Model & Program Governance
Operational controls for model & program governance, with maturity levels, evidence requirements, and implementation guidance.
Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →10 controls
AI Model Preview and Staged Release Policy
Distinguish preview and experimental access from approved production use. Require documented governance approval at each release stage before wider deployment.
AI System Intake and Approval Workflow
Use a standard intake process before new AI systems enter the organization. Record use case, data classification, risk tier, and ownership. Route approvals across relevant functions and retain GRC records.
AI Governance Program Milestone Framework
Set governance milestones throughout deployment. Require completion before a system advances to its next lifecycle stage.
Continuous AI Assurance Function Design
Operate an ongoing assurance function that produces regular evidence of control effectiveness. Give boards, regulators, and enterprise customers current records of the governance program’s performance.
Generative AI Input Data Classification
Classify data entering generative AI through prompts, context windows, retrieved documents, tool outputs, and conversation history. Address privacy, confidentiality, and regulatory risks absent from general data classification rules.
RAI Benchmark-Aligned Evaluation Framework
Map system evaluations to benchmarks such as HELM Safety, AIR-Bench, and FACTS. Produce evidence regulators, auditors, and enterprise customers can compare against independent standards.
Emerging AI Modality Classification and Governance Extension
Detect new AI capabilities entering the organization, including ambient AI, multimodal agents, brain-computer interfaces, and always-on assistants. Extend governance coverage before widespread deployment.
AI-Generated Deliverable Disclosure and Citation Standards
Set AI disclosure standards for client-facing, regulatory, and published work. Verify generated citations and factual claims before external distribution. Professional services teams should disclose AI involvement before closing engagements.
AI Capability Claim Substantiation Standard
Set documentation standards for AI capability claims. Cover marketing, product documentation, sales discussions, regulatory submissions, and procurement responses. Retain supporting evidence that meets FTC disclosure expectations and enterprise due diligence requirements.
AI Output Pre-Publication Verification for High-Stakes Claims
Require human checks of AI-generated numbers, legal citations, regulatory references, and other high-stakes claims before external publication or regulatory submission. Keep verification checklists and auditable approval records.
Model & Program Governance, tracked weekly
New model & program governance controls and the regulatory developments driving them, plus everything else changing in AI governance. Every Thursday.
