Skip to main content

AI governance control atlas

AI Governance, Ethics & Explainability: from risk to evidence

A control map for moving from shadow AI discovery to risk-tiered, explainable, and security-aware AI operations.

AI risk grows faster than policy when organizations cannot inventory use cases, data dependencies, or decision impact.

Responsible AIAI use-case inventoryExplainabilityApplication security

AI-01 · Control 1

AI inventory

Every material model, agent, and Copilot-style tool has an owner and purpose.

Accountable owner
AI governance or product risk lead
Review cadence
Review at least annually and after a material change.

Maturity path

  • Foundational: Establish ownership, a documented workflow, and initial evidence for ai inventory.
  • Developing: Run ai inventory consistently with review cadence, metrics, and exception handling.
  • Advanced: Continuously improve ai inventory through automation, testing, and executive reporting.

Test method: Review current evidence with the accountable owner and record exceptions.

Evidence to look for

  • AI system register
  • Use-case owner record
  • Data dependency map

AI-02 · Control 2

Risk tiering

Review effort matches impact instead of treating every experiment equally.

Accountable owner
AI governance lead with system owner
Review cadence
Review at least annually and after a material change.

Maturity path

  • Foundational: Establish ownership, a documented workflow, and initial evidence for risk tiering.
  • Developing: Run risk tiering consistently with review cadence, metrics, and exception handling.
  • Advanced: Continuously improve risk tiering through automation, testing, and executive reporting.

Test method: Review current evidence with the accountable owner and record exceptions.

Evidence to look for

  • Risk classification
  • Impact assessment
  • Approval and exception log

AI-03 · Control 3

Dependencies and vendors

Data, models, providers, subprocessors, and access paths are visible before they become hidden risk.

Accountable owner
AI system owner with procurement and security
Review cadence
Review at least annually and after a material change.

Maturity path

  • Foundational: Establish ownership, a documented workflow, and initial evidence for dependencies and vendors.
  • Developing: Run dependencies and vendors consistently with review cadence, metrics, and exception handling.
  • Advanced: Continuously improve dependencies and vendors through automation, testing, and executive reporting.

Test method: Review current evidence with the accountable owner and record exceptions.

Evidence to look for

  • Model and vendor inventory
  • Data dependency map
  • Subprocessor and transfer review

AI-04 · Control 4

Usage controls

People know which tools and data uses are permitted, restricted, or prohibited.

Accountable owner
Security, legal, or responsible AI lead
Review cadence
Review at least annually and after a material change.

Maturity path

  • Foundational: Establish ownership, a documented workflow, and initial evidence for usage controls.
  • Developing: Run usage controls consistently with review cadence, metrics, and exception handling.
  • Advanced: Continuously improve usage controls through automation, testing, and executive reporting.

Test method: Review current evidence with the accountable owner and record exceptions.

Evidence to look for

  • Acceptable-use policy
  • Approved-tool register
  • Training and acknowledgement

AI-05 · Control 5

Human oversight

People with appropriate authority can review, challenge, and stop consequential AI-assisted decisions.

Accountable owner
Business owner with privacy or risk lead
Review cadence
Review at least annually and after a material change.

Maturity path

  • Foundational: Establish ownership, a documented workflow, and initial evidence for human oversight.
  • Developing: Run human oversight consistently with review cadence, metrics, and exception handling.
  • Advanced: Continuously improve human oversight through automation, testing, and executive reporting.

Test method: Review current evidence with the accountable owner and record exceptions.

Evidence to look for

  • Human review procedure
  • Decision and override record
  • Escalation path

AI-06 · Control 6

Evaluation and monitoring

AI systems are tested for quality, safety, bias, privacy, and performance before and after release.

Accountable owner
Technical system owner
Review cadence
Review at least annually and after a material change.

Maturity path

  • Foundational: Establish ownership, a documented workflow, and initial evidence for evaluation and monitoring.
  • Developing: Run evaluation and monitoring consistently with review cadence, metrics, and exception handling.
  • Advanced: Continuously improve evaluation and monitoring through automation, testing, and executive reporting.

Test method: Review current evidence with the accountable owner and record exceptions.

Evidence to look for

  • Evaluation plan and results
  • Monitoring dashboard
  • Release acceptance record

AI-07 · Control 7

Runtime assurance

High-risk systems are monitored after launch, not only approved once.

Accountable owner
System owner with security lead
Review cadence
Review at least annually and after a material change.

Maturity path

  • Foundational: Establish ownership, a documented workflow, and initial evidence for runtime assurance.
  • Developing: Run runtime assurance consistently with review cadence, metrics, and exception handling.
  • Advanced: Continuously improve runtime assurance through automation, testing, and executive reporting.

Test method: Review current evidence with the accountable owner and record exceptions.

Evidence to look for

  • Human oversight record
  • Access and usage logs
  • Periodic control review

AI-08 · Control 8

Incident and drift response

The organization can detect, contain, investigate, and learn from unsafe output or material system change.

Accountable owner
AI system owner with incident lead
Review cadence
Review at least annually and after a material change.

Maturity path

  • Foundational: Establish ownership, a documented workflow, and initial evidence for incident and drift response.
  • Developing: Run incident and drift response consistently with review cadence, metrics, and exception handling.
  • Advanced: Continuously improve incident and drift response through automation, testing, and executive reporting.

Test method: Review current evidence with the accountable owner and record exceptions.

Evidence to look for

  • AI incident playbook
  • Drift or change log
  • Rollback and corrective-action record

Questions to ask internally

  • Do you know where AI is used?
  • Which systems affect people or eligibility?
  • Can you trace data, models, vendors, and subprocessors?
  • Can staff distinguish approved from unapproved tools?
  • Who can challenge or stop a consequential output?
  • What evidence proves testing and monitoring after launch?
  • How would you respond to harmful output or model drift?