Start with the AI estate
Governance cannot operate on AI systems the institution does not know about. Establish one inventory across models, agents, applications, embedded SaaS AI and suppliers.
Define materiality and decision rights
Decide which AI activities require institutional intake, risk review, legal/compliance input, executive approval or independent assurance.
Translate policy into workflow
Turn policy statements into conditions, required evidence, accountable authorities, review queues and exceptions with expiry.
Preserve the decision record
Capture what was proposed, what evidence existed, who decided, which conditions applied and what changed later.
Extend governance into runtime
Monitor operating systems for material changes, incidents, policy breaches, human-review requirements and evidence gaps.
Report decisions, not dashboard volume
Give executives a view of material AI exposure, value, exceptions and decisions requiring action rather than a catalogue of metrics.