AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

How to run AI governance at scale

A practical guide for compliance officers, general counsel, GRC teams, and risk managers navigating the operational realities of enterprise AI governance. Questions every compliance team needs to answer.

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →
Agentic AI×
1

How do we inventory and classify AI systems by risk level?

A framework for cataloging all AI tools in use, including shadow AI, and assessing risk based on data sensitivity, decision impact, and regulatory exposure.

2

Who owns AI governance within the organization?

Defining accountability for AI governance, whether in Legal, IT, Risk, or a dedicated AI ethics function, and establishing clear escalation paths.

3

How do we ensure third-party AI vendors meet our standards?

Extending vendor due diligence to cover model transparency, data handling, bias testing, and contractual liability for AI outputs.

6

What does meaningful human oversight look like for high-risk AI decisions?

Defining what "in the loop" means in practice, what level of review satisfies regulatory standards, and how to document it.

8

How should employees be trained on acceptable AI use?

Covering what tools are approved, what data can be input, and how to handle AI-assisted work product in regulated industries.

9

How do we maintain data privacy compliance when using AI?

Addressing training data sourcing, data minimization, cross-border transfers, and the right to explanation under GDPR and CCPA.

10

How do we document AI decision-making for auditability?

Meeting regulatory and litigation demands for explainability through logging, version control, and model cards.

11

How do we ensure human-in-the-loop review is actually effective?

Moving beyond checkbox approval to build oversight protocols that counter automation bias and give reviewers genuine authority to override AI decisions.

16

Do we have a complete AI inventory?

Building and maintaining a centralized registry of every AI tool in use, including shadow AI discovered through procurement, network, and employee channels.

18

What is our process for model drift monitoring?

Defining ownership and cadence for ongoing monitoring of deployed AI models to detect performance degradation, behavioral shifts, and emerging bias after deployment.

20

Is our AI red-teaming rigorous enough?

Defining pass/fail criteria for adversarial testing of high-risk AI systems before deployment, covering toxicity, data leakage, jailbreaking, and misuse scenarios.

21

How do we govern AI agents that take autonomous actions?

Agentic AI systems that can browse the web, execute code, send messages, and interact with external services require governance controls that traditional policy frameworks were never designed to handle.

22

How do we apply a three lines of defense model to AI risk?

The three lines of defense model translates directly to AI governance, with first-line business ownership, second-line risk oversight, and third-line independent assurance each requiring AI-specific adaptations.

24

What does audit-ready AI documentation look like in practice?

Organizations facing regulatory scrutiny, board inquiries, or litigation need to produce evidence that AI systems were built, deployed, and monitored responsibly. Audit readiness is not a documentation exercise. It is an evidence-management discipline built into the AI lifecycle.

29

How do we build an AI governance program from scratch?

A sequenced guide to standing up an AI governance program — from initial inventory through ongoing operations — for organizations that are starting with nothing.

32

How do we manage third-party AI vendors safely throughout the vendor lifecycle?

End-to-end guidance for managing external AI vendor relationships from initial due diligence through ongoing monitoring, covering data handling, contractual protections, and what to do when vendors change their models.

33

What do we do when an AI system causes harm or fails?

A structured incident response process for AI failures — from initial detection through containment, root cause investigation, regulatory notification, and prevention.

35

How do we report AI risk to the board and audit committee?

A structured approach to surfacing material AI risk at the board level — defining what to report, how often, and what escalation thresholds trigger immediate notification outside the normal cycle.

36

How do we intake and govern open-weight and self-hosted AI models?

A governance framework for organizations that download, fine-tune, or self-host open-weight models — covering intake review, deployment controls, and ongoing maintenance obligations that differ from API-based vendor relationships.

38

How do we govern AI models from preview release through retirement?

A lifecycle governance framework covering every stage of an AI model's production life — from evaluating preview releases, through controlled promotion to general availability, to scheduled re-assessment triggers and formal retirement.

39

How do we monitor voluntary AI safety commitments and respond when they change?

A process for tracking the voluntary safety commitments and pledges made by AI vendors and foundation model providers — and for reassessing vendor relationships when those commitments are downgraded, abandoned, or fail to be honored.

40

How do we govern our AI supply chain and manage upstream model dependencies?

A governance framework for managing the risks introduced by upstream AI dependencies — foundation models, third-party datasets, AI-enabled development tools, and compute infrastructure — as components of the organization's AI supply chain.

42

How do we build and maintain a multi-framework AI risk register?

A practical approach to consolidating AI risks from multiple regulatory frameworks (EU AI Act, NIST AI RMF, GDPR, ISO 42001, sector-specific) into a single, actionable risk register — without duplicating effort or missing framework-specific requirements.

43

How do we engage regulators and standards bodies proactively on AI governance?

A framework for organizations that want to move beyond reactive compliance — engaging regulators through comment processes, standards participation, and direct dialogue to shape governance requirements and demonstrate good-faith leadership.

New guidance, every week

We publish practical guidance as governance questions come up in the field — plus everything else changing in AI regulation. Every Thursday.

Powered by Buttondown.