AI Governance Template
Use this template to help an organization establish a practical AI governance framework.
Governance Record
| Field | Value |
|---|---|
| Organization | [Organization Name] |
| Framework Name | [AI Governance Framework Name] |
| Version | 0.1 |
| Status | Draft |
| Executive Sponsor | [Name or Role] |
| Program Owner | [Department or Person] |
| Audience | Leadership, IT, legal, privacy, procurement, staff |
| Last Reviewed | [Month Year] |
Purpose
This framework establishes how the organization evaluates, approves, uses, monitors, and governs artificial intelligence tools and AI-enabled services.
Governance Principles
- Human accountability remains in place.
- AI outputs must be reviewed when they affect important decisions.
- Sensitive information must be protected.
- AI use should support transparency, fairness, accessibility, and public trust.
- Approved tools and use cases must be documented.
- Risks must be identified before deployment.
Governance Structure
| Role | Responsibility |
|---|---|
| Executive Sponsor | Provides strategic direction and executive accountability |
| AI Governance Lead | Coordinates policy, approvals, and ongoing review |
| IT / Security | Reviews technical security, access, and system integration |
| Legal / Privacy | Reviews legal, records, privacy, and regulatory concerns |
| Procurement | Reviews vendor requirements and contract protections |
| Department Owner | Defines business need, implementation plan, and local controls |
| Staff User | Uses approved tools responsibly and follows agency guidance |
Approved AI Use Cases
List the categories of AI use that are generally allowed.
- Drafting and editing routine communications
- Summarizing approved documents
- Creating training outlines
- Supporting internal knowledge search
- Drafting checklists and workflow guides
- Creating first drafts for human review
Restricted or Prohibited Uses
List activities that require elevated review or should not be used without formal authorization.
- Eligibility or benefits determinations
- Employment decisions
- Enforcement or disciplinary decisions
- Legal conclusions or legal advice
- Safety-critical recommendations
- Uploading confidential or protected information into unapproved tools
- Fully automated public decisions without meaningful human review
AI Use Case Approval Process
Step 1: Define the Business Need
Describe the problem, service, workflow, or outcome the proposed AI use case is intended to support.
Step 2: Assess Risk
Identify data, privacy, security, legal, operational, fairness, and public-trust considerations.
Step 3: Review the Tool or Vendor
Confirm that the proposed tool meets security, privacy, accessibility, data ownership, and procurement requirements.
Step 4: Approve or Modify the Use Case
Document whether the use case is approved, denied, approved with conditions, or returned for revision.
Step 5: Monitor and Review
Review performance, incidents, feedback, changes in vendor terms, and continued suitability over time.
Required Documentation
- AI use case description
- Responsible owner
- Risk assessment
- Data categories involved
- Approval decision
- Required safeguards
- Training requirements
- Vendor review record
- Review date
- Incident or escalation record, if applicable