AI Governance Institute
← News
Research2026-08-24

PwC India Sets Board-Approved Risk Appetite as the Anchor for AI Model Governance

What happened

PwC India's Governing models in the AI era guidance, published in July 2026, recommends that organizations start by formally defining what qualifies as a model before attempting to build an inventory, because model-like tools such as retrieval components, scoring functions, and embedding layers are routinely omitted from governance programs when scope is left undefined. The guidance then calls for a full model register that captures ownership, data sources, dependencies, validation status, and limitations for every in-scope system. PwC also recommends that boards approve explicit risk appetite thresholds specific to AI model risk, rather than relying on generic enterprise risk tolerances that were written before AI systems became operationally significant. For third-party AI, the guidance advises organizations to apply AI-specific due diligence rather than adapting standard vendor assessments, reflecting the distinct failure modes, opacity, and update cadences of AI solutions. The recommendations align with documentation and conformity obligations under ISO/IEC 42001:2023 and the inventory and risk classification expectations that regulators have begun to enforce under the EU AI Act, as flagged in the EU AI Act enforcement update earlier this year.

Why it matters

  • ·Incomplete scope definitions are the root cause of most AI inventory failures: without a formal organizational definition of 'model,' retrieval components, scoring layers, and embedded tools escape the register entirely, creating undocumented regulatory exposure under frameworks like ISO/IEC 42001:2023 that require documented system inventories.
  • ·Board-level risk appetite for AI model risk is increasingly a regulatory expectation, not merely a governance best practice, and organizations that cannot demonstrate an approved threshold face difficulty defending their AI risk classification decisions during audits or incident reviews.
  • ·Third-party AI due diligence programs built on standard vendor questionnaires systematically miss AI-specific risks such as undisclosed model updates, training data provenance gaps, and opaque failure modes, meaning procurement controls must be redesigned rather than simply extended.

Governance controls affected

What to do now

  • ☐Publish and ratify an internal definition of 'model' that explicitly includes model-like tools such as retrieval components, embedding layers, and scoring functions, then use that definition to scope your next inventory exercise.
  • ☐Audit your existing AI model register against the PwC metadata categories: confirm that every entry has an assigned owner, documented data sources, dependency map, validation status, and recorded limitations.
  • ☐Bring a board-level AI model risk appetite proposal to the next governance committee cycle, distinct from general enterprise risk appetite, with draft thresholds tied to your highest-risk model categories.
  • ☐Review your third-party AI vendor due diligence questionnaire and add AI-specific sections covering model update notification, training data provenance disclosure, and vendor incident response obligations.
  • ☐Map the PwC guidance recommendations against your current ISO/IEC 42001:2023 implementation gaps and use them to prioritize remediation items before your next conformity review.

What to watch next

Regulators in the EU are already citing documentation and inventory gaps in early AI Act enforcement actions, so organizations that have not completed a scoped inventory by year-end face growing audit exposure. Pending technical standards under the EU AI Act are expected to add further specificity to what a conforming model register must contain, and those standards will likely reference inventory metadata categories similar to those PwC recommends. Compliance teams should also watch whether guidance from national competent authorities begins to specify board-level risk appetite documentation as a formal requirement rather than a recommendation, a trajectory already visible in financial services AI risk frameworks such as the Treasury Department AI Risk Management Framework for Financial Services.

Related Coverage

Research2026-10-03

CSA's ISO 42001 Certification Guide Sets the Audit Evidence Bar

The Cloud Security Alliance published a practical guide to achieving certification under ISO/IEC 42001:2023, the international standard for AI management systems. The guide specifies the concrete documentation an auditor will expect. Required artifacts include an AI policy, a scope statement, a risk and impact assessment method, a Statement of Applicability, role definitions, an AI inventory, provenance records, and incident logs. Organizations pursuing certification or requiring it from vendors now have a clearer benchmark against which their current programs will be measured.

Research2026-10-02

PwC: AI Attacks Top Threat List, But Only 22% Back Autonomous Cyber Defense

PwC's 2027 Global Digital Trust Insights report is based on nearly 4,000 leaders across 70-plus countries. It finds that attacks targeting AI systems rank as the threat enterprises feel least prepared to handle. Only 22% of respondents would deploy fully autonomous AI agents for cyber defense without human oversight, with governance skill gaps cited as a barrier. A parallel readiness failure appears in quantum-resistant security, where just 21% of organizations have begun adopting protections against future decryption attacks.

Enforcement2026-09-29

Florida AG Targets ChatGPT's Human-Like Persona and Safety Guardrails

Florida Attorney General James Uthmeier has filed to block OpenAI from giving ChatGPT human attributes such as first-person language and emotion-mimicking responses. The filing argues these design choices deceive users into trusting the chatbot as a friend, particularly harming minors. It also seeks to require third-party-approved safety guardrails before OpenAI deploys new AI models.