Governance first: audits, frameworks and vendor disclosures
AI moves fast when governance is in place first. Here’s how I’d establish it, audit it against real frameworks, and hold every vendor to written AI and data disclosures.
Governance comes first
Everyone wants to talk about what AI can do. The question that decides whether it works at a company is the one that comes before that: who owns it, who approves it, and what happens when something goes wrong. Governance isn’t a brake on AI adoption. It’s what lets a company move fast without losing track of what it’s running.
I studied this in Data and Technology Governance at ASU, and I see it every day running a portfolio of 70+ AI projects. Every project already has a portfolio owner and an executive stakeholder. That’s governance at the project level. The company needs the same thing for AI as a whole.
Establish it before you scale
- Own
Name an executive sponsor and a cross-functional council: legal, compliance, risk, IT and security, data and the business.
- Inventory
One list of every AI system, whether it was built, bought or is embedded in a vendor’s product.
- Tier
Classify each use by risk: what it can see, what it can do, and what a wrong answer would cost.
- Audit
Check regularly that what’s running still meets the frameworks the company has committed to.
- Manage vendors
Hold every third party to written AI and data disclosures, and keep checking them.
The order matters. You can’t audit what isn’t inventoried, and you can’t hold a vendor to rules you never wrote down.
Audits against real frameworks
A policy that’s approved once and filed isn’t governance. Audits are how you find out whether the system running today still matches the one that was approved. I’d anchor them to recognized frameworks, so the questions aren’t invented each time:
| Framework | What the audit checks |
|---|---|
| NIST AI Risk Management Framework | Its four functions: Govern (owners, policy, accountability), Map (context and impact), Measure (testing and monitoring) and Manage (response and treatment of risk). |
| NIST Generative AI Profile (AI 600-1) | Risks specific to generative AI, such as made-up answers, data leakage and harmful output, and the controls for each. |
| ISO/IEC 42001 | Whether the company runs a documented AI management system: roles, objectives, controls and continual improvement. |
| Confidentiality, integrity and availability | The data side: who can see it, whether it can be trusted, and whether it’s there when it’s needed. |
A good audit tests whether controls actually work, not just whether they exist. That includes checking that human review is real: a person clicking “approve” on output they didn’t have time to read isn’t oversight.
Vendor management runs through governance
Most of the AI a company uses, it doesn’t build. It arrives inside software it already pays for, and vendors add AI features all the time, sometimes without much notice. That’s why vendor management has to sit inside governance, not beside it.
Every contract with a third party should spell out its AI and data disclosures, and those disclosures have to reach past the vendor itself to the companies it relies on:
| Disclosure | What the contract should require |
|---|---|
| Where AI is used | Which features use AI, which models power them, and notice before new AI features are switched on. |
| Training on your data | Whether your data, prompts or outputs are ever used to train or improve their models, with a default of no. |
| Retention and deletion | How long prompts, outputs and logs are kept, and proof of deletion at the end of the contract. |
| Subprocessors | Every fourth party that touches your data, including the AI model providers behind the vendor, with notice of changes. |
| Model changes | Notice when the underlying model or provider changes, since a new model can behave differently. |
| Audit and exit rights | The right to review their controls, and a clean way out that returns your data. |
Signing the contract is the start, not the end. Vendors get reassessed when they ship a major release, change models or add subprocessors. When I run a structured pilot of a new AI platform, these are the questions that come before any feature demo.
Where to start
- Name the owners. Every AI system in use gets a business owner and a risk tier this quarter.
- Build the inventory. Include vendor-embedded AI and the tools employees adopted on their own. You can’t govern what you can’t see.
- Pick the framework. Use the NIST AI Risk Management Framework as the backbone, so audits ask the same questions every time.
- Review the top vendors. Start with the vendors that touch the most sensitive data, and check their contracts against the disclosures above.
- Schedule the audits. Put audits on the calendar, plus triggers for a re-review: a new model, new data or a new kind of decision.