Purpose
Establish organizational AI policy, clear ownership/RACI, risk-acceptance authority, and continual improvement so technical pillars have accountable stewards.
Engineering philosophy
Technical controls without organizational governance drift. A production-ready AI program names owners, accepts residual risk explicitly, and improves from incidents and audits.
Why it matters
Enterprises fail AI readiness when no one owns a pillar, exceptions are informal, and leadership cannot see residual risk.
Common failures
- AI features ship with no named owner for safety or eval gates
- Exceptions granted in chat with no expiry
- No AI policy covering acceptable use and prohibited applications
- Compliance theater without leadership review of risk
Mandatory checks
Gate controls. Each check is pass/fail via artifact + pass condition. Expected from the annotated capability level when the system meets the minimum criticality tier.
Documented AI policy covering acceptable use and prohibited applications shall exist
- Artifact
- Approved AI acceptable-use / prohibited-applications policy
- Pass condition
- Policy has version, owner, and review date ≤ 12 months; includes both acceptable-use and prohibited-application sections
Each production AI system shall have named owners for critical APRF domains
- Artifact
- System inventory with owner fields for critical domains
- Pass condition
- 0 production systems missing required domain owners in inventory query
Risk acceptance for known control gaps shall be recorded with owner and expiry
- Artifact
- Risk-acceptance register samples
- Pass condition
- 100% of open control-gap waivers have owner + expiry date; 0 expired waivers without escalation record
Internal audit or independent assessment shall sample APRF evidence on a defined cadence
- Artifact
- Independent assessment or internal-audit sampling report against APRF evidence
- Pass condition
- PASS if the last sampling report is ≤12 months old and lists sampled check IDs and findings
Recommended checks
Strengthen posture beyond the gate. Same measurable structure; non-blocking unless elevated by organizational policy.
Periodic leadership review of AI risk posture and APRF maturity
- Artifact
- Leadership AI risk / APRF maturity review minutes (or board pack excerpt) + action log
- Pass condition
- Leadership reviewed AI risk posture and APRF capability attained ≤90 days ago; open actions have owners and due dates
Continual improvement backlog fed by incidents and eval failures
- Artifact
- Improvement backlog (tickets) linked from incidents and eval failures + sample of closed items last quarter
- Pass condition
- ≥80% of Sev-1/2 AI incidents and critical eval fails in the last quarter produced a backlog item; ≥50% of those items closed or have a dated plan
Evidence required
- AI policy document
- Ownership/RACI for production AI systems
- Risk-acceptance register samples
Severity & risk
- Severity
- high
- Impact if violated
- Risk level
- medium
- Typical residual risk (impact × likelihood)
Engineering best practices
- Map APRF domains to teams; avoid orphan pillars
- Time-box exceptions; auto-escalate expired waivers
- Tie promotions and funding to measurable maturity for high-criticality systems
Automatic validations
- Inventory systems missing owners
- Alerts on expired risk acceptances
Manual validations
- Annual policy review
- Leadership tabletop on AI risk acceptance
Examples
- A risk register entry accepts a missing multi-provider fallback until Q3 with CTO sign-off
- Each agent product lists owners for Security, Safety, Evaluation, and Reliability
References
Crosswalks
GOVERN Govern
NIST AI Risk Management Framework · supports
Accountable Accountable and Transparent
NIST AI Risk Management Framework · supports
§4 Context of the organization
ISO/IEC 42001 · aligns-with
§5 Leadership
ISO/IEC 42001 · supports
§6 Planning
ISO/IEC 42001 · partial
§10 Improvement
ISO/IEC 42001 · aligns-with
CC1 Control Environment
SOC 2 Trust Services Criteria · evidence-for
CC3 Risk Assessment
SOC 2 Trust Services Criteria · evidence-for
Operational Excellence Operational Excellence
AWS Well-Architected Framework · aligns-with
Future evolution
Machine-readable organizational control catalogs mapped to APRF domains and ISO 42001 clauses.