AI Governance Institute
← News
Research2026-07-23

DDMI's Two-Step AI Approval Model Shows How Enterprises Can Operationalize Use-Case and Product Review as Separate Gates

What happened

DDMI, a data-driven enterprise, has shared a detailed case study via Dataversity describing how it operationalized AI governance through a structured two-step approval process in an article titled AI Governance in Action: Practical Insights from a Data-Driven Enterprise. In the first step, reviewers assess whether the proposed use case is appropriate and permissible before any specific tool or product is considered. Only after use-case approval does the second step evaluate the particular AI product or service under consideration, including legal and regulatory checks, security assessments, and data-location guardrails. The separation of these two gates prevents organizations from anchoring approval decisions to a specific vendor or product before the underlying use has been validated, a sequencing error that is common in ad hoc AI adoption. DDMI also describes continuous monitoring obligations that persist after deployment, framing governance as an ongoing function rather than a one-time approval event. The practical controls outlined in the case study are directly transferable to enterprise AI review workflows and complement widely discussed models such as the Mastercard pre-build risk scorecard and the gated governance approach covered in a recent enterprise case study.

Why it matters

  • ·Regulators and auditors increasingly expect documented, structured AI intake processes: a two-step model that separates use-case approval from product approval creates a clear audit trail and reduces the risk of approvals being driven by vendor preference rather than risk analysis.
  • ·Data-location guardrails embedded at the approval stage address a persistent compliance exposure, many organizations discover cross-border data transfer or residency violations only after deployment, at which point remediation is costly and may trigger notification obligations under applicable privacy regimes.
  • ·Continuous monitoring requirements in the DDMI model reflect the direction of emerging AI governance frameworks globally, meaning organizations that treat approval as a terminal event rather than the start of an ongoing oversight obligation are building programs that are already misaligned with regulatory expectations.

Governance controls affected

What to do now

  • Audit your current AI intake process to determine whether use-case approval and product or vendor approval are distinct gates, and restructure the workflow if they are conflated into a single step.
  • Add data-location and cross-border transfer checks as explicit criteria in your product-level approval gate, not as a post-deployment review.
  • Define the continuous monitoring obligations that attach to each approved AI deployment, including who is responsible, at what cadence, and what thresholds trigger escalation or re-review.
  • Document the rationale for both the use-case and product approval decisions separately so that each gate produces an independently retrievable audit record.
  • Map the DDMI legal and regulatory check criteria against your existing vendor assessment questionnaire and update the questionnaire where gaps exist.

What to watch next

Compliance teams should monitor whether other named enterprises publish similarly granular case studies, as regulators in multiple jurisdictions are signaling that documented intake processes will be an early focus of AI governance audits. The ISO/IEC 42001:2023 – Information Technology – Artificial Intelligence – Management System certification process is increasingly being used as a benchmark against which enterprise intake workflows are evaluated, and auditors are beginning to ask for evidence of structured pre-deployment gates specifically. Teams should also track whether forthcoming guidance from US state regulators, particularly those implementing provisions of laws like the Colorado AI Act SB205, incorporates explicit sequencing requirements for use-case versus product approval, which would elevate the DDMI model from best practice to legal obligation in those jurisdictions.

Stay ahead of stories like this

Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-08-24

NHS Trust Pilot Governance Framework Offers a Template for Regulated AI Deployments

NHS Digital Regulations Innovation published a case study describing how an NHS Trust built a structured implementation and governance framework for AI pilot studies, led by a consultant radiologist. The framework covers local approval processes, oversight mechanisms, and controlled evaluation before scaling to production. Compliance teams in healthcare and other regulated industries can use it as a reference model for governing AI pilots that handle sensitive data or inform clinical decisions.

Research2026-09-01

PwC Banking AI Framework Maps Five Gaps SR 26-2 Left Unresolved

PwC Germany published a whitepaper structuring AI governance for banks around five core challenges: scope definition, three-lines-of-defense adaptation, proportionality, third-party risk, and AI-specific model validation. The paper offers a practical implementation scaffold for financial institutions working through model risk management reform. It does not introduce regulatory obligations, but provides detailed control-ownership guidance banks can use to close gaps left by existing supervisory requirements.

Research2026-09-01

SR 26-2 Implementation Guide Exposes Legacy Model Inventory Gaps

Lumenova AI has published a practitioner implementation guide for SR 26-2, the Federal Reserve and OCC's updated model risk management supervisory guidance. The guide identifies concrete steps including model inventory rationalization, revised materiality-based tiering, strengthened validation independence, and a separate governance lane for agentic and generative AI. Compliance teams at regulated financial institutions can use the operating model recommendations as a readiness benchmark ahead of examinations.