AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

← News
Research2026-08-24

PwC India Sets Board-Approved Risk Appetite as the Anchor for AI Model Governance

What happened

PwC India's Governing models in the AI era guidance, published in July 2026, recommends that organizations start by formally defining what qualifies as a model before attempting to build an inventory, because model-like tools such as retrieval components, scoring functions, and embedding layers are routinely omitted from governance programs when scope is left undefined. The guidance then calls for a full model register that captures ownership, data sources, dependencies, validation status, and limitations for every in-scope system. PwC also recommends that boards approve explicit risk appetite thresholds specific to AI model risk, rather than relying on generic enterprise risk tolerances that were written before AI systems became operationally significant. For third-party AI, the guidance advises organizations to apply AI-specific due diligence rather than adapting standard vendor assessments, reflecting the distinct failure modes, opacity, and update cadences of AI solutions. The recommendations align with documentation and conformity obligations under ISO/IEC 42001:2023 and the inventory and risk classification expectations that regulators have begun to enforce under the EU AI Act, as flagged in the EU AI Act enforcement update earlier this year.

Why it matters

  • ·Incomplete scope definitions are the root cause of most AI inventory failures: without a formal organizational definition of 'model,' retrieval components, scoring layers, and embedded tools escape the register entirely, creating undocumented regulatory exposure under frameworks like ISO/IEC 42001:2023 that require documented system inventories.
  • ·Board-level risk appetite for AI model risk is increasingly a regulatory expectation, not merely a governance best practice, and organizations that cannot demonstrate an approved threshold face difficulty defending their AI risk classification decisions during audits or incident reviews.
  • ·Third-party AI due diligence programs built on standard vendor questionnaires systematically miss AI-specific risks such as undisclosed model updates, training data provenance gaps, and opaque failure modes, meaning procurement controls must be redesigned rather than simply extended.

Governance controls affected

What to do now

  • Publish and ratify an internal definition of 'model' that explicitly includes model-like tools such as retrieval components, embedding layers, and scoring functions, then use that definition to scope your next inventory exercise.
  • Audit your existing AI model register against the PwC metadata categories: confirm that every entry has an assigned owner, documented data sources, dependency map, validation status, and recorded limitations.
  • Bring a board-level AI model risk appetite proposal to the next governance committee cycle, distinct from general enterprise risk appetite, with draft thresholds tied to your highest-risk model categories.
  • Review your third-party AI vendor due diligence questionnaire and add AI-specific sections covering model update notification, training data provenance disclosure, and vendor incident response obligations.
  • Map the PwC guidance recommendations against your current ISO/IEC 42001:2023 implementation gaps and use them to prioritize remediation items before your next conformity review.

What to watch next

Regulators in the EU are already citing documentation and inventory gaps in early AI Act enforcement actions, so organizations that have not completed a scoped inventory by year-end face growing audit exposure. Pending technical standards under the EU AI Act are expected to add further specificity to what a conforming model register must contain, and those standards will likely reference inventory metadata categories similar to those PwC recommends. Compliance teams should also watch whether guidance from national competent authorities begins to specify board-level risk appetite documentation as a formal requirement rather than a recommendation, a trajectory already visible in financial services AI risk frameworks such as the Treasury Department AI Risk Management Framework for Financial Services.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-08-18

Vendor AI Usage Reports Systematically Filter Harmful Behavior, Study Finds

An independent research platform called the AI Observatory, led by researchers from Stanford and MIT, analyzed over 24,000 real AI conversations and found that usage reports published by major AI companies systematically exclude non-work-related interactions. The omission conceals materially higher rates of sensitive behaviors including harassment, hate speech, and adult content. Enterprise compliance programs that rely on vendor-published data for risk assessments are working from a structurally incomplete picture.

Research2026-08-17

KPMG Frames AI Governance as a Model Risk Problem, Not a Separate Silo

KPMG has published a guide positioning AI oversight as an extension of existing model risk management structures rather than a standalone governance program. The guide organizes AI oversight around four pillars: governance, development, validation, and monitoring. Compliance teams are advised to integrate AI controls into familiar model risk frameworks rather than build parallel processes.

Research2026-08-24

NHS Trust Pilot Governance Framework Offers a Template for Regulated AI Deployments

NHS Digital Regulations Innovation published a case study describing how an NHS Trust built a structured implementation and governance framework for AI pilot studies, led by a consultant radiologist. The framework covers local approval processes, oversight mechanisms, and controlled evaluation before scaling to production. Compliance teams in healthcare and other regulated industries can use it as a reference model for governing AI pilots that handle sensitive data or inform clinical decisions.