AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

← News
Research2026-07-23

DDMI's Two-Step AI Approval Model Shows How Enterprises Can Operationalize Use-Case and Product Review as Separate Gates

What happened

DDMI, a data-driven enterprise, has shared a detailed case study via Dataversity describing how it operationalized AI governance through a structured two-step approval process in an article titled AI Governance in Action: Practical Insights from a Data-Driven Enterprise. In the first step, reviewers assess whether the proposed use case is appropriate and permissible before any specific tool or product is considered. Only after use-case approval does the second step evaluate the particular AI product or service under consideration, including legal and regulatory checks, security assessments, and data-location guardrails. The separation of these two gates prevents organizations from anchoring approval decisions to a specific vendor or product before the underlying use has been validated, a sequencing error that is common in ad hoc AI adoption. DDMI also describes continuous monitoring obligations that persist after deployment, framing governance as an ongoing function rather than a one-time approval event. The practical controls outlined in the case study are directly transferable to enterprise AI review workflows and complement widely discussed models such as the Mastercard pre-build risk scorecard and the gated governance approach covered in a recent enterprise case study.

Why it matters

  • ·Regulators and auditors increasingly expect documented, structured AI intake processes: a two-step model that separates use-case approval from product approval creates a clear audit trail and reduces the risk of approvals being driven by vendor preference rather than risk analysis.
  • ·Data-location guardrails embedded at the approval stage address a persistent compliance exposure -- many organizations discover cross-border data transfer or residency violations only after deployment, at which point remediation is costly and may trigger notification obligations under applicable privacy regimes.
  • ·Continuous monitoring requirements in the DDMI model reflect the direction of emerging AI governance frameworks globally, meaning organizations that treat approval as a terminal event rather than the start of an ongoing oversight obligation are building programs that are already misaligned with regulatory expectations.

Governance controls affected

What to do now

  • Audit your current AI intake process to determine whether use-case approval and product or vendor approval are distinct gates, and restructure the workflow if they are conflated into a single step.
  • Add data-location and cross-border transfer checks as explicit criteria in your product-level approval gate, not as a post-deployment review.
  • Define the continuous monitoring obligations that attach to each approved AI deployment, including who is responsible, at what cadence, and what thresholds trigger escalation or re-review.
  • Document the rationale for both the use-case and product approval decisions separately so that each gate produces an independently retrievable audit record.
  • Map the DDMI legal and regulatory check criteria against your existing vendor assessment questionnaire and update the questionnaire where gaps exist.

What to watch next

Compliance teams should monitor whether other named enterprises publish similarly granular case studies, as regulators in multiple jurisdictions are signaling that documented intake processes will be an early focus of AI governance audits. The ISO/IEC 42001:2023 – Information Technology – Artificial Intelligence – Management System certification process is increasingly being used as a benchmark against which enterprise intake workflows are evaluated, and auditors are beginning to ask for evidence of structured pre-deployment gates specifically. Teams should also track whether forthcoming guidance from US state regulators -- particularly those implementing provisions of laws like the Colorado AI Act SB205 -- incorporates explicit sequencing requirements for use-case versus product approval, which would elevate the DDMI model from best practice to legal obligation in those jurisdictions.

Stay ahead of stories like this

Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-08-17

KPMG Frames AI Governance as a Model Risk Problem, Not a Separate Silo

KPMG has published a guide positioning AI oversight as an extension of existing model risk management structures rather than a standalone governance program. The guide organizes AI oversight around four pillars: governance, development, validation, and monitoring. Compliance teams are advised to integrate AI controls into familiar model risk frameworks rather than build parallel processes.

Research2026-08-17

Keyrus 2026 Guide Sets a Baseline Operating Model for AI Governance Programs

Consulting firm Keyrus has published a practitioner guide outlining how enterprises should structure AI governance programs in 2026, emphasizing four foundational elements: a complete AI inventory, risk-based prioritization, cross-functional governance teams, and oversight of vendor-supplied models. The guide provides a replicable operating model that compliance teams can adapt and pair with existing controls. It targets organizations at any stage of AI governance maturity.

Research2026-08-10

Bluewave's 90-Day Blueprint Gives Compliance Teams a Phased Governance Starter Model

Bluewave Technology Group has published a phased implementation guide outlining how organizations can stand up a foundational AI governance program within 90 days. The blueprint sequences controls across three phases, beginning with scope definition, a working group, an acceptable use policy, and an AI inventory, then adds ownership structures, approval tollgates, observability, and vendor and privacy review questions. It is designed as a practical starter model for compliance teams that have not yet formalized AI governance.