AI Governance and Risk Management

AI Governance and Risk Management

This guide brings together my writing on enterprise AI governance: how organisations assign responsibility for AI risk, assess systems in their real deployment context, and turn standards and regulation into operating controls. It is written from a security architecture perspective for governance leads, security teams, engineering leaders, and executives.

Start with accountability

AI governance works when decision rights are explicit. A policy or committee cannot accept risk on behalf of a business owner. Start by naming who approves a use case, who owns its outcomes, and who can pause or retire it when the risk changes.

Assess the whole system

The model alone is rarely the whole risk. Data flows, hosting, model providers, human oversight, and the business process all matter. Map those boundaries before deciding which controls or regulatory roles apply.

A practical review checklist

For each AI use case, record its purpose and affected people; the accountable business owner; the data and model providers involved; the system’s risk classification and supporting evidence; human review and escalation paths; monitoring and change triggers; and who can suspend it. Revisit the assessment when the model, data, provider, or business purpose changes.

These articles are independent practitioner analysis, not legal advice. For regulatory decisions, consult the applicable primary text and qualified counsel.

Related guides: Cloud AI trust boundaries · Cryptography and TLS · About the author and editorial policy