Playbook
A practical AI governance playbook.
Frameworks tell you what 'good' looks like. A playbook tells you how to run it. This is the operating model I use to govern AI across its lifecycle in financial services — built to be embedded from the design stage, not bolted on at review. The thread running through all of it: humans design these systems, and humans stay accountable for them.
Governance operating model
Establish a single, lightweight forum that reviews AI use cases before they're built, sets the risk tier for each, and defines what evidence a given tier requires. The aim is speed with a paper trail: low-risk use cases move fast; high-risk ones get proportionate scrutiny.
See the operating model in depthRoles and ownership
The question that quietly decides whether governance works: who owns the outcome when the model is wrong? Name an accountable human owner for every deployed model, and define the roles around them — who validates, who monitors, who can pull it from production.
See the full RACIControls across the lifecycle
Attach the right control to each stage: data checks at sourcing, bias and performance testing at validation, guardrails and human-in-the-loop at deployment, and drift monitoring in production. The lifecycle — not the launch — is the unit of governance.
Evidence and documentation
If you can't show it, you didn't do it. Define the minimum evidence pack for each risk tier — validation results, data lineage, decision logs, and sign-offs — and make producing it a by-product of the workflow rather than a scramble before an audit.
Human oversight and escalation
Decide in advance which decisions require a human, what triggers escalation (a low confidence score, a high-impact decision, a detected contradiction), and how a reviewer acts on it. Oversight designed after launch is oversight that doesn't happen.
Deep dive
The governance operating model, in depth
Governance only works if it’s wired into how the organization is structured, funded, and held accountable. This is an illustrative worked example — how to weigh the ways to organize, what a target-state center of excellence looks like, and the questions that pressure-test whether the model actually holds together.
Part 1 · How to organize
Three ways to organize for success
Every model balances the same forces — time-to-market, reusability, funding and cost, and managing limited resources. The trade-off is where control sits.
Centralized
A central team designs the processes, capabilities, and operating model and shoulders the initial cost and management.
Pros
- Speed of execution
- Simplified operating model and implementation
- Creates reusable components and blueprints
Cons
- Business teams can feel disconnected
- A narrower set of technologies, ideas, and vendors
- Potential for slower use-case development
Hybrid / Centrally Led
Common target stateA center manages funding, core reusable components, and architecture, while lines of business build what matters to them. Harder to coordinate at scale and risks some duplication.
Pros
- Lets business lines build what's important to them
- Creates shared, centralized utilities
- Speed to market
Cons
- Potential duplication of work, tech, and components
- Hard to manage before blueprints exist
- First movers bear the brunt of the costs
Decentralized
Lines of business own delivery inside their own products, with direct control of funding and technology choices. Speed is traded for cost and duplication.
Pros
- Businesses directly manage and fund delivery
- Technology decisions owned by each product
- Product, data, and business teams know their space in detail
Cons
- Major duplication of effort and cost
- Competition for limited talent and vendors
- Limits cross-enterprise use cases
A common goal is to move toward a hybrid, centrally-led model over roughly 18–24 months — capturing the speed and reuse of a center while keeping delivery close to the business.
Part 2 · Target state
A GenAI Center of Excellence
In a hybrid, centrally-led model, a center of excellence owns the shared capabilities and standards, while risk, legal, finance, and the lines of business align to it as a cabinet.
Reports in
GenAI Center of Excellence — Lead
Core functions · direct reports
Cabinet · aligned partner functions
Part 3 · Diagnostic
Pressure-testing the operating model
Before committing to a structure, work through where the current state is unclear. These are the questions that surface the gaps — across strategy, funding, platform, resourcing, and risk.
Strategy
Typical current state
- GenAI strategy spans central technology, operations, line-of-business CIO and business-AI teams, and a GenAI Council.
- Use-case ideas are captured in a central intake tool.
Questions to pressure-test
- How does an idea move from a product or business team up to the GenAI Council?
- Do business and technology organizations within a line of business work from a documented joint operating model — or does each drive AI separately?
- Is the prioritization approach documented and shared with product teams?
Funding
Typical current state
- Enterprise technology capacity is funded centrally for GenAI use cases.
- First-mover costs are unclear to lines of business, which hampers prioritization and funding.
Questions to pressure-test
- Lines of business fund integration into their own products — but is the cost of leveraging shared GenAI platforms clear enough to make funding decisions?
- Teams believe MVP and prototyping are centrally funded; is the path to actually access those funds clear?
Platform
Typical current state
- An enterprise GenAI platform has been stood up.
- Third-party GenAI capabilities (productivity suites, CRM, service management, data and analytics vendors) are being onboarded both inside and outside that platform, without a clear vendor strategy.
Questions to pressure-test
- How are product teams directed to a clear solution catalog and recommendations?
- GenAI is appearing in most third-party platforms at varying maturity — how is that managed and communicated to the broader organization?
- Who owns the approach across technology, enterprise functions, and operations for the proliferation of tools?
Resourcing
Typical current state
- Lines of business handle GenAI governance (risk, escalation, regulatory, prioritization) by leveraging existing traditional-AI governance.
- No end-to-end view of accountability for GenAI across lines of business, operations, and technology.
- No centralized expertise to get the first wave of use cases fully into production.
Questions to pressure-test
- If the GenAI Council is the final approval, how are use cases tracked, reviewed, and risk-assessed before they reach it?
- Under a federated model, is there a clear picture of the operating model and who is accountable for each step?
- Is there a central team or set of blueprints to drive the first use cases fully into production — testing the platform, cloud capabilities, reg/control/legal reviews, and data requirements?
Risk
Typical current state
- GenAI use cases follow traditional-AI governance and product-development routines.
- A risk-and-control review hub-and-spoke vets use cases before they reach pre-vetting and the GenAI Council.
Questions to pressure-test
- Technology platform owners have started a risk-and-control process — but does it account for business-level risk and controls?
- How are risk, control, and legal teams partnered across lines of business, operations, and technology to agree a unified approach, and to show where business-specific controls are still needed?
Deep dive · Roles & ownership
Who does what: the GenAI RACI
Naming an accountable owner only works if the whole cast is clear. This RACI maps every activity across the AI lifecycle to who is Responsible, Accountable, Consulted, and Informed — from intake through monitoring.
| GenAI Governance | Business & Function Roles | GenAI Platform | Enterprise Risk | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Activity | GenAI Center of Excellence | GenAI Product Management | GenAI Pre-Vetting Committee | GenAI Executive Committee | Business Use Case Owner | Business Technology | Business Model Risk | Business Control Manager | Business Legal / Risk / Compliance | Tech Control Manager | Tech Legal / Risk / Compliance | Central Technology | Central Tech Control | Model Risk Governance | Enterprise Data Governance | Info Sec Governance |
| Intake and Prioritization | ||||||||||||||||
| Develop use cases to identify objectives, risks, and business outcomes | C | C | R/A | C | I | I | I | C | ||||||||
| Legal, Risk & Compliance evaluate the use case against the current / emerging risk environment | C | R | I | I | C | A | C | |||||||||
| Use cases prioritized and moved to GenAI Product Management for review / approval | C | C | R/A | C | C | C | C | C | C | |||||||
| Pre-Development | ||||||||||||||||
| GenAI use case development | R | A | C | C | C | C | C | |||||||||
| Use case assessment and review | R | A | C | C | C | C | C | C | ||||||||
| LOB Risk & Control Committee review | A/R | C | C/I | R/A | I/C | I/C | I/C | |||||||||
| GenAI pre-vetting review | A/R | C | C/I | R/A | ||||||||||||
| Development | ||||||||||||||||
| Lead use case development activities | C/I | I | R/A | C | C | C | C | C | C | I | C/I | R/A | ||||
| Tech design | I | R | R | I | I | I | C/I | C/I | R | C/I | ||||||
| Lead enterprise change-management activities | R/A | I | R/A | I | C | C | C | C/I | C/I | I | ||||||
| Develop use case if in-house developed | R/A | I | R/A | C | C | C | C | C/I | C/I | R/A | R/A | |||||
| LOB Risk & Control Committee review | R | I | I/C | C | C | C | C | |||||||||
| LOB BCM - risk-assessment & control enhancements | C | R | I | I/C | I/C | I/C | C | C | ||||||||
| GenAI Committee approval | I | R/A | C | C | R/A | C | C | C | C | C | C | I | ||||
| Deployment | ||||||||||||||||
| Operational implementation; follows SDLC routines | R | I | C | A | C | C | C | C | C | R | R | C | ||||
| Implement GenAI solution (Tech and central AI delivery) | R | I | R/A | A | C | C | C | C | R | R | R | |||||
| Monitoring | ||||||||||||||||
| Monitor GenAI performance | R | I | R/A | C | I | I | I | I | C | C | ||||||
| Revalidation — based on regular routines | I | I | R/A | C | C | C | C | C | C | C | ||||||
Scroll horizontally to see all 16 roles.