Rules sit in separate teams
Privacy, cyber security, procurement, model risk and business teams may review the same use case without one shared record.
This guide helps Indian enterprises assign owners, review use cases and keep the evidence their leadership and control teams need.
Connect public guidance to company controls
Name the accountable executive
OwnerMap the rules that apply
ScopeReview live use cases
PracticeKeep evidence and decisions
RecordThe company still needs a working system of owners, risk tiers, controls and records. Legal, privacy, security, risk and sector teams decide which rules apply. This guide covers the management system around those decisions and does not replace legal advice.
The implementation gap
Public guidance sets a direction. Employees and delivery teams need plain rules for tools, data, approvals, testing, incidents and human review.
Privacy, cyber security, procurement, model risk and business teams may review the same use case without one shared record.
Employees can adopt public AI tools before a formal programme or vendor review begins.
A bank, manufacturer and healthcare company can face different review needs for similar technology.
Teams try to reconstruct data use, tests and approvals after a question or incident.
From guidance to practice
Use the Government of India guidance as a common base. Add the company’s legal, sector, security and risk requirements to each use-case review.
User information
Tell users what the system does, what it cannot do and when a person reviews the result.
Human authority
Set human authority for decisions that affect customers, employees or access to a service.
Safe testing
Use short tests and clear release conditions so controls grow with real evidence.
Outcome review
Check data, outcomes and complaint routes for groups that may receive different results.
Named owners
Name the business owner, system owner, approvers and incident owner before release.
Evidence
Keep the use case, risk tier, tests, limits, approvals and next review date together.
Responsibility map
The AI leader connects the work. Each control function keeps the authority already assigned to it by the organisation.
| Decision | Working owner | Required input | Final authority |
|---|---|---|---|
| Use-case priority | Business sponsor | Value, cost and delivery evidence | Executive portfolio forum |
| Data use | Data or product owner | Purpose, fields, access and retention | Privacy and legal teams |
| Security release | System owner | Architecture, access and test results | Information security |
| Customer or employee impact | Business process owner | Human review, fairness and complaint route | Business and control owners |
First 90 days
A current inventory will show where ownership, controls and evidence are missing. Use those cases to shape the first company standard.
Days 1–20
Days 21–40
Days 41–65
Days 66–90
Related decisions
These pages cover the owner, starting point and India-specific context around this guide.
Questions leaders ask
No. Public guidance gives organisations a common direction. Each company must map that guidance to the laws, sector requirements, contracts and internal standards that apply to its work. Legal and control teams should approve the final policy.
A cross-functional group should write it. Include business, technology, security, privacy, legal, risk, procurement and people teams. One executive should own the final mandate and resolve decisions that cross team boundaries.
Publish a short approved-tool and data rule first. Tell employees which tools they may use, which data must stay out, which work needs human review and where to request a new tool or use case.
No. It describes an operating model for ownership, review and evidence. The organisation’s legal, privacy, compliance and sector teams must interpret the requirements that apply and retain formal approval.
Set the first governance cycle
Gyde can map the current portfolio, define the first review paths and prepare the company team to run the system.