From principles to machinery

Lesson 1 of 5 in Designing the AI Governance Operating Model.

By 2019, researchers had counted more than eighty published sets of AI ethics principles — corporate, governmental, academic — and found them converging on the same five ideas: transparency, fairness, non-maleficence, responsibility, privacy. The Dutch tax administration subscribed to every one of them. It still ran a risk-scoring system that flagged thousands of families for fraud partly on nationality, ignored frontline warnings for years, and brought down a government.

That is the policy-to-practice gap, and it is the problem this module exists to solve. Principles do not review use cases, challenge model owners, or notice that a system drifted. People in defined roles, following defined procedures, with defined authority do — and the design of those roles, procedures, and authorities is what practitioners call the AI governance operating model. A principle without machinery is a press release.

Key terms: operating model, governance program, maturity model, accountability, governance theater

Suppose you are hired to build the program from nothing. The sequencing matters, because each step produces the input the next one needs — and organisations that skip ahead (usually straight to writing a policy) produce documents that govern an AI estate nobody has actually looked at.

The sequence that works: mandate → inventory → policy → risk tiering → controls → assurance. First, secure a written mandate from executive leadership — without decision rights and budget, everything downstream is advisory theatre. Second, inventory what already exists (the next module is entirely about this). Only then write policy, because now you know what you are regulating. Tier the inventory by risk so effort lands where harm concentrates. Attach controls proportionate to each tier. Finally, add assurance — independent checking that the controls actually operate.

Building the program: the sequence that works

  1. Executive mandate

    A written charter from the board or executive committee: scope, decision rights, budget, reporting line. Without it, governance is a suggestion.

  2. Inventory the AI estate

    Discover every AI system in use — built, bought, and embedded in SaaS. You cannot govern what you cannot see.

  3. Write policy against reality

    An enterprise AI policy plus acceptable-use policy, informed by what the inventory actually found — not by what leadership imagined was in use.

  4. Tier by risk

    Classify every inventoried system and every new use case into 3–5 risk tiers so scrutiny is proportionate.

  5. Attach controls per tier

    Assessments, documentation, testing, oversight, and monitoring requirements that scale with the tier.

  6. Assure it works

    Second-line challenge and third-line audit verify controls operate in practice, not just on paper.

  7. Iterate: metrics feed the mandate

    Coverage and effectiveness metrics go back to the board, which refreshes the mandate, budget, and priorities.

Programs also mature in a predictable arc, borrowed from capability-maturity models used in software and risk management for decades. Knowing where you sit stops two opposite mistakes: demanding optimized-level metrics from an ad-hoc program (it will fake them), and letting a mature organisation coast on repeatable-level paperwork. Assess honestly — the staircase below includes the self-test question for each step.

Level 1 — Ad hoc: heroics and luck

Governance happens when a motivated individual notices a problem. No inventory, no defined roles, outcomes depend on who happens to be in the room. Self-test: if your most safety-conscious engineer resigned tomorrow, would any AI review still happen? If no — you are here.

Level 2 — Repeatable: a process exists somewhere

An intake form, a review checklist, maybe a committee — but coverage is partial and enforcement inconsistent. Teams that opt in are governed; teams that do not are invisible. Self-test: can you name the AI systems that have never been through your process? If you cannot even enumerate them, you are at level 2 at best.

Level 3 — Defined: written, resourced, mandatory

Policy, tiering scheme, RACI, committee charter, and training all exist and apply enterprise-wide. This is the level most regulatory frameworks implicitly assume. Self-test: does a new hire in any business unit learn, in onboarding, what they must do before deploying AI?

Level 4 — Managed: measured and enforced

Coverage and effectiveness are quantified: % of AI systems inventoried, assessment cycle times, overdue-action counts, incident rates. Deviations trigger consequences. Self-test: can the CRO tell the board, with evidence, what fraction of the AI estate is assessed and monitored — and is anyone’s bonus affected when the number slips?

Level 5 — Optimized: the program improves itself

Post-incident reviews, near-miss registries, and metric trends feed changes to the controls themselves. Governance cost per use case falls while coverage rises. Self-test: name one control you changed in the last year because your own data showed it wasn’t working.

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.