Building AI Products & Workflows · Governance, adoption and scaling · lesson 16 of 18 · 12 min
Operational AI governance for product teams
Governance that enables
AI governance is often seen as a brake. Done well, it is what lets organisations move faster with confidence: clear rules on what's allowed, clear owners, and proportionate checks. Our Responsible AI course covers principles and ethics in depth; this lesson focuses on the operational machinery product and operations teams need.
The building blocks
1. An AI use policy. What tools staff may use, with which data; what requires approval; disclosure rules. Short and practical beats long and ignored.
2. An inventory (register) of AI systems. For each feature or tool: owner, purpose, users, data categories, providers and models (versions), risk level, evaluation status, and review dates.
3. Risk-tiered review. Not every AI use needs the same scrutiny.
Tier 1 (low): internal drafting aids, no personal data
-> self-assessment checklist
Tier 2 (medium): customer-facing content with human review,
or personal data processed
-> product + privacy + security review
Tier 3 (high): decisions affecting individuals' rights or access
(credit, hiring, health), autonomous actions,
regulated domains
-> full impact assessment, legal review, sign-off
4. Clear ownership. Every AI feature has an accountable owner responsible for its performance, risks and compliance, not "the AI team" collectively.
5. Standard artefacts. AI brief, data flow map, evaluation report, risk assessment, monitoring plan and incident runbook. Templates make these fast.
6. Change management. Prompt, model, tool and data source changes go through evaluation and appropriate review, proportionate to tier.
7. Incident management. A way to report AI issues, triage them, fix them and learn.
Regulatory awareness
AI regulation is evolving and varies by jurisdiction. Examples product teams should be aware of include the EU AI Act (a risk-based framework whose obligations phase in over time and whose high-risk deadlines were postponed by the 2026 Digital Omnibus; see the lesson on AI regulation for product teams), existing data protection laws that already apply to AI processing (such as GDPR and UK GDPR), sector regulations (finance, health, employment), consumer protection and advertising rules, and national AI strategies and guidelines in places such as the UAE and Saudi Arabia. Requirements and timelines are changing; work with legal counsel to determine what applies to you, and design your governance so new requirements can be absorbed (the inventory and risk tiers help).
Voluntary frameworks, such as the NIST AI Risk Management Framework and the ISO/IEC 42001 standard for AI management systems, offer useful structures even where not mandatory.
Governance in the development lifecycle
| Stage | Governance activity | |---|---| | Idea | Register use case, initial risk tier | | Prototype | Approved tools and data only | | Pre-launch | Evaluation report, risk review per tier, privacy/security sign-off | | Launch | Monitoring plan, incident runbook, user disclosures | | Operation | Periodic review, change control, audits | | Retirement | Data deletion, communication, register update |
Worked example
A financial services firm's product team wants an AI assistant that helps advisers draft client suitability notes. Risk tier 3 (regulated advice context). Governance steps: impact assessment; legal review of regulatory obligations for record-keeping and advice; adviser remains responsible and must review every note; evaluation focused on factual accuracy against client data; audit logging; quarterly review. The project takes longer than an internal drafting tool, but it launches with confidence and survives its first regulatory audit.
Meanwhile, a tier 1 internal meeting-notes tool goes live in two weeks with a checklist. Proportionality lets both happen.
Anti-patterns
- One-size-fits-all review boards that become bottlenecks.
- Policies nobody reads or can find.
- No inventory, so nobody knows what AI is in use.
- Governance that ends at launch.
Hands-on: an AI register that tools can read
Start the register as a spreadsheet if you must, but a structured file (or a database table) lets you automate checks: overdue reviews, features without owners, tier 3 systems without an impact assessment.
