AI Governance
Govern AI by use case, risk, data and autonomy—not by model name alone.
AI governance should cover internal AI use, client AI delivery and third-party AI vendors.
01Governance structure
- Executive Owner
- To be confirmed
- Risk Owner
- To be confirmed
- Technical Owner
- To be confirmed
- Review Forum
- To be confirmed
02AI system inventory
- Fields
- Use case
- Owner
- Model/provider
- Data categories
- Users
- Tools/actions
- Risk tier
- Evaluation status
- Production status
- Review date
03Review triggers
- New AI vendor
- New production AI use case
- Sensitive/personal data use
- AI agent with external actions
- High-impact decision support
- Material model/provider change
- Security/privacy incident
- Significant evaluation regression
04Governance controls
- Use-case approval
- Vendor due diligence
- Data-access review
- AI threat model
- Evaluation
- Human oversight
- Tool/action permissions
- Logging/auditability
- Cost monitoring
- Incident response
- Periodic review
05Standards and frameworks
Recognized AI risk-management standards can be considered where appropriate. Do not claim ISO/IEC 42001 certification unless formally certified and scope is verified.
This document is a draft framework provided for review. It is not legal advice, and it must be confirmed against actual Fuchsius operations and applicable law before publication.