Governance that remains executable
The core is not a thick policy document, but a workable operating model: who may use AI, who approves use cases, which controls apply and what evidence is retained.
- AI inventory and use case intake
- Risk classification and prioritisation
- Roles, ownership and escalation path
- Controls, training and evidence file