# ai-register.yaml (one entry per AI feature, tool or agent)
- id: AI-014
name: Adviser suitability-note drafter
owner: head-of-advice-operations
purpose: Draft suitability notes from client fact-finds for adviser review
users: [advisers]
affected: [retail clients]
data_categories: [personal, financial]
providers: [{vendor: model-provider-A, region: UK, model: pinned-version-recorded-in-release-notes}]
autonomy: assist # assist | review | audit | full
risk_tier: 3
artefacts: {brief: link, data_flow: link, eval_report: link, dpia: link, runbook: link}
last_eval: 2026-08-28
next_review: 2026-11-30
status: live
import datetime as dt, yaml # pip install pyyaml
REQUIRED_BY_TIER = {1: ["brief"], 2: ["brief", "data_flow", "eval_report", "runbook"],
3: ["brief", "data_flow", "eval_report", "dpia", "runbook"]}
def tier_for(entry):
if entry["autonomy"] == "full" or "decisions_about_people" in entry.get("flags", []):
return 3
if "personal" in entry["data_categories"] or "customers" in entry.get("affected", []):
return max(2, entry.get("risk_tier", 2))
return entry.get("risk_tier", 1)
today = dt.date.today()
for e in yaml.safe_load(open("ai-register.yaml", encoding="utf-8")):
issues = []
t = tier_for(e)
if t != e["risk_tier"]:
issues.append(f"tier looks like {t}, recorded {e['risk_tier']}")
missing = [a for a in REQUIRED_BY_TIER[t] if not e.get("artefacts", {}).get(a)]
if missing:
issues.append(f"missing artefacts: {missing}")
if dt.date.fromisoformat(str(e["next_review"])) < today:
issues.append("review overdue")
if not e.get("owner"):
issues.append("no owner")
print(e["id"], "OK" if not issues else "; ".join(issues))
Run it weekly (or in CI for the repository that holds the register) and send the output to the governance channel. Governance that is checked automatically gets followed.
Going further
Automate governance where you can: register entries created from project templates, evaluation reports generated by your harness, monitoring dashboards linked from the register. Governance that is embedded in tooling is followed; governance that lives only in documents is not.
Video lecture: Operational AI governance for product teams
Lecture coming soon · 15 chapters · about 8 minutes. Read the full transcript below.
- Operational AI governance
- Analogy: rules of the road
- Seven building blocks
- Risk tiers
- Regulation and frameworks
- Across the lifecycle
- Simple example: two marketing uses
- Worked example: two speeds
- Business example (illustrative)
- Hands-on in the lesson
- Common mistakes
- How you'll know it works
- Watch me do it: register + checks
- Recap
- Try this now (40 minutes)
Lecture transcript
Operational AI governance
Say AI governance in most companies and people picture a committee that says no slowly. Done well, it's the opposite. Clear rules on what's allowed, clear owners, and checks proportionate to risk are what let teams move fast with confidence. In this lesson you'll learn the building blocks of operational AI governance, how risk tiers keep low-risk tools moving while protecting high-risk ones, how regulation fits in, and how to automate the paperwork.
Analogy: rules of the road
Here's an analogy. Good governance is like the rules of the road. Speed limits, lanes and traffic lights don't stop people driving; they let millions of people drive fast and safely at the same time. A motorway has different rules from a school street, because the risks differ. Risk tiers are your speed limits: fast lanes for low-risk tools, careful streets for high-risk ones.
Seven building blocks
There are seven building blocks. An AI use policy: which tools staff may use with which data, what needs approval, and disclosure rules. Short and practical beats long and ignored. An inventory, or register, of every AI system: owner, purpose, users, data, providers and model versions, risk level, evaluation status and review dates. Risk-tiered review. Clear ownership: every feature has one accountable person, not the AI team in general. Standard artefacts with templates. Change management for prompts, models, tools and data sources. And incident management.
Risk tiers
Risk tiers make governance proportionate. Tier one, low: internal drafting aids with no personal data, which need a self-assessment checklist. Tier two, medium: customer-facing content with human review, or personal data processing, which needs product, privacy and security review. Tier three, high: decisions affecting people's rights or access, like credit, hiring or health; autonomous actions; or regulated domains. These need a full impact assessment, legal review and formal sign-off.
Regulation and frameworks
Regulation is evolving and varies by jurisdiction. Product teams should know the EU AI Act, a risk-based framework whose obligations phase in over time, with high-risk deadlines postponed by the 2026 Digital Omnibus. Existing data protection laws already apply to AI processing. Sector rules in finance, health and employment matter, as do consumer protection and advertising rules, and national frameworks in places like the UAE, Saudi Arabia and Pakistan. Work with counsel on what applies, and design governance so new requirements can be absorbed. Voluntary frameworks like the NIST AI Risk Management Framework and ISO slash IEC forty-two thousand and one give you useful structure.
