AI governance can seem intimidating at first, especially if you’re focusing on what you don’t know. According to 2023 Gartner research, for example, IT and data analytics leaders cited issues like skill gaps (57 percent), a lack of understanding about the effect that AI has on their business (38 percent) and stymied collaboration (22 percent) as key challenges that they faced while building out their governance framework.
A solid AI governance framework doesn’t just magically appear overnight. Instead, you need to build it, brick by brick, in a way that works for you.
“It doesn’t have to be a bottleneck,” says Renaud Baguena, group vice president, global head of risk management at Publicis Sapient. “You can make it very flexible, very fast. When companies fail is when you’re either underthinking or overthinking it. At the end of the day, governance just means appointing a set of people who are accountable for defining a strategy, making decisions and ensuring every activity is executed according to such decisions.”
The right kind of governance framework will address key elements that align AI systems with ethical guidelines and your organization’s goals.
And you don’t necessarily have to start from the ground up. “Building a governance framework doesn’t necessarily require you to invent things from zero,” says Todd Cherkasky, group vice president, customer experience and innovation consulting. “You’ve got lawyers in place that are looking at policies that are already anticipating some regulatory changes, for example, so you could do an assessment about where the gaps are. The goal is to supplement existing policies and frameworks and make them more durable.”
Organizational structure and roles
Want to get governance right? Start with identifying clear roles and responsibilities. This could mean appointing a CAIO or leveraging current leaders to take charge of AI oversight. Their job is to bring different departments and teams together to seamlessly put policies into practice.
“You should make sure your governance team is cross-functional,” Baguena explains. “You need data people. You need engineering people. You need lawyers. You need sales people. Make sure that all those people are in a room and empowered to have conversations, to have disagreements. And you should also have someone who is a kind of referee, who serves as the whistle in the game and makes decisions because it’s their job.”
He adds, “You need to empower the experts in their own domain to do the right research because they have 10 years of study in their domain. For example, an employment lawyer needs to tell you what the impact of AI is in employment regulation. Same for data privacy. Get the expertise where it is; you need experts to weigh in, then the company can make a decision.”
At the same time, governance isn’t in the hands of a select group of people. “Governance is everyone’s responsibility. It’s not just accomplished by having a team or working group set up with a name,” emphasizes Cherkasky. To ensure that everyone is aligned on governance, organizations should invest in “awareness, learning and development, empowering and resourcing.”
Global organizations have the added challenge of designing governance frameworks that need to be flexible enough to meet different regulations in different regions. They might establish localized AI governance roles to ensure compliance with regional variations in data protection laws and cultural expectations so that global strategies meet local needs.
Policies and procedures
Strong policies and procedures are the backbone of any AI governance framework. Governance committees craft these to set ethical boundaries and define what’s permissible for AI technologies within their organization. Legal teams, AI experts and ethical committees typically work hand-in-hand to develop these policies.
Procedures should lay out guidelines for ethical use data, timelines for regular audits and plans for continuous improvement. Compliance frameworks help organizations stay on track with both current and new legal requirements.
Risk management and monitoring
Effective AI governance thrives on robust risk management strategies. It’s not just about reacting to issues but also proactively identifying and mitigating potential problems. Regular audits and real-time monitoring can flag anomalies and assess performance.
"Make sure you know where your data is coming from and that you’re auditing your algorithms regularly,” says Venkatesh. “Get a third-party audit and document everything thoroughly." Leveraging advanced monitoring tools, businesses can track AI models in real time, identifying deviations from expected outcomes and facilitating rapid corrective measures.
Ready to de-risk your generative AI implementation? Check out our AI risk management playbook and learn how to overcome common challenges.