# AI Governance Charter Template and RACI Matrix

The documents that make AI governance ownership explicit: a charter, a RACI across the core activities, an escalation and pause-authority table, and a one-page structure summary for the board. The output is a signed structure with a named owner for every activity.

**Who this is for:** The general counsel, chief compliance officer, or chief risk officer asked to stand up AI governance and get it approved by the executive.

Source playbook: https://aigovernance.com/playbook/ai-governance-ownership

---

## AI governance charter

_The founding document. Fill each section. Keep it to two pages so people actually read it._

### Template

> Two pages. Approved by the executive sponsor and minuted.

- **Purpose:** why this body exists, in two sentences
- **Scope:** what counts as AI for this charter, what is in and out
- **Mandate and authority:** what the body can decide, approve, require, and halt
- **Membership:** roles (not names) with a chair and a quorum rule
- **Decision rights:** which decisions the body makes, which it advises on, which are delegated and to whom
- **Meeting cadence:** how often, and the trigger for an out-of-cycle meeting
- **Escalation:** what comes to this body, from where, and how fast
- **Reporting:** what goes up to the board or audit committee, and how often
- **Interfaces:** how this body works with Risk, Legal, Security, Data, and Product
- **Review:** the date this charter is next reviewed, and who owns that

### Worked example

- **Purpose:** The AI Governance Committee sets the standards for responsible AI use across the company and holds delegated authority to approve, condition, or halt AI deployments. It is the escalation point for AI risk that exceeds a business unit's tolerance.
- **Scope:** Any system that uses machine learning to generate content, predictions, classifications, or actions, whether built, fine-tuned, or bought. Excludes deterministic automation and basic analytics.
- **Mandate and authority:** Approve High-tier deployments; require assessments and controls; pause any AI system pending review; own the AI policy set.
- **Membership:** Chair is the Chief Risk Officer. Members: AI Governance Lead, General Counsel or delegate, Head of Security, Head of Data, and a rotating business owner. Quorum is the chair plus three, including Legal or Security.
- **Decision rights:** Makes the call on High-tier approvals and policy changes. Advises on Limited-tier. Minimal-tier is delegated to the business owner with a register entry.
- **Meeting cadence:** Monthly. Out-of-cycle within 3 business days on a Sev-1 AI incident or a pause request.
- **Escalation:** Business units escalate via the AI Governance Lead. Incidents come from the incident process.
- **Reporting:** Quarterly to the Audit Committee, using the board AI risk report.
- **Interfaces:** Risk owns the register; Legal owns regulatory interpretation; Security owns AI security testing; Data owns data governance; Product owns system-level implementation.
- **Review:** Next review 2027-03-01, owned by the AI Governance Lead.

### Acceptance criteria

- Every section is filled with a real decision, not left as a placeholder.
- The charter states what the body can halt and who can invoke a pause, with no ambiguity.
- It has been approved by an executive sponsor and the approval is minuted.
- It names a review date and an owner for the review.

---

## AI governance RACI

_Removes "everyone, so no one". One responsible role per activity. Use R, A, C, I, and keep exactly one A per row._

### Template

> Fill each cell with R, A, C, or I. Exactly one A per row. Rename the role columns to match your org.

| Activity | Board / Committee | Exec sponsor | AI governance lead | Legal | Risk | Security | Data | Business / product owner |
|---|---|---|---|---|---|---|---|---|
| AI system inventory | | | | | | | | |
| Risk classification | | | | | | | | |
| Vendor due diligence | | | | | | | | |
| Incident response | | | | | | | | |
| Regulatory monitoring | | | | | | | | |
| Training and awareness | | | | | | | | |
| Model approval to deploy | | | | | | | | |
| Board reporting | | | | | | | | |

### Worked example

| Activity | Board / Committee | Exec sponsor | AI governance lead | Legal | Risk | Security | Data | Business / product owner |
|---|---|---|---|---|---|---|---|---|
| AI system inventory | I | I | A | C | C | C | C | R |
| Risk classification | I | I | A | C | R | C | C | C |
| Vendor due diligence | I | I | C | C | A | C | C | R |
| Incident response | I | I | C | C | A | R | C | C |
| Regulatory monitoring | I | I | R | A | C | I | I | I |
| Training and awareness | I | A | R | C | C | C | C | C |
| Model approval to deploy | I | I | A | C | C | C | C | R |
| Board reporting | A | R | R | C | C | I | I | I |

**Why the non-obvious calls:** on risk classification the AI governance lead is Accountable for the method, Risk is Responsible for running it per system. On incident response Risk is Accountable for the outcome, Security is Responsible for containment. On regulatory monitoring the lead does the scanning, but Legal is Accountable for the interpretation that reaches the business.

### Acceptance criteria

- Exactly one role is Accountable for each activity.
- The Responsible role for each activity has confirmed they have the capacity and access to do it.
- The RACI is attached to the charter and reviewed on the same cycle.
- Role labels match real job titles in your organization, so there is no "who is that?" ambiguity.

---

## Escalation and pause-authority table

_Pre-decides who acts when something goes wrong, so nobody improvises it under pressure._

### Template

| Condition | Decision owner | Timeline | Who must be notified |
|---|---|---|---|
| Suspected harmful or biased output in production | <role> | <act within X hours> | <roles> |
| High-tier system wants to deploy without a signed assessment | <role> | <before deployment> | <roles> |
| Vendor announces a material model or safety change | <role> | <within X days> | <roles> |
| Regulatory deadline or new obligation identified | <role> | <within X days> | <roles> |
| Request to pause a live AI system | <role with pause authority> | <immediate> | <roles> |
| AI incident rated Sev-1 | <role> | <immediate, plus out-of-cycle committee> | <roles> |

### Worked example

| Condition | Decision owner | Timeline | Notify |
|---|---|---|---|
| Suspected harmful or biased output in production | On-call Security lead can restrict; AI Governance Lead decides on full pause | Restrict within 2h, pause decision within 8h | CRO, GC, business owner |
| High-tier deploy without signed assessment | AI Governance Lead (blocks) | Before deployment | Business owner, CRO |
| Vendor material model change | Vendor risk manager triages; AI Governance Lead decides on re-test or pause | Within 5 business days | Business owner, Security |
| New regulatory obligation | General Counsel | Assessment within 10 business days | AI Governance Committee |
| Pause request for a live system | CRO or AI Governance Lead, either can invoke | Immediate | CEO staff, GC, business owner, Comms |
| Sev-1 AI incident | Incident Commander per IR plan; committee convenes | Immediate; committee within 3 business days | Full committee, Audit Committee chair |

### Acceptance criteria

- At least two named roles can invoke a pause, so a single person's absence cannot block it.
- Every condition has a decision owner who has agreed to hold that authority.
- Timelines are concrete (hours or business days), not "promptly".
- The table is stored where an on-call responder can find it at 2am, not only in the charter binder.

---

## Governance structure one-pager

_The board-facing summary. Structure, authority, and how it connects to existing risk governance, on one page with no jargon._

### Template

> One page for a board or executive pack.

- **The model in one line:** <Legal-led / Risk-led / dedicated function>, chaired by <role>
- **Why this model:** <two sentences tied to your regulatory and AI exposure>
- **What the body decides:** <three to five bullets>
- **What it escalates to the board:** <two to three bullets>
- **How it connects to existing governance:** <one line each for Risk, Audit, Security>
- **Resourcing:** <headcount and budget, or the ask>
- **First 90 days:** <three deliverables with dates>

### Worked example

- **The model in one line:** Risk-led. The AI Governance Committee sits under enterprise risk and is chaired by the CRO.
- **Why this model:** Our AI exposure is concentrated in regulated decisions (hiring, credit) where the primary risk is legal and regulatory. Housing it in Risk plugs it into existing board risk reporting rather than building a parallel track.
- **What the body decides:** High-tier deployment approvals; the AI policy set; pause decisions; the quarterly board risk picture.
- **What it escalates to the board:** Any Sev-1 AI incident; risk that exceeds stated appetite; material new regulatory obligations.
- **How it connects:** Feeds the enterprise risk register; reports quarterly to the Audit Committee; draws on the existing incident process for AI incidents.
- **Resourcing:** One dedicated AI Governance Lead plus 0.2 FTE each from Legal, Security, and Data. Committee time is existing.
- **First 90 days:** Charter and RACI approved (month 1). Inventory complete with tiers (month 2). First quarterly board report delivered (month 3).

### Acceptance criteria

- It fits on one page and a non-specialist director can follow it.
- It states plainly how AI governance connects to the board's existing risk oversight, not as a standalone silo.
- The resourcing line is a real number or a specific ask, not "to be determined".

---

## Governance controls this kit produces evidence for

- **BRD-002**: The charter is the committee charter and decision-rights document, approved and minuted.
- **BRD-010**: The charter's membership, quorum, and cadence sections plus the review date evidence the committee operating cadence and membership lifecycle.
- **HOC-006**: The escalation and pause-authority table is the documented override and escalation procedure.
- **MGV-003**: The one-pager's first-90-days section seeds the governance program milestone framework.
- **BRD-011**: The RACI's training row assigns accountability for the AI governance training program.