Across the lifecycle
Governance runs across the whole lifecycle. At the idea stage, register the use case with an initial tier. When prototyping, use approved tools and data only. Before launch: evaluation report, tier-appropriate reviews and sign-offs. At launch: monitoring plan, incident runbook and user disclosures. In operation: periodic review, change control and audits. And at retirement: data deletion, communication and a register update.
Simple example: two marketing uses
A simple example. A marketing team wants to use an AI tool to brainstorm social captions. No personal data, human-written final posts, internal use only. That's tier one: a self-assessment checklist and an entry in the register, done in a day. The same team later wants AI to reply to customer comments automatically. Customer-facing, public, sometimes complaints: that's at least tier two, with review, monitoring and an owner.
Worked example: two speeds
Here's proportionality in action. A financial services firm wants an assistant that helps advisers draft client suitability notes. That's tier three, a regulated advice context. So: an impact assessment, legal review of record-keeping and advice obligations, advisers remain responsible and review every note, evaluation focused on factual accuracy against client data, audit logging and quarterly review. It takes longer, but it launches with confidence and survives its first regulatory audit. Meanwhile, a tier one internal meeting-notes tool goes live in two weeks with a checklist. Both happen, because governance is proportionate.
Business example (illustrative)
Illustrative numbers for the two-speed firm. In one year it registered twenty-six AI uses: eighteen tier one, six tier two, two tier three. Tier one items went live in a median of four days, tier two in about three weeks, and tier three in about three months. The register made the first regulatory information request easy: they answered in an afternoon, with links to every artefact.
Hands-on in the lesson
The hands-on section turns your register into something tools can check. Each entry is structured: owner, purpose, data categories, providers and regions, autonomy, risk tier, links to artefacts and review dates. A short Python script recalculates each entry's likely tier, flags missing artefacts for that tier, overdue reviews and missing owners, and prints a weekly report for your governance channel. Governance that's checked automatically gets followed. Governance that lives in a forgotten document doesn't.
Common mistakes
Common mistakes. A single review board for everything, which becomes a bottleneck. A long policy nobody reads. No register, so nobody knows what AI is in use. Governance that stops at launch. Treating vendor tools as outside governance because someone else built them. And documents that duplicate each other instead of templates that feed one register.
How you'll know it works
How will you know your governance works? Low-risk tools go live quickly, high-risk ones get proper scrutiny, and people describe the process as helpful rather than obstructive. The register is complete and current. Reviews happen on schedule. And when a regulator, client or auditor asks what AI you use and how it's controlled, you can answer from the register in an afternoon.
Watch me do it: register + checks
Watch me do it. I open ai-register dot yaml. Each entry has an ID, name, owner, purpose, users, who's affected, data categories, providers with region and model, autonomy, risk tier, links to artefacts and review dates. Next, the check script. Required-by-tier lists the artefacts each tier needs: a brief for tier one, up to brief, data flow, evaluation report, impact assessment and runbook for tier three. Tier-for recalculates the likely tier: full autonomy or decisions about people means three; personal data or customers affected means at least two. Then the loop compares recorded and calculated tiers, lists missing artefacts, flags overdue reviews and missing owners. I run it on our register. AI fourteen is OK. AI twenty-two is missing its impact assessment. AI thirty-one's review is overdue. I post the output in the governance channel and assign the two fixes.
Recap
To recap: good governance enables speed. Build a use policy, a register, risk tiers, clear ownership, standard artefacts, and change and incident management. Keep up with regulation through counsel and design for change. Embed governance across the lifecycle and automate the checks. Your next step: draft a one-page risk-tier policy and classify three AI uses you know. Next, we'll look at AI regulation for product teams in more detail.
Try this now (40 minutes)
Try this now. Write a one-page risk-tier policy with three tiers, examples and the review each needs. Then list three AI uses in your organisation and classify each. Create register entries for them with an owner, purpose, data categories, providers, autonomy, tier and next review date. If you have a few more minutes, run the register check script on those entries.
Key takeaways
- Good governance enables speed: clear rules, owners and proportionate checks.
- Building blocks: use policy, AI inventory, risk-tiered review, ownership, standard artefacts, change and incident management.
- Regulation varies and evolves (e.g. EU AI Act, data protection, sector rules); work with counsel and design for change.
- Embed governance across the lifecycle and automate it in tooling where possible.
Try it
Draft a one-page risk-tier policy for your organisation and classify three AI uses you know into tiers with the review each requires.