes and retirement

How should governance scale?

Apply controls according to the consequence of error, affected people, autonomy, data sensitivity and reversibility. A summarization aid and an automated payment decision should not receive the same review merely because both use AI.

Governance vs. model risk management

Model risk management focuses on model performance, validation and limitations. AI governance is broader: it also covers purpose, data, users, vendors, security, accountability and operational use.

What evidence should be retained?

Keep the approved use case, risk assessment, test results, configuration, model and data versions, monitoring, overrides, incidents and material changes. The evidence should show what the system did and who remained responsible.

Related Terms