It answers who may approve AI use cases, which models and data are permitted, what testing and human oversight are required, how shadow AI is handled, and how incidents are escalated. Frameworks such as the NIST AI Risk Management Framework structure it as govern-map-measure-manage; laws such as the EU AI Act increasingly turn parts of it into legal duty.
Key points
Inventory and policy firstKnow which AI systems and features are in use — including embedded AI in vendors’ tools — and set acceptable-use rules before risk assessment begins.
Named system ownersEach deployed model needs a named owner for its risk, performance, data, and retirement — not diffuse committee accountability.
Important limitationGovernance is the scaffolding, not the protection. An approved-model list and a policy page do not secure a model; the value comes from the controls, testing, and monitoring the framework demands and from the enforcement behind it.