Governance starts with an inventory
Organisations first need to know which AI capabilities operate in which processes, which data they use, and who is accountable for production.
A central inventory connects business use, technical components, providers, risk classification, and approval status.
Controls must be technically effective
Policies alone do not prevent an unauthorised system action. Permissions, logging, quality tests, and approval steps must be implemented in the platform and the process.
- Role-based access to data and capabilities
- Versioned tests for relevant quality criteria
- Traceable approvals and changes
- Defined escalation and shutdown paths
Evidence is produced during daily operation
An auditable operation continuously collects model and prompt versions, test results, data sources, incidents, and accountable approvals. This reduces one-off effort before an audit.