Open reference architecture

AI Governance Architecture

A lifecycle for governing AI according to consequence and evidence rather than applying the same paperwork to every use case.

Inventory

Maintain an accountable inventory of material AI use cases, owners, providers/models, data categories and business purpose.

Risk classification

Classify use by consequence, autonomy, affected people, data sensitivity, reversibility and regulatory/contractual context.

Approval

Set proportionate approval gates before deployment and before material changes to models, data, tools or autonomy.

Evaluation

Define task-specific quality, safety, security, bias/fairness where relevant, privacy and reliability tests with acceptance thresholds.

Human oversight

Specify who can review, override, stop and investigate the system; human review must be meaningful rather than ceremonial.

Change control

Track provider/model/version, prompts/policies, retrieval sources, tools and material configuration changes.

Monitoring & incidents

Monitor material failures and policy breaches; preserve evidence, contain impact and feed lessons into controls/evaluation.

Retirement

Remove access, integrations, data copies and obsolete documentation when a use case ends; retain required audit evidence appropriately.