AI Governance Institute
All governance templates →Who owns AI governance within the organization?

Implementation Kit

AI Governance Charter Template and RACI Matrix

The documents that make AI governance ownership explicit: a charter, a RACI across the core activities, an escalation and pause-authority table, and a one-page structure summary for the board. The output is a signed structure with a named owner for every activity.

Who this is for: The general counsel, chief compliance officer, or chief risk officer asked to stand up AI governance and get it approved by the executive.

Download the kit (Markdown) ↓4 artifacts. Every table also copies as CSV.

1. AI governance charter

Document

The founding document. Fill each section. Keep it to two pages so people actually read it.

Template

Two pages. Approved by the executive sponsor and minuted.

  • Purpose: why this body exists, in two sentences
  • Scope: what counts as AI for this charter, what is in and out
  • Mandate and authority: what the body can decide, approve, require, and halt
  • Membership: roles (not names) with a chair and a quorum rule
  • Decision rights: which decisions the body makes, which it advises on, which are delegated and to whom
  • Meeting cadence: how often, and the trigger for an out-of-cycle meeting
  • Escalation: what comes to this body, from where, and how fast
  • Reporting: what goes up to the board or audit committee, and how often
  • Interfaces: how this body works with Risk, Legal, Security, Data, and Product
  • Review: the date this charter is next reviewed, and who owns that

Worked example

  • Purpose: The AI Governance Committee sets the standards for responsible AI use across the company and holds delegated authority to approve, condition, or halt AI deployments. It is the escalation point for AI risk that exceeds a business unit's tolerance.
  • Scope: Any system that uses machine learning to generate content, predictions, classifications, or actions, whether built, fine-tuned, or bought. Excludes deterministic automation and basic analytics.
  • Mandate and authority: Approve High-tier deployments; require assessments and controls; pause any AI system pending review; own the AI policy set.
  • Membership: Chair is the Chief Risk Officer. Members: AI Governance Lead, General Counsel or delegate, Head of Security, Head of Data, and a rotating business owner. Quorum is the chair plus three, including Legal or Security.
  • Decision rights: Makes the call on High-tier approvals and policy changes. Advises on Limited-tier. Minimal-tier is delegated to the business owner with a register entry.
  • Meeting cadence: Monthly. Out-of-cycle within 3 business days on a Sev-1 AI incident or a pause request.
  • Escalation: Business units escalate via the AI Governance Lead. Incidents come from the incident process.
  • Reporting: Quarterly to the Audit Committee, using the board AI risk report.
  • Interfaces: Risk owns the register; Legal owns regulatory interpretation; Security owns AI security testing; Data owns data governance; Product owns system-level implementation.
  • Review: Next review 2027-03-01, owned by the AI Governance Lead.

Acceptance criteria

  • Every section is filled with a real decision, not left as a placeholder.
  • The charter states what the body can halt and who can invoke a pause, with no ambiguity.
  • It has been approved by an executive sponsor and the approval is minuted.
  • It names a review date and an owner for the review.

2. AI governance RACI

Spreadsheet

Removes "everyone, so no one". One responsible role per activity. Use R, A, C, I, and keep exactly one A per row.

Template

Fill each cell with R, A, C, or I. Exactly one A per row. Rename the role columns to match your org.

ActivityBoard / CommitteeExec sponsorAI governance leadLegalRiskSecurityDataBusiness / product owner
AI system inventory
Risk classification
Vendor due diligence
Incident response
Regulatory monitoring
Training and awareness
Model approval to deploy
Board reporting

Worked example

ActivityBoard / CommitteeExec sponsorAI governance leadLegalRiskSecurityDataBusiness / product owner
AI system inventoryIIACCCCR
Risk classificationIIACRCCC
Vendor due diligenceIICCACCR
Incident responseIICCARCC
Regulatory monitoringIIRACIII
Training and awarenessIARCCCCC
Model approval to deployIIACCCCR
Board reportingARRCCIII

Why the non-obvious calls: on risk classification the AI governance lead is Accountable for the method, Risk is Responsible for running it per system. On incident response Risk is Accountable for the outcome, Security is Responsible for containment. On regulatory monitoring the lead does the scanning, but Legal is Accountable for the interpretation that reaches the business.

Acceptance criteria

  • Exactly one role is Accountable for each activity.
  • The Responsible role for each activity has confirmed they have the capacity and access to do it.
  • The RACI is attached to the charter and reviewed on the same cycle.
  • Role labels match real job titles in your organization, so there is no "who is that?" ambiguity.

3. Escalation and pause-authority table

Spreadsheet

Pre-decides who acts when something goes wrong, so nobody improvises it under pressure.

Template

ConditionDecision ownerTimelineWho must be notified
Suspected harmful or biased output in production<role><act within X hours><roles>
High-tier system wants to deploy without a signed assessment<role><before deployment><roles>
Vendor announces a material model or safety change<role><within X days><roles>
Regulatory deadline or new obligation identified<role><within X days><roles>
Request to pause a live AI system<role with pause authority><immediate><roles>
AI incident rated Sev-1<role><immediate, plus out-of-cycle committee><roles>

Worked example

ConditionDecision ownerTimelineNotify
Suspected harmful or biased output in productionOn-call Security lead can restrict; AI Governance Lead decides on full pauseRestrict within 2h, pause decision within 8hCRO, GC, business owner
High-tier deploy without signed assessmentAI Governance Lead (blocks)Before deploymentBusiness owner, CRO
Vendor material model changeVendor risk manager triages; AI Governance Lead decides on re-test or pauseWithin 5 business daysBusiness owner, Security
New regulatory obligationGeneral CounselAssessment within 10 business daysAI Governance Committee
Pause request for a live systemCRO or AI Governance Lead, either can invokeImmediateCEO staff, GC, business owner, Comms
Sev-1 AI incidentIncident Commander per IR plan; committee convenesImmediate; committee within 3 business daysFull committee, Audit Committee chair

Acceptance criteria

  • At least two named roles can invoke a pause, so a single person's absence cannot block it.
  • Every condition has a decision owner who has agreed to hold that authority.
  • Timelines are concrete (hours or business days), not "promptly".
  • The table is stored where an on-call responder can find it at 2am, not only in the charter binder.

4. Governance structure one-pager

Document

The board-facing summary. Structure, authority, and how it connects to existing risk governance, on one page with no jargon.

Template

One page for a board or executive pack.

  • The model in one line: <Legal-led / Risk-led / dedicated function>, chaired by <role>
  • Why this model: <two sentences tied to your regulatory and AI exposure>
  • What the body decides: <three to five bullets>
  • What it escalates to the board: <two to three bullets>
  • How it connects to existing governance: <one line each for Risk, Audit, Security>
  • Resourcing: <headcount and budget, or the ask>
  • First 90 days: <three deliverables with dates>

Worked example

  • The model in one line: Risk-led. The AI Governance Committee sits under enterprise risk and is chaired by the CRO.
  • Why this model: Our AI exposure is concentrated in regulated decisions (hiring, credit) where the primary risk is legal and regulatory. Housing it in Risk plugs it into existing board risk reporting rather than building a parallel track.
  • What the body decides: High-tier deployment approvals; the AI policy set; pause decisions; the quarterly board risk picture.
  • What it escalates to the board: Any Sev-1 AI incident; risk that exceeds stated appetite; material new regulatory obligations.
  • How it connects: Feeds the enterprise risk register; reports quarterly to the Audit Committee; draws on the existing incident process for AI incidents.
  • Resourcing: One dedicated AI Governance Lead plus 0.2 FTE each from Legal, Security, and Data. Committee time is existing.
  • First 90 days: Charter and RACI approved (month 1). Inventory complete with tiers (month 2). First quarterly board report delivered (month 3).

Acceptance criteria

  • It fits on one page and a non-specialist director can follow it.
  • It states plainly how AI governance connects to the board's existing risk oversight, not as a standalone silo.
  • The resourcing line is a real number or a specific ask, not "to be determined".

Governance controls this kit produces evidence for

Completing the artifacts above gives you a head start on the evidence requirements for these controls.

BRD-002
BRD-002

The charter is the committee charter and decision-rights document, approved and minuted.

BRD-010
BRD-010

The charter's membership, quorum, and cadence sections plus the review date evidence the committee operating cadence and membership lifecycle.

HOC-006
HOC-006

The escalation and pause-authority table is the documented override and escalation procedure.

MGV-003
MGV-003

The one-pager's first-90-days section seeds the governance program milestone framework.

BRD-011
BRD-011

The RACI's training row assigns accountability for the AI governance training program.

This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.

Decide what to implement next

Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.

Start the AI governance assessment →