AI Governance Institute
← News

Protiviti's AI Governance Guide Surfaces a Structural Gap: Most Enterprises Still Lack Formal Intake, Inventory, and Committee Controls

What happened

Protiviti released the AI Governance Guide: Risks, ROI & Enterprise Strategy, a structured reference document addressing the most common questions enterprise compliance and risk teams face when standing up or scaling an AI governance program. Published in December 2024, the guide covers four foundational areas: establishing executive leadership accountability for AI, forming an AI governance committee with defined decision rights, creating scalable intake and inventory processes for AI models, and embedding ethical standards into cross-functional collaboration. The document does not carry the force of regulation, but it reflects current practitioner consensus on the minimum structural controls that organizations should have in place. Protiviti positions the guide as applicable to US enterprises across sectors, particularly those that have deployed AI tools without yet formalizing oversight mechanisms.

Why it matters

  • ·Regulatory exposure: US federal and state regulators, including the FTC and emerging state-level frameworks in Colorado, Texas, and California, are increasingly scrutinizing whether organizations can demonstrate structured AI oversight, making the absence of a formal governance committee or model inventory a documented liability.
  • ·Operational impact: Without a scalable AI intake and model inventory process, compliance teams cannot answer basic audit questions about which AI systems are in use, who approved them, or what risks they carry, creating material gaps in any compliance program.
  • ·Organizational risk: Diffuse executive accountability for AI outcomes, where no named leader or committee owns AI governance, leaves organizations unable to escalate incidents, enforce policy, or demonstrate board-level oversight to auditors, investors, or regulators.

Governance controls affected

What to do now

  • Audit whether your organization has a formally chartered AI governance committee with documented decision rights, membership, and escalation paths, and close any gaps against the committee structure Protiviti recommends.
  • Review your current AI model intake process to confirm it captures all deployed models, including third-party and shadow AI tools, and assigns a risk classification to each at the point of intake.
  • Confirm that a named executive or senior leadership function holds documented accountability for AI governance outcomes, separate from IT or legal ownership alone.
  • Map your existing AI inventory against your ethics and acceptable use policies to identify models or use cases that have never been formally reviewed against those standards.
  • Use the guide's committee and intake framework as a baseline for a maturity gap assessment, then prioritize the three or four structural controls most likely to be requested by regulators or auditors in the next 12 months.

What to watch next

Compliance teams should monitor how state-level AI governance requirements in Colorado, Texas, and California begin to prescribe specific committee structures, inventory obligations, or executive accountability standards, since voluntary frameworks like this one often anticipate what becomes mandatory. The FTC's continued AI enforcement activity and the SEC's evolving expectations for AI risk disclosure to investors are also likely to create pressure for the exact structural controls Protiviti describes. Practitioners building governance programs should track whether ISO 42001 certification begins to emerge as a de facto audit benchmark that regulators or procurement counterparties reference, which would raise the stakes for organizations that have not yet formalized their committee and intake controls.

Stay ahead of stories like this

Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-09-01

SR 26-2 Forces Banks to Rethink Model Governance From Inventory to Board Oversight

The OCC and Federal Reserve's revised model risk management guidance, SR 26-2, resets supervisory expectations for U.S. banks by shifting to a materiality-based approach that covers both traditional statistical models and AI systems, replacing the SR 11-7 framework that had governed bank model governance since 2011. Practitioner analysis from CRA identifies four areas banks must redesign: inventory scope, model tiering, validation independence, and governance alignment up to the board. A companion implementation guide from Lumenova AI adds concrete steps, including inventory rationalization and a distinct governance lane for agentic and generative AI, while a proposed academic framework maps a six-layer control architecture for bringing GenAI systems into SR 26-2 scope. Banks that still run AI governance and model risk management as separate programs face the most immediate pressure to harmonize them.

Research2026-09-06

Telstra's Role-Based AI Policy Overhaul Offers a Replicable Governance Blueprint

A case study published by the University of Technology Sydney documents how Telstra restructured its AI governance program around role-based policy ownership and simplified intake and impact assessment workflows. The research, produced through UTS's Human Technology Institute, identifies specific operational changes that reduced friction in AI triage while strengthening accountability. Enterprise compliance teams can extract a practical operating model from the findings.

Research2026-09-01

PwC Banking AI Framework Maps Five Gaps SR 26-2 Left Unresolved

PwC Germany published a whitepaper structuring AI governance for banks around five core challenges: scope definition, three-lines-of-defense adaptation, proportionality, third-party risk, and AI-specific model validation. The paper offers a practical implementation scaffold for financial institutions working through model risk management reform. It does not introduce regulatory obligations, but provides detailed control-ownership guidance banks can use to close gaps left by existing supervisory requirements.