Governance 1: Intro
AI Implementation Requires A Complex Structure of Governance and Risk Management
There is a lot of heat in the discussions of AI use in organizations. The word ‘transformation’ gets tossed around like a hand grenade. When you scratch the surface, much of the trouble stems from the fact that AI is both immature and implemented without an abiding regard for control and consequences.
Somehow, the fact that the board of directors is responsible for governance gets lost in the angst. It turns out that the effective use of AI requires a significant redesign of basic organizational controls. Board directors remain responsible for decisions even when AI participates in them.
You can’t really start to think about HR’s (or any other function’s) role until the basic governance issues are sorted. In the absence of a clear governance structure, the use of AI is not much more than a heap of unmanaged risk.
Over the next few posts, I am going to take a deep look at the components of organizational governance in an AI informed world. I was ‘prompted’ to do this by a (still ongoing) set of interactions with the team at aderit.ai. They have built a model of the elements of ongoing control needed to use and trust agents (or the orchestration of agents). Their work is defining the machine components of governance and control.
Governance can seem like an esoteric, dense, complicated topic with limited utility. Unlike AI with its blistering pace of exciting progress, governance is about steering the organization. The terrain is at least as dry as accounting and equally (maybe even more) important. Governance can seem overwhelming, detailed, complicated, and dense. Taken in its entirety, governance is an overwhelming set of requirements that can easily seem impossible to implement.
Accounting tells the board whether the enterprise’s financial story is trustworthy; AI governance should tell it whether delegated machine judgment is authorized, controlled, effective, and safe.
Throughout this discussion, I am going to use the metaphor of a diamond and its facets. Many organizational elements look different depending on the lens with which they are viewed. The diamond is a thing of beauty because of its facets, not despite them. The metaphor is a scalable view. It can be used to think about organization wide issues as well as the microcosms of data coherence and completeness.
How does an organization safely delegate consequential authority—to humans or machines—while retaining control and accountability for what happens?
For starters, governance is the system that addresses the following four questions:
Security, compliance, risk, accountability, data governance, organizational authority, and agent controls aren’t competing definitions of governance. They are different views of the same underlying problem (facets of the diamond).
For the board, there should be a standard evidence package that includes:
AI inventory and material-use summary
New and retired high-risk systems
Business value and performance indicators
Exceptions to policy
Incidents, complaints, overrides, and near misses
Testing and assurance findings
Regulatory exposure
Third-party concentration risk
Remediation owners and deadlines
Morale, productivity, and sentiment analysis
Key references:
NIST AI Risk Management Framework: https://www.nist.gov/itl/ai-risk-management-framework. The most authoritative general-purpose operating framework. Its model—Govern, Map, Measure, Manage—covers organizational accountability, AI inventories, risk tolerance, lifecycle controls, monitoring, documentation, and executive responsibility.
ISO/IEC 42001: https://www.nacdonline.org/all-governance/governance-resources/governance-research/director-faqs-and-essentials/implementing-ai-governance/. The most comprehensive auditable management-system standard. It tells an organization how to establish, operate, review, and continuously improve AI governance.
NACD Director Essentials: Implementing AI Governance: https://www.nacdonline.org/all-governance/governance-resources/governance-research/director-faqs-and-essentials/implementing-ai-governance/ . Probably the clearest US voice on directors’ fiduciary and oversight responsibilities. Its current guidance covers the board’s agenda, expertise, committee structure, management reporting, and deployment decisions
Photo by Charles Forerunner on Unsplash




