AI Knowledge · Case study 01 · AI governance

Governance first: audits, frameworks and vendor disclosures

AI moves fast when governance is in place first. Here’s how I’d establish it, audit it against real frameworks, and hold every vendor to written AI and data disclosures.

Governance comes first

Everyone wants to talk about what AI can do. The question that decides whether it works at a company is the one that comes before that: who owns it, who approves it, and what happens when something goes wrong. Governance isn’t a brake on AI adoption. It’s what lets a company move fast without losing track of what it’s running.

I studied this in Data and Technology Governance at ASU, and I see it every day running a portfolio of 70+ AI projects. Every project already has a portfolio owner and an executive stakeholder. That’s governance at the project level. The company needs the same thing for AI as a whole.

Establish it before you scale

  1. Own

    Name an executive sponsor and a cross-functional council: legal, compliance, risk, IT and security, data and the business.

  2. Inventory

    One list of every AI system, whether it was built, bought or is embedded in a vendor’s product.

  3. Tier

    Classify each use by risk: what it can see, what it can do, and what a wrong answer would cost.

  4. Audit

    Check regularly that what’s running still meets the frameworks the company has committed to.

  5. Manage vendors

    Hold every third party to written AI and data disclosures, and keep checking them.

The order matters. You can’t audit what isn’t inventoried, and you can’t hold a vendor to rules you never wrote down.

Audits against real frameworks

A policy that’s approved once and filed isn’t governance. Audits are how you find out whether the system running today still matches the one that was approved. I’d anchor them to recognized frameworks, so the questions aren’t invented each time:

FrameworkWhat the audit checks
NIST AI Risk Management FrameworkIts four functions: Govern (owners, policy, accountability), Map (context and impact), Measure (testing and monitoring) and Manage (response and treatment of risk).
NIST Generative AI Profile (AI 600-1)Risks specific to generative AI, such as made-up answers, data leakage and harmful output, and the controls for each.
ISO/IEC 42001Whether the company runs a documented AI management system: roles, objectives, controls and continual improvement.
Confidentiality, integrity and availabilityThe data side: who can see it, whether it can be trusted, and whether it’s there when it’s needed.

A good audit tests whether controls actually work, not just whether they exist. That includes checking that human review is real: a person clicking “approve” on output they didn’t have time to read isn’t oversight.

Vendor management runs through governance

Most of the AI a company uses, it doesn’t build. It arrives inside software it already pays for, and vendors add AI features all the time, sometimes without much notice. That’s why vendor management has to sit inside governance, not beside it.

Every contract with a third party should spell out its AI and data disclosures, and those disclosures have to reach past the vendor itself to the companies it relies on:

DisclosureWhat the contract should require
Where AI is usedWhich features use AI, which models power them, and notice before new AI features are switched on.
Training on your dataWhether your data, prompts or outputs are ever used to train or improve their models, with a default of no.
Retention and deletionHow long prompts, outputs and logs are kept, and proof of deletion at the end of the contract.
SubprocessorsEvery fourth party that touches your data, including the AI model providers behind the vendor, with notice of changes.
Model changesNotice when the underlying model or provider changes, since a new model can behave differently.
Audit and exit rightsThe right to review their controls, and a clean way out that returns your data.

Signing the contract is the start, not the end. Vendors get reassessed when they ship a major release, change models or add subprocessors. When I run a structured pilot of a new AI platform, these are the questions that come before any feature demo.

Where to start

  • Name the owners. Every AI system in use gets a business owner and a risk tier this quarter.
  • Build the inventory. Include vendor-embedded AI and the tools employees adopted on their own. You can’t govern what you can’t see.
  • Pick the framework. Use the NIST AI Risk Management Framework as the backbone, so audits ask the same questions every time.
  • Review the top vendors. Start with the vendors that touch the most sensitive data, and check their contracts against the disclosures above.
  • Schedule the audits. Put audits on the calendar, plus triggers for a re-review: a new model, new data or a new kind of decision.
More case studies

Keep reading

Back to AI Knowledge