No shared inventory
Models, embedded provider features, experiments, and automated decisions are adopted without a current view of their purpose, data, owners, and status.
05 · AI capability
Create proportionate controls for AI use through clear ownership, risk classification, evaluation, transparency, oversight, and change management.
The context
Responsible AI governance should help teams make better decisions, not merely produce policy. Controls need to reflect how an AI capability is used, who may be affected, what can go wrong, and who has the authority and evidence to approve, monitor, pause, or change it.
Models, embedded provider features, experiments, and automated decisions are adopted without a current view of their purpose, data, owners, and status.
Low-impact assistance and consequential automated decisions follow the same process, creating either unnecessary friction or insufficient scrutiny.
Initial review exists, but model, data, prompts, providers, integrations, user behaviour, and operating context can change without a reassessment trigger.
Areas of attention
The appropriate techniques, controls, and delivery depth follow the use case. These areas keep the technical work connected to the people and decisions around it.
Record AI capabilities, intended uses, providers, data, affected people, lifecycle state, and accountable business and technical owners.
Classify use cases by consequence and context, then connect them to proportionate evidence, approval, access, oversight, and documentation.
Define quality, safety, fairness, robustness, disclosure, explanation, challenge, and record-keeping needs for the specific use.
Establish monitoring, incidents, user feedback, provider change, reassessment triggers, retirement, and evidence retention responsibilities.
Potential outputs
Outputs are shaped around the decision and engagement stage. Each should have a clear audience, purpose, owner, review criteria, and stated limitation.
Evaluation and responsibility
AI quality cannot be separated from its context of use. Representative inputs, subject expertise, realistic scenarios, and accountable owners are part of the engineering work.
Governance design and technical implementation do not replace legal, regulatory, privacy, security, employment, or sector-specific advice. Appropriate specialists should interpret applicable obligations.
Working path
The exact sequence depends on the use case and current evidence. Each stage should leave a reviewable result and an informed choice about the next step.
Identify AI uses, intended purposes, owners, providers, data, affected people, status, and existing controls.
Assess consequence, uncertainty, sensitivity, autonomy, scale, and relevant organisational or external requirements.
Define proportionate evaluation, documentation, approval, access, oversight, transparency, and escalation.
Monitor operation and establish incident, feedback, provider-change, reassessment, and retirement processes.
AI capability questions
Early questions should expose the task, evidence, uncertainty, and responsibilities that shape a safe and useful implementation.
Proportionate governance is still useful, but the control depth should match the use. A bounded drafting aid should not necessarily follow the same process as a system influencing an important eligibility decision.
No. We can help implement technical and operating controls and prepare evidence, but compliance conclusions require the relevant legal, regulatory, contractual, and organisational authority.
At minimum it should make the intended use, owner, users, affected people, provider or model, data context, lifecycle status, dependencies, material risks, controls, and review history discoverable.
Review timing should follow consequence, rate of change, monitoring signals, incidents, complaints, provider updates, data shifts, and explicit reassessment triggers rather than one universal schedule.
Start a conversation
Share the workflow, evidence, people affected, and the outcome you want. We can help frame a responsible first question and bounded next step.