1. Home
  2. Resources
  3. Enterprise AI Governance Framework

An AI governance framework people can run.

Use this framework to assign owners, sort AI use cases by risk, record approvals and give leaders one clear view of the AI portfolio.

Named ownersRisk-based controlsRecorded decisions
Governance recordGyde
Enterprise AI governance

One route from idea to approved use

01

Register the use case

Owner
02

Assign a risk tier

Risk
03

Apply the required checks

Controls
04

Record the decision

Evidence
Review the live portfolio each monthExecutive view
AI governance
AI governance is the set of owners, rules, checks and records used to decide how an organisation builds, buys and uses AI.

A working framework covers the full path from an employee idea to a live system. It says who can approve each decision, which checks apply, what evidence to keep and when leaders should stop or change an initiative.

The management problem

AI work spreads faster than the decisions around it.

Separate teams buy tools, test models and automate work. Leaders then struggle to see what is live, who owns it and which risks remain open.

01

No complete inventory

Security, legal and business teams work from different lists of tools, vendors and use cases.

02

The same checks for every use case

A writing assistant and an automated credit decision should follow different review paths.

03

Approvals without evidence

Teams cannot show which data, tests, people and conditions supported a release decision.

04

Leadership sees projects, not a portfolio

Spend, expected value, risk and ownership stay split across project updates.

The framework

Six parts make the system usable.

Each part has a named owner and a record that another person can review. Start with the controls you need for live work, then add detail as the portfolio grows.

01

Who decides

Mandate

Set the scope, decision rights and escalation route for the AI council and control functions.

02

What exists

Inventory

Keep one register of use cases, tools, models, vendors, owners, data and current status.

03

What can go wrong

Risk tiers

Place each use case on a review path based on data, impact, autonomy and exposure.

04

What to check

Control library

Match privacy, security, testing, human review and monitoring checks to each risk tier.

05

Why it was approved

Evidence

Keep test results, approvals, known limits, owners and release conditions with the use case.

06

What happens next

Portfolio review

Review value, cost, incidents, adoption and open decisions on a fixed cadence.

Control matrix

Increase control as the possible harm rises.

The exact tiers depend on the organisation. This example gives teams a clear starting point for routing work.

TierTypical useMinimum checksDecision owner
1 · AssistDrafting, search and summarisationApproved tool, data rule, user reviewBusiness owner
2 · RecommendScoring, forecasting and next-best actionTier 1 plus test set, bias review and monitoringBusiness and risk owners
3 · ActAutomated actions that change a record or serviceTier 2 plus access limits, rollback and incident planExecutive sponsor and control functions

90-day rollout

Build the framework around live decisions.

A policy document alone will not change how teams work. Apply the first version to active use cases and improve it from the evidence those reviews produce.

01

Days 1–20

Map the current portfolio

List active use cases, tools, vendors, owners, data and open decisions. Choose an executive sponsor.
02

Days 21–40

Set tiers and decision rights

Agree the risk questions, approval paths and the authority held by business, technology and control teams.
03

Days 41–65

Review live use cases

Run representative use cases through the framework. Record gaps, delays and unclear ownership.
04

Days 66–90

Start the operating cadence

Publish the portfolio view, close urgent gaps and schedule monthly and quarterly reviews.

Questions leaders ask

Practical answers

Who should own AI governance?

An executive sponsor should own the mandate. Business, technology, security, privacy, legal, risk and audit teams keep their existing authority. A Chief AI Officer or another named leader can connect their decisions and maintain the portfolio record.

Does every AI use case need the same review?

No. The review should match the data, impact, autonomy and exposure of the use case. Low-risk assistance can follow a short path. Systems that recommend or take material actions need stronger tests, approvals and monitoring.

What should an AI inventory contain?

Record the use case, business owner, users, model or tool, vendor, data used, decision impact, risk tier, current stage, approval status, expected value, cost and next review date.

How often should leaders review the AI portfolio?

Review active delivery and open decisions each month. Use a quarterly review for funding, policy changes, major risks and the next set of priorities. High-risk systems also need event-based reviews after an incident or material change.

Need an accountable owner?

Put the framework to work on the live portfolio.

Gyde can establish the first governance cycle, prepare executive decisions and leave the team with a system it can continue to run.