Joe Meylor

Playbook

A practical AI governance playbook.

Frameworks tell you what 'good' looks like. A playbook tells you how to run it. This is the operating model I use to govern AI across its lifecycle in financial services — built to be embedded from the design stage, not bolted on at review. The thread running through all of it: humans design these systems, and humans stay accountable for them.

01

Governance operating model

Establish a single, lightweight forum that reviews AI use cases before they're built, sets the risk tier for each, and defines what evidence a given tier requires. The aim is speed with a paper trail: low-risk use cases move fast; high-risk ones get proportionate scrutiny.

See the operating model in depth
02

Roles and ownership

The question that quietly decides whether governance works: who owns the outcome when the model is wrong? Name an accountable human owner for every deployed model, and define the roles around them — who validates, who monitors, who can pull it from production.

See the full RACI
03

Controls across the lifecycle

Attach the right control to each stage: data checks at sourcing, bias and performance testing at validation, guardrails and human-in-the-loop at deployment, and drift monitoring in production. The lifecycle — not the launch — is the unit of governance.

04

Evidence and documentation

If you can't show it, you didn't do it. Define the minimum evidence pack for each risk tier — validation results, data lineage, decision logs, and sign-offs — and make producing it a by-product of the workflow rather than a scramble before an audit.

05

Human oversight and escalation

Decide in advance which decisions require a human, what triggers escalation (a low confidence score, a high-impact decision, a detected contradiction), and how a reviewer acts on it. Oversight designed after launch is oversight that doesn't happen.

Deep dive

The governance operating model, in depth

Governance only works if it’s wired into how the organization is structured, funded, and held accountable. This is an illustrative worked example — how to weigh the ways to organize, what a target-state center of excellence looks like, and the questions that pressure-test whether the model actually holds together.

Illustrative example. A generic operating-model pattern for discussion — not the structure of any specific institution. Adapt it to your own organization.

Part 1 · How to organize

Three ways to organize for success

Every model balances the same forces — time-to-market, reusability, funding and cost, and managing limited resources. The trade-off is where control sits.

Centralized

A central team designs the processes, capabilities, and operating model and shoulders the initial cost and management.

Pros

  • Speed of execution
  • Simplified operating model and implementation
  • Creates reusable components and blueprints

Cons

  • Business teams can feel disconnected
  • A narrower set of technologies, ideas, and vendors
  • Potential for slower use-case development

Hybrid / Centrally Led

Common target state

A center manages funding, core reusable components, and architecture, while lines of business build what matters to them. Harder to coordinate at scale and risks some duplication.

Pros

  • Lets business lines build what's important to them
  • Creates shared, centralized utilities
  • Speed to market

Cons

  • Potential duplication of work, tech, and components
  • Hard to manage before blueprints exist
  • First movers bear the brunt of the costs

Decentralized

Lines of business own delivery inside their own products, with direct control of funding and technology choices. Speed is traded for cost and duplication.

Pros

  • Businesses directly manage and fund delivery
  • Technology decisions owned by each product
  • Product, data, and business teams know their space in detail

Cons

  • Major duplication of effort and cost
  • Competition for limited talent and vendors
  • Limits cross-enterprise use cases

A common goal is to move toward a hybrid, centrally-led model over roughly 18–24 months — capturing the speed and reuse of a center while keeping delivery close to the business.

Part 2 · Target state

A GenAI Center of Excellence

In a hybrid, centrally-led model, a center of excellence owns the shared capabilities and standards, while risk, legal, finance, and the lines of business align to it as a cabinet.

Reports in

GenAI Center of Excellence — Lead

Core functions · direct reports

Program Management
GenAI Council / Intake
Strategy
Ethics, Bias & Policy
Governance
Product Management (Use Cases)
Architecture
Technology — Platform & Product
Data
AI Centers of Excellence
Model Risk
Training
Communications & Change Mgmt
Business Development

Cabinet · aligned partner functions

Legal
Risk & Compliance
Controls
Finance / FinOps
LOB Data Science Leads
LOB AI Tech Leads
Direct report to the CoE LeadAligned to CoE leadership

Part 3 · Diagnostic

Pressure-testing the operating model

Before committing to a structure, work through where the current state is unclear. These are the questions that surface the gaps — across strategy, funding, platform, resourcing, and risk.

Strategy

Typical current state

  • GenAI strategy spans central technology, operations, line-of-business CIO and business-AI teams, and a GenAI Council.
  • Use-case ideas are captured in a central intake tool.

Questions to pressure-test

  • How does an idea move from a product or business team up to the GenAI Council?
  • Do business and technology organizations within a line of business work from a documented joint operating model — or does each drive AI separately?
  • Is the prioritization approach documented and shared with product teams?

Funding

Typical current state

  • Enterprise technology capacity is funded centrally for GenAI use cases.
  • First-mover costs are unclear to lines of business, which hampers prioritization and funding.

Questions to pressure-test

  • Lines of business fund integration into their own products — but is the cost of leveraging shared GenAI platforms clear enough to make funding decisions?
  • Teams believe MVP and prototyping are centrally funded; is the path to actually access those funds clear?

Platform

Typical current state

  • An enterprise GenAI platform has been stood up.
  • Third-party GenAI capabilities (productivity suites, CRM, service management, data and analytics vendors) are being onboarded both inside and outside that platform, without a clear vendor strategy.

Questions to pressure-test

  • How are product teams directed to a clear solution catalog and recommendations?
  • GenAI is appearing in most third-party platforms at varying maturity — how is that managed and communicated to the broader organization?
  • Who owns the approach across technology, enterprise functions, and operations for the proliferation of tools?

Resourcing

Typical current state

  • Lines of business handle GenAI governance (risk, escalation, regulatory, prioritization) by leveraging existing traditional-AI governance.
  • No end-to-end view of accountability for GenAI across lines of business, operations, and technology.
  • No centralized expertise to get the first wave of use cases fully into production.

Questions to pressure-test

  • If the GenAI Council is the final approval, how are use cases tracked, reviewed, and risk-assessed before they reach it?
  • Under a federated model, is there a clear picture of the operating model and who is accountable for each step?
  • Is there a central team or set of blueprints to drive the first use cases fully into production — testing the platform, cloud capabilities, reg/control/legal reviews, and data requirements?

Risk

Typical current state

  • GenAI use cases follow traditional-AI governance and product-development routines.
  • A risk-and-control review hub-and-spoke vets use cases before they reach pre-vetting and the GenAI Council.

Questions to pressure-test

  • Technology platform owners have started a risk-and-control process — but does it account for business-level risk and controls?
  • How are risk, control, and legal teams partnered across lines of business, operations, and technology to agree a unified approach, and to show where business-specific controls are still needed?

Deep dive · Roles & ownership

Who does what: the GenAI RACI

Naming an accountable owner only works if the whole cast is clear. This RACI maps every activity across the AI lifecycle to who is Responsible, Accountable, Consulted, and Informed — from intake through monitoring.

Illustrative example. A generic, de-identified mapping for discussion — not the RACI of any specific institution. Adapt the roles and assignments to your own organization.
RResponsibledoes the workAAccountableowns the outcomeCConsultedtwo-way inputIInformedkept up to date
GenAI GovernanceBusiness & Function RolesGenAI PlatformEnterprise Risk
Activity
GenAI Center of Excellence
GenAI Product Management
GenAI Pre-Vetting Committee
GenAI Executive Committee
Business Use Case Owner
Business Technology
Business Model Risk
Business Control Manager
Business Legal / Risk / Compliance
Tech Control Manager
Tech Legal / Risk / Compliance
Central Technology
Central Tech Control
Model Risk Governance
Enterprise Data Governance
Info Sec Governance
Intake and Prioritization
Develop use cases to identify objectives, risks, and business outcomesCCR/ACIIIC
Legal, Risk & Compliance evaluate the use case against the current / emerging risk environmentCRIICAC
Use cases prioritized and moved to GenAI Product Management for review / approvalCCR/ACCCCCC
Pre-Development
GenAI use case developmentRACCCCC
Use case assessment and reviewRACCCCCC
LOB Risk & Control Committee reviewA/RCC/IR/AI/CI/CI/C
GenAI pre-vetting reviewA/RCC/IR/A
Development
Lead use case development activitiesC/IIR/ACCCCCCIC/IR/A
Tech designIRRIIIC/IC/IRC/I
Lead enterprise change-management activitiesR/AIR/AICCCC/IC/II
Develop use case if in-house developedR/AIR/ACCCCC/IC/IR/AR/A
LOB Risk & Control Committee reviewRII/CCCCC
LOB BCM - risk-assessment & control enhancementsCRII/CI/CI/CCC
GenAI Committee approvalIR/ACCR/ACCCCCCI
Deployment
Operational implementation; follows SDLC routinesRICACCCCCRRC
Implement GenAI solution (Tech and central AI delivery)RIR/AACCCCRRR
Monitoring
Monitor GenAI performanceRIR/ACIIIICC
Revalidation — based on regular routinesIIR/ACCCCCCC

Scroll horizontally to see all 16 roles.

Want the playbook applied to your stack?

Start a conversation