No complete inventory
Security, legal and business teams work from different lists of tools, vendors and use cases.
Use this framework to assign owners, sort AI use cases by risk, record approvals and give leaders one clear view of the AI portfolio.
One route from idea to approved use
Register the use case
OwnerAssign a risk tier
RiskApply the required checks
ControlsRecord the decision
EvidenceA working framework covers the full path from an employee idea to a live system. It says who can approve each decision, which checks apply, what evidence to keep and when leaders should stop or change an initiative.
The management problem
Separate teams buy tools, test models and automate work. Leaders then struggle to see what is live, who owns it and which risks remain open.
Security, legal and business teams work from different lists of tools, vendors and use cases.
A writing assistant and an automated credit decision should follow different review paths.
Teams cannot show which data, tests, people and conditions supported a release decision.
Spend, expected value, risk and ownership stay split across project updates.
The framework
Each part has a named owner and a record that another person can review. Start with the controls you need for live work, then add detail as the portfolio grows.
Who decides
Set the scope, decision rights and escalation route for the AI council and control functions.
What exists
Keep one register of use cases, tools, models, vendors, owners, data and current status.
What can go wrong
Place each use case on a review path based on data, impact, autonomy and exposure.
What to check
Match privacy, security, testing, human review and monitoring checks to each risk tier.
Why it was approved
Keep test results, approvals, known limits, owners and release conditions with the use case.
What happens next
Review value, cost, incidents, adoption and open decisions on a fixed cadence.
Control matrix
The exact tiers depend on the organisation. This example gives teams a clear starting point for routing work.
| Tier | Typical use | Minimum checks | Decision owner |
|---|---|---|---|
| 1 · Assist | Drafting, search and summarisation | Approved tool, data rule, user review | Business owner |
| 2 · Recommend | Scoring, forecasting and next-best action | Tier 1 plus test set, bias review and monitoring | Business and risk owners |
| 3 · Act | Automated actions that change a record or service | Tier 2 plus access limits, rollback and incident plan | Executive sponsor and control functions |
90-day rollout
A policy document alone will not change how teams work. Apply the first version to active use cases and improve it from the evidence those reviews produce.
Days 1–20
Days 21–40
Days 41–65
Days 66–90
Related decisions
These pages cover the owner, starting point and India-specific context around this guide.
Primary references
Questions leaders ask
An executive sponsor should own the mandate. Business, technology, security, privacy, legal, risk and audit teams keep their existing authority. A Chief AI Officer or another named leader can connect their decisions and maintain the portfolio record.
No. The review should match the data, impact, autonomy and exposure of the use case. Low-risk assistance can follow a short path. Systems that recommend or take material actions need stronger tests, approvals and monitoring.
Record the use case, business owner, users, model or tool, vendor, data used, decision impact, risk tier, current stage, approval status, expected value, cost and next review date.
Review active delivery and open decisions each month. Use a quarterly review for funding, policy changes, major risks and the next set of priorities. High-risk systems also need event-based reviews after an incident or material change.
Need an accountable owner?
Gyde can establish the first governance cycle, prepare executive decisions and leave the team with a system it can continue to run.