Service scope
Implementation scope
The AI Management System is built to cover AI you develop, AI you provide to others, and AI you consume from third parties - three different risk profiles that most governance efforts collapse into one.
AIMS Context & Scope
Establish the organizational context for AI, the interested parties whose expectations apply, and a scope boundary that reflects the roles the organization actually plays - developer, provider, deployer or user of AI systems.
AI Governance Structure
Stand up the decision-making body that approves AI use cases, sets tolerance, and resolves escalations, with defined membership, authority and meeting cadence rather than an informal review by whoever is available.
AI Policy & Objectives
Write an AI policy that states what the organization will and will not do with AI, and set measurable AI objectives connected to business and risk outcomes rather than aspirational language.
AI Roles & Accountability
Assign accountability for each AI system across its lifecycle - business owner, technical owner, data owner and risk reviewer - so that responsibility does not evaