Governance operating model
Principles are only real when they change what happens on a Tuesday. This module gives you a practical operating model: a way to organize governance, know what you have, sort uses by risk, keep humans in charge, and review the whole thing on a rhythm. It is how good intentions become dependable practice.
By the end, you will be able to
- Organize governance around a small set of ongoing functions.
- Know every AI use in your organization and who owns it.
- Sort uses into risk tiers with clear boundaries.
- Set the human oversight, reporting, and review that keep it all honest.
Lesson 1
A governance spine
You do not have to invent governance from nothing. A few ongoing functions, borrowed from a widely used framework, give you a spine to hang everything on.
Governance is easier when it is organized around a small number of ongoing functions rather than a one-time policy. A widely used voluntary framework, the NIST AI Risk Management Framework (AI RMF 1.0), offers a simple set of four to borrow.
- Govern: the cross-cutting culture, roles, and accountability that the other three functions run inside.
- Map: understand each AI use in its real context, including who it affects.
- Measure: track how a use is actually performing, including its harms.
- Manage: act on what you find, from adjusting to pausing to stopping a use.
Note
These four are a voluntary framework, not a law. You are borrowing a proven structure, not meeting a legal requirement. Use it as a spine and adapt it to your size and mission.
Try it
Take one AI use in your organization and walk it through the four functions out loud: how is it governed, mapped, measured, and managed? The gaps you feel are your starting to-do list.
RememberBorrow four ongoing functions as a spine: Govern, Map, Measure, and Manage. It is a voluntary structure, not law.
Lesson 2
Inventory and ownership
You cannot govern what you cannot see. The first concrete step is knowing every place AI is in use and who owns each one.
Most organizations underestimate how much AI is already in their tools. Before you can set controls, you need an honest inventory: the tools you chose, the AI embedded in software you already use, and the vendor systems making decisions in the background.
- Systems: the AI tools your organization has deliberately adopted.
- Embedded AI: features inside familiar software, like writing help or suggested replies.
- Vendors: outside platforms that score, sort, or route people for you.
- Use cases: what each one is actually used for, in plain terms.
- Data: what information each use touches.
- Owners: a named, accountable person for every single entry.
Important
The most common gap is not a dangerous tool. It is a use no one owns. If an entry on your inventory has no named owner, that is the first thing to fix, before any control.
Try it
Start the list. Name three AI uses in your organization and, for each, the one person who should be accountable for it. Notice where you cannot name an owner.
RememberInventory every AI use, including embedded and vendor ones, and give each one a named, accountable owner.
Lesson 3
Risk tiers and boundaries
Not every AI use needs the same care. Sorting uses into a few risk tiers lets you spend attention where the stakes are real.
Treating every AI use the same either strangles low-risk work in paperwork or lets high-risk work run unwatched. A small set of risk tiers fixes that, matching the level of control to the level of consequence.
- Routine: low stakes, reversible, no personal decisions. Light-touch, allowed by default.
- Controlled: real stakes, allowed with defined controls and review.
- Restricted: high stakes touching people or sensitive data, allowed only with strong safeguards and sign-off.
- Prohibited: uses your organization has decided it will not do, full stop.
A drafting assistant used for a newsletter subject line sits in routine. The same assistant used to help decide who receives emergency assistance sits in restricted, because a person's outcome depends on it. The tier follows the stakes, not the software.
Try it
Take three AI uses from your inventory and drop each into a tier: routine, controlled, restricted, or prohibited. The ones you argue over are the ones worth governing carefully.
RememberSort uses into routine, controlled, restricted, and prohibited, and always provide a clear exception path.
Lesson 4
Human oversight and recourse
A tier is only as good as the human standing behind the high-stakes decisions. Meaningful oversight has specific parts.
For any use that affects a person, a human has to stay meaningfully in control. That is more than a name on a form. It means a real person with the ability and the standing to change the outcome, and a real path for the affected person to push back.
- Competence: the human reviewer understands the decision well enough to judge it.
- Authority: that person can actually override the tool, not just approve it.
- Time: they have the room to review properly, not a rushed rubber stamp.
- Documentation: what was used, checked, and decided is written down.
- Appeal: the affected person has a clear way to question the decision and reach a human.
Important
The quiet failure is the rubber stamp: a reviewer with no time, no real authority, or no understanding, approving whatever the tool produced. On paper there is human oversight. In practice there is none.
Try it
Pick one high-stakes AI use and test it against the five parts. Which one is weakest today? That weak link is where oversight would actually break.
RememberMeaningful oversight needs competence, authority, time, documentation, and a real appeal path, not just a signature.
Lesson 5
Policy, reporting, and review
Governance is not a document you write once. It is a rhythm: training, tracking, reporting to the board, and changing policy as you learn.
The final piece turns everything above into an ongoing practice. Policy is written and taught, incidents and complaints are tracked, a few honest measures reach the board on a schedule, and the policy itself changes as reality teaches you things.
- Training: the people using AI know the policy and the safe habits behind it.
- Incidents: near misses and problems are reported without blame, so they surface.
- Complaints: the people affected have a route to raise concerns, and it is watched.
- Metrics: a small set of honest measures, including harm, reaches the board.
- Board cadence: AI oversight is a standing item on a regular schedule, not a crisis reaction.
- Policy change: what you learn feeds back into the policy, which is expected to evolve.
Note
Keep the reporting small and honest. A short, truthful set of measures the board actually reads beats a large dashboard no one trusts. The goal is a rhythm you will really keep.
Try it
Decide one thing: how often would AI oversight appear on your board's agenda, and what few measures would you want to see each time? Writing that down starts the rhythm.
RememberMake governance a rhythm: train, track incidents and complaints, report a few honest measures, and let policy evolve.
What you leave with
Governance charter, RACI, and risk-tier framework
A working operating model on a page or two. It holds a short governance charter and a simple map of who is responsible and accountable for AI decisions. It also sets your risk-tier definitions, with their boundaries and exception path. It turns your principles into something your organization can actually run.
This is just for you. It saves on this device only, and nothing is scored.