AI Governance
Every rule your organization will ever make about AI has to trace back to a person with the authority to make it stick. That is what governance is. Five gated levels, from the decisions only leadership can make to the annual loop that keeps them honest.
AI Governance is a complete engagement on its own, and it is already built into our AI Business Transformation methodology. Built on ISO/IEC 42001, ISO/IEC 42005, the EU AI Act, and the NIST AI RMF.
The business decides.
IT enforces.
Most AI governance programs fail the same way. The people who build the controls end up deciding what the controls should be, because nobody upstream ever decided. That is not governance; it is convenience wearing governance’s clothes, and it fails the first time it is tested.
This methodology keeps deciders and enforcers structurally separate. Leadership, the governance board and the domain owners decide. CIO-side teams build the enforcement exactly as the register declared. The gates are the only place the two halves meet, and what crosses is a signed decision, never an assumption.
AI is arriving on two tracks. Both are legitimate.
A governance program designed for only one track is blind to half of what the organization is doing, and the half it misses is usually the half growing the fastest.
The productivity wave
Assistants and personal AI tools on every desk, and small solutions people build for their own work. Multiplied across an organization, this is a healthy proliferation of AI everywhere work is done. It is not a failure of discipline; it is what successful adoption of a general-purpose technology looks like.
The transformational few
Deliberate programs that redesign core workflows around what AI makes possible. These are enterprise efforts demanding cross-functional coordination and executive attention, because they redefine how the business actually does its work.
Five gated levels. Each level's exit list is the next level's entry list.
No level begins until the prior level's exit criteria are signed. That is the whole difference between a governance program and a governance document.
Plaster Group's AI Governance Methodology · © 2026 Plaster Group · plastergroup.com
Select any level to open it.
Level 1 secures five decisions no one below the C-suite can make, taken in a deliberate order, each recorded in a short signed artifact. Authority that is merely assumed is borrowed, and borrowed authority fails the first time it is tested.
- Sponsorship. The CEO names one executive to lead AI governance, and that executive accepts in writing. One name, one page, is the difference between a decision and a debate.
- Risk appetite. The CEO and executive team, with the CFO at the table, write down how much risk the organization will carry and for what, in tolerance bands specific enough that an engineer can build to them. The board affirms.
- Hard lines. Leadership states what the organization will not do with AI, plus restricted uses requiring a named approver, with counsel's review on record. Leaders write more carefully when they know their sentences will become software.
- Board oversight intent. The board chair decides what directors review, how often, and through which committee, so oversight is designed on purpose rather than improvised after an incident.
- Operating structure. The CEO decides the shape of the governance board, its chair and its seats. Only the CEO can make this call, because every seat is carved from some executive's territory.
Five signed artifacts, each naming a person. Until they exist, nothing downstream can be decided, only discussed.
Level 2 charters the governance board and writes the organization's rulebook as a connected set of frameworks, so nothing downstream ever has to re-decide it. A governance board without chartered decision rights is just a recurring meeting.
- The chartered board. A standing cross-functional body with written decision rights, cadence, quorum, and the authority to grant exceptions, each with an owner and an expiry date. A small permanent team carries governance between meetings.
- Risk classification. Written criteria sort every AI system, present and future, into tiers of consequence: impact on people, reversibility, data sensitivity, regulatory class, and how much the system acts on its own.
- The permission table. Tiers become rows, autonomy becomes columns, and every combination is decided in advance as permitted, conditional with a named approver, or off the table.
- One thin policy. The Level 1 and Level 2 decisions fold into a single AI policy the board of directors formally ratifies, readable by a regulator, a customer, or a donor.
- Shadow AI, channeled. An amnesty the governance board formally stands behind, every boundary paired with a sanctioned alternative, and shadow use routed into the program's priorities as a map of real demand.
- Working registers. A regulatory register signed by counsel, a 30-minute impact assessment done before anything is built or bought, and a control list recording which safeguards run and why.
Policy ratified. Tiers calibrated against the real inventory. Every tier-and-autonomy combination decided before any system ships.
Level 3 carries the rules to the cheapest place governance will ever operate: the design table. A concern caught while a workflow is still on the whiteboard costs a conversation; caught at deployment it costs a rebuild; caught in production it costs an incident.
- The people who own the work make the calls. Domain owners classify every AI-enabled step as their teams design, applying the Level 2 frameworks as a constraint that shapes the design rather than a review that rejects it.
- Oversight in names and numbers. For every step, the design states who reviews, how much, with what authority, and where issues escalate. “A human will check it” is never enough.
- An honest workload check. Signed by the domain owner, because oversight that would bury a reviewer in 400 approvals a day is not oversight, it is rubber-stamping waiting to happen.
- Every step declares its data. Source systems, the quality required for its tier, how an output traces back to what went into it, and where its outputs land.
- Bought, not built. When there is no workflow to redesign, the tool is risk-classified at intake and then follows the same rules as everything else.
One Classification Register carrying every step with its tier, autonomy, oversight and data requirements, confirmed buildable by the CIO in writing. That signature is what turns a handoff into a contract.
Level 4 is where IT puts up the guardrails and the rules become protections that work automatically. Everything decided upstream is built into the systems themselves, so compliance stops depending on memory.
- Every actor gets an identity, including the AI. People and agents alike operate under their own credentials, scoped to the task and expiring when it ends, with every agent bound to a named human owner. Revoking an identity is the kill switch, designed and tested before it is needed.
- Guardrails and release gates. Actions beyond a system's permitted autonomy are refused at the moment they are attempted, and nothing unclassified reaches production. The hard lines leadership wrote at Level 1 are enforced here, word for word.
- Every decision leaves a trail. Audit trails record what happened with the acting identity attached, so any decision can be reconstructed in minutes, for an auditor, a regulator, or your own peace of mind.
- Bought AI walks through the same door. Vendor systems enter through the same classification checkpoint, with contract terms securing audit rights and incident notification, and a monitoring rhythm that catches AI features vendors add in updates.
- Rehearsed, not improvised. Incident runbooks are exercised before go-live, so the first real event is not the first run-through.
Nothing unclassified can reach production. Breaking the rules stops being a risk to manage, because the systems prevent it by design.
Level 5 is the cadenced operating loop that keeps the whole arrangement honest, and it is deliberately permanent. Controls drift toward ceremony, and regulation moves while paperwork stands still.
- A quarterly audit that tests behavior, not binders. Four questions, evidence required for each: what work changed, what got caught, what got fixed, and which forum decided something that mattered.
- A standing watch. A named owner tracks regulation and standards monthly and routes every change into the registers that govern daily work.
- Revalidation on evidence. Deployed systems are re-tested when a drift alert, a material change or a new use calls for it, with a yearly backstop so no system goes unexamined.
- An annual re-signature. The board of directors re-ratifies the policy against the year's actual record, in a one-page summary of what changed and what the evidence taught.
- The uncomfortable question, asked out loud. The measures themselves are audited, including which metrics the organization has started gaming.
- The loop compounds. Temporary fixes age visibly on a register until retired, and what worked is codified into reusable patterns, so the second domain's governance costs a fraction of the first.
Each cycle's evidence re-authorizes the next one. Every level of this program passes through a gate, including the level that never ends.
Every combination decided before anything ships.
Classification writes the rows. The autonomy standard writes the columns. The permission table binds them, and one board-ratified policy makes the whole page something the organization answers for.
| Risk tier ↓ / Autonomy → | Advise only | Act with approval | Act with oversight | Act within bounds |
|---|---|---|---|---|
| Low | ✓ permitted | ✓ permitted | ✓ permitted | ✓ permitted |
| Moderate | ✓ permitted | ✓ permitted | ✓ permitted | named approver |
| High | ✓ permitted | ✓ permitted | named approver | × forbidden |
| Critical | ✓ permitted | named approver | × forbidden | × forbidden |
Illustrative pattern. Every client's table is calibrated to its own risk appetite, written at Level 1.
The frameworks auditors and regulators already work from.
The international standard for the management of AI, and the one an organization can actually be certified against. Its clauses are what an auditor tests.
Its companion standard for assessing how AI systems affect people. Named by almost no one else in this market, and the backbone of a defensible impact assessment.
Law, with obligations phasing in through 2028. Build governance now and the dates arrive as a matter of course rather than as a scramble.
The US risk-management framework, including its Generative AI Profile. Voluntary, widely adopted, and the vocabulary most American regulators reach for.
These are the frameworks a board can name when asked what its AI governance is based on. They prescribe accountabilities in detail and are unanimously silent on titles, org charts and reporting lines, which means every organization has to invent its own people layer. That invention is the work.
Which gate have you not passed?
The methodology is gated, so the first “no” is where your program actually is, regardless of how much has been built downstream. Most organizations are already deploying AI by the time they get here, and the program is built for that entry rather than a restart: where upstream decisions are missing, it builds a Minimum Viable Decision Layer, the smallest set of decisions the guardrails cannot run without, sanctioned in writing by an executive with the authority to own them and carrying a sunset date. Nothing is emailed to you and nothing is stored.
Answer all five to see your result.
Done well, this arrangement pays every stakeholder it touches.
AI investment that actually lands as value, because the discipline that governs AI is the same discipline the research links to achieving high value from it. Incidents that never happen never reach the income statement.
Oversight it can honestly attest: a policy it ratified, reporting it understands, and an annual re-signature grounded in real evidence.
Decisions that stick. Clear ownership, faster approvals, and the freedom to move quickly precisely because the boundaries are known and enforced.
Rules that arrive explained rather than announced, the safety to be open about the tools they already use, and legitimacy for the solutions they build to do their own work better.
An organization adopting AI boldly, and worthy of their trust while doing so.
Adopt boldly. Rest easy.
Enterprise experience. AI-native delivery. Real outcomes.
Start a Conversation