PwC India Sets Board-Approved Risk Appetite as the Anchor for AI Model Governance
What happened
PwC India's Governing models in the AI era guidance, published in July 2026, recommends that organizations start by formally defining what qualifies as a model before attempting to build an inventory, because model-like tools such as retrieval components, scoring functions, and embedding layers are routinely omitted from governance programs when scope is left undefined. The guidance then calls for a full model register that captures ownership, data sources, dependencies, validation status, and limitations for every in-scope system. PwC also recommends that boards approve explicit risk appetite thresholds specific to AI model risk, rather than relying on generic enterprise risk tolerances that were written before AI systems became operationally significant. For third-party AI, the guidance advises organizations to apply AI-specific due diligence rather than adapting standard vendor assessments, reflecting the distinct failure modes, opacity, and update cadences of AI solutions. The recommendations align with documentation and conformity obligations under ISO/IEC 42001:2023 and the inventory and risk classification expectations that regulators have begun to enforce under the EU AI Act, as flagged in the EU AI Act enforcement update earlier this year.
Why it matters
- ·Incomplete scope definitions are the root cause of most AI inventory failures: without a formal organizational definition of 'model,' retrieval components, scoring layers, and embedded tools escape the register entirely, creating undocumented regulatory exposure under frameworks like ISO/IEC 42001:2023 that require documented system inventories.
- ·Board-level risk appetite for AI model risk is increasingly a regulatory expectation, not merely a governance best practice, and organizations that cannot demonstrate an approved threshold face difficulty defending their AI risk classification decisions during audits or incident reviews.
- ·Third-party AI due diligence programs built on standard vendor questionnaires systematically miss AI-specific risks such as undisclosed model updates, training data provenance gaps, and opaque failure modes, meaning procurement controls must be redesigned rather than simply extended.
Governance controls affected
What to do now
- ☐Publish and ratify an internal definition of 'model' that explicitly includes model-like tools such as retrieval components, embedding layers, and scoring functions, then use that definition to scope your next inventory exercise.
- ☐Audit your existing AI model register against the PwC metadata categories: confirm that every entry has an assigned owner, documented data sources, dependency map, validation status, and recorded limitations.
- ☐Bring a board-level AI model risk appetite proposal to the next governance committee cycle, distinct from general enterprise risk appetite, with draft thresholds tied to your highest-risk model categories.
- ☐Review your third-party AI vendor due diligence questionnaire and add AI-specific sections covering model update notification, training data provenance disclosure, and vendor incident response obligations.
- ☐Map the PwC guidance recommendations against your current ISO/IEC 42001:2023 implementation gaps and use them to prioritize remediation items before your next conformity review.
What to watch next
Regulators in the EU are already citing documentation and inventory gaps in early AI Act enforcement actions, so organizations that have not completed a scoped inventory by year-end face growing audit exposure. Pending technical standards under the EU AI Act are expected to add further specificity to what a conforming model register must contain, and those standards will likely reference inventory metadata categories similar to those PwC recommends. Compliance teams should also watch whether guidance from national competent authorities begins to specify board-level risk appetite documentation as a formal requirement rather than a recommendation, a trajectory already visible in financial services AI risk frameworks such as the Treasury Department AI Risk Management Framework for Financial Services.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
