Build an AI inventory
Record AI systems acquired, developed or embedded in other products. Include owners, purpose, users, affected people, data, model or provider, integrations, deployment status and critical dependencies. Provide a route for teams to disclose experimentation and “shadow AI” without making discovery punitive.
Assign accountability
- Name a business owner for the outcome and a technical owner for operation.
- Define who approves deployment, material change, exception and retirement.
- Identify security, privacy, legal, procurement, data and domain reviewers.
- Set escalation criteria for high-impact or uncertain uses.
Classify risk proportionately
Consider impact on people, essential services, financial or administrative decisions, sensitive data, security, explainability, reversibility, autonomy and scale. Higher-risk uses need stronger testing, approval, monitoring and human oversight.
Control the lifecycle
- Define data provenance, quality, permission and retention expectations.
- Evaluate providers, model limitations, contractual controls and concentration risk.
- Test performance, security, misuse, bias and failure modes appropriate to the context.
- Design meaningful human review and an appeal or correction route where relevant.
- Monitor drift, incidents, complaints, overrides and changes after deployment.
Keep decision evidence
Retain the inventory record, risk assessment, approval, testing results, known limitations, user instructions, monitoring plan, incident history and retirement decision. Evidence should reflect what users can actually see and what the system actually does.
First 30-day plan
- Publish one intake route for existing and proposed AI use.
- Inventory the ten most consequential or widespread uses.
- Approve a simple risk-classification method and review threshold.
- Assess one high-priority use end to end.
- Report unresolved ownership, data, security and oversight decisions to leadership.