Enterprise AI insight
What AI governance needs before production
A delivery-oriented checklist for ownership, controls, evidence and escalation before an AI capability goes live.
Governance is how decisions get made
AI governance should tell a delivery team who can approve a use, what evidence is required, which limits apply and what happens when performance changes. A policy without an operating path leaves the difficult decisions inside the project.
Named accountability
Identify a business owner for the outcome, a technical owner for the system, and the people accountable for risk, privacy, security and affected users. Clarify who accepts residual risk and who can pause or withdraw the capability.
A documented purpose and boundary
Write down the intended users, allowed decisions, prohibited uses and operating context. Specify where human review is required. This boundary becomes the reference point for design, testing, monitoring and change control.
Evidence appropriate to impact
Define acceptance measures before testing. Evidence may include task performance, error analysis, subgroup analysis where relevant and lawful, adversarial testing, human-factors testing, security review and operational rehearsal. Higher-impact uses require stronger evidence and oversight.
Data and model traceability
Maintain enough information to understand the data sources, model or service version, prompts and system components involved in a release. Record material limitations and the conditions under which testing was performed.
Operational controls
Plan monitoring, incident reporting, user feedback, access control, supplier change, fallback behaviour and retirement. Agree thresholds that trigger investigation, restriction or rollback. Governance continues after approval.
A proportionate path
Not every AI use needs the same process. A lightweight internal assistant and a capability influencing a consequential customer decision should not pass through identical gates. Classify by impact and uncertainty, then scale evidence and approval accordingly.
The production readiness question
Before release, ask: can the organisation explain what this capability does, who owns it, what evidence supports it, how it is supervised and how it can be stopped? If any answer is unclear, that is the next governance task.