AI Governance Institute
← News
Research2026-09-12

FTI Consulting's 30-Day AI Governance Playbook Sets a Program-Launch Baseline

What happened

FTI Consulting's Risk Management in the AI Era: A Playbook for Leaders gives compliance officers a sequenced 30-day structure for getting an AI governance program off the ground. The playbook is organized in three phases: securing leadership alignment on risk appetite and accountability, conducting a baseline assessment of existing AI exposure, and identifying where AI creates the most business value and therefore the greatest governance priority. Rather than treating every AI risk as equally urgent, the framework directs teams to triage by business impact, which gives compliance officers a practical rationale for sequencing their workload. The document is aimed at leaders who recognize the need to govern AI but lack a coherent starting point, and it positions governance as an ongoing operating model rather than a one-time compliance exercise. The publication follows a growing body of practitioner guidance from consulting firms, including similar efforts catalogued in reports from Bluewave's 90-day blueprint and Keyrus's 2026 baseline operating model, reflecting demand for implementation-ready frameworks over high-level principles.

Why it matters

  • ·Organizations without a documented AI governance program face increasing exposure as regulations such as the EU AI Act: High-Risk AI Systems, Transparency, and Enforcement Powers Applicable 2 August 2026 and state-level frameworks create affirmative compliance obligations -- an undocumented program is difficult to defend in an audit or enforcement context.
  • ·The playbook's sequencing logic -- alignment before assessment, assessment before deployment review -- addresses the most common operational failure mode in AI governance programs, where controls are adopted before ownership and risk appetite are settled, producing documentation that does not reflect actual practice.
  • ·For risk and audit functions, the 30-day triage model creates a concrete deliverable timeline that can be reported to senior leadership and the board, supporting the kind of structured AI risk reporting that frameworks such as ISO/IEC 42001:2023 - Artificial Intelligence Management System and mature governance programs now expect.

Governance controls affected

What to do now

  • ☐Use the FTI playbook's first phase as a checklist prompt: confirm that your organization has documented AI risk appetite and assigned clear ownership before attempting to expand or formalize technical controls.
  • ☐Map the playbook's baseline assessment phase against your existing AI inventory to identify gaps between systems currently in use and systems subject to formal governance review.
  • ☐If your governance program is still undocumented, treat the 30-day structure as a board-reportable milestone plan and schedule a progress update at the 30-day mark.
  • ☐Cross-reference the playbook's value-identification phase with your AI system inventory to prioritize governance resources toward the use cases with the highest business impact and corresponding regulatory exposure.
  • ☐Benchmark your program launch timeline against peer frameworks published by FTI, Bluewave, and Keyrus to identify which phases your organization has completed and which remain open.

What to watch next

As practitioner demand for implementation-ready AI governance models grows, compliance teams should monitor whether consulting firm playbooks begin to be cited by regulators or enforcement bodies as a reasonable standard of care -- a pattern already visible in financial services through guidance like SR 26-2. The NIST Artificial Intelligence Risk Management Framework Playbook and ISO/IEC 42001:2023 - Artificial Intelligence Management System remain the most widely cited foundations for program design, and teams should track whether forthcoming regulatory guidance begins referencing phased launch structures as a baseline expectation. Organizations that have not completed a governance program launch should also watch for enforcement actions where the absence of a documented program -- rather than a specific control failure -- becomes the primary finding.

Related Coverage

Enforcement2026-09-22

NY Comptroller Audit Finds SUNY Lacked AI Definition, Inventory, or Approval Workflows

New York State Comptroller Thomas DiNapoli released an audit finding that SUNY Administration had no effective AI governance framework, no standard definition of AI, and no documented policies or approval workflows for AI development and use. The audit identified specific weaknesses in inventory management, policy controls, and internal accountability. The findings create a public-sector governance benchmark that compliance teams in both government and regulated industries should treat as a checklist.

Enforcement2026-09-30

SBA's AI Fraud Pilot Never Classified as High-Impact, OIG Finds

The SBA's Office of Inspector General found that a Palantir-powered AI fraud detection pilot for COVID-19 loan programs was never classified as a high-impact use case under OMB guidance. As a result, required safeguards including impact assessments, human oversight mechanisms, and borrower appeals processes were never put in place. The OIG issued six recommendations, including establishing a formal process for identifying and documenting high-impact AI use cases.

Research2026-10-02

PwC: AI Attacks Top Threat List, But Only 22% Back Autonomous Cyber Defense

PwC's 2027 Global Digital Trust Insights report is based on nearly 4,000 leaders across 70-plus countries. It finds that attacks targeting AI systems rank as the threat enterprises feel least prepared to handle. Only 22% of respondents would deploy fully autonomous AI agents for cyber defense without human oversight, with governance skill gaps cited as a barrier. A parallel readiness failure appears in quantum-resistant security, where just 21% of organizations have begun adopting protections against future decryption attacks.