AI Governance Institute
← News
Research2026-07-09

Multi-Tiered AI Governance Committees Tested at Scale: Banco Bradesco and TELUS Case Studies Reveal What Works

What happened

The AI Company Data Initiative released Responsible AI in Practice: AI Company Data Initiative Case Studies, a primary-source report documenting real-world AI governance implementations at two major enterprises operating across multiple jurisdictions. Banco Bradesco, one of Brazil's largest financial institutions, and TELUS, a Canadian telecommunications company, each contributed detailed accounts of their governance architectures, including the composition and mandate of strategic steering committees, the cadence and scope of quarterly operational reviews, and the specific mechanisms used to embed human-rights safeguards across the AI development lifecycle. The report identifies cross-functional alignment as a structural requirement rather than an aspiration, noting that both organizations developed role-specific training programs rather than relying on generalized AI literacy initiatives. Published under a global jurisdiction scope, the findings are intended as a transferable implementation model for enterprises building or maturing their own responsible AI programs.

Why it matters

  • ·Regulatory exposure: Human-rights-based safeguards are increasingly referenced in emerging AI regulations and procurement standards, and organizations that cannot demonstrate their governance structure embeds these considerations at the lifecycle level face heightened scrutiny under frameworks such as the EU AI Act and UNESCO AI Ethics Recommendation.
  • ·Operational impact: The two-tier committee structure documented here, separating strategic oversight from operational execution with defined review cadences, provides a concrete governance architecture that compliance teams can map against their existing controls and identify gaps in accountability chains.
  • ·Organizational risk: Role-specific AI training requirements, as implemented at both Banco Bradesco and TELUS, reduce the risk of misuse and accountability gaps across business units, and organizations relying on generic training programs may find those programs inadequate under regulator or auditor review.

Governance controls affected

What to do now

  • Map your current AI governance committee structure against the two-tier strategic and operational model documented for Banco Bradesco and TELUS, and identify any gaps in decision rights or escalation paths.
  • Review your AI governance charter to confirm that human-rights considerations are explicitly embedded as a mandatory checkpoint at each stage of the AI system lifecycle, not addressed only at the policy level.
  • Audit your AI training program to determine whether it differentiates by job function, and replace any single generalized module with role-specific curricula aligned to the responsibilities of each group interacting with AI systems.
  • Establish a quarterly AI governance review cadence at the operational committee level if one does not already exist, with defined agenda items covering risk thresholds, incident review, and policy updates.
  • Use the Banco Bradesco and TELUS case studies as a benchmark input to your next AI governance maturity assessment, documenting where your program aligns with and diverges from the structures described.

What to watch next

Compliance teams should monitor whether other major industry initiatives publish comparable case study reports, as regulators in the EU and Latin America have signaled increasing interest in using enterprise implementation evidence to inform guidance on what constitutes adequate governance structure. The AI Company Data Initiative may release additional sector-specific case studies covering industries beyond financial services and telecommunications, which would allow compliance teams to benchmark against peers more precisely. Enforcement actions and supervisory reviews in Brazil and Canada, where Banco Bradesco and TELUS operate, may increasingly reference governance architecture expectations that align with the multi-tiered committee model documented here.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-09-07

CISO AI Confidence Tracks Governance Readiness, Not Control Effectiveness

An IANS Research survey of 113 CISOs found that optimism about managing AI security risks over the next 24 months correlates more strongly with organizational readiness factors than with verified technical controls. Factors such as leadership understanding of AI risk, defined governance ownership, CISO budget authority, and adequate staffing drive confidence levels. Analysts caution that these signals reflect favorable conditions rather than demonstrated control outcomes, and that third-party AI risk and agent authorization gaps remain broadly unaddressed.

Research2026-09-06

Telstra's Role-Based AI Policy Overhaul Offers a Replicable Governance Blueprint

A case study published by the University of Technology Sydney documents how Telstra restructured its AI governance program around role-based policy ownership and simplified intake and impact assessment workflows. The research, produced through UTS's Human Technology Institute, identifies specific operational changes that reduced friction in AI triage while strengthening accountability. Enterprise compliance teams can extract a practical operating model from the findings.

Research2026-09-03

ISO 42001 Implementation Gap Exposed: Clause-by-Clause Guide Sets Audit Baseline

enz.ai has published a detailed implementation guide for ISO/IEC 42001:2023, covering each clause of the standard from scoping and leadership through internal audit and Annex A control mapping. The guide gives compliance teams a structured path for standing up a conformant AI management system before pursuing formal certification. Organizations facing regulatory expectations of structured AI governance can use the guidance to assess and close readiness gaps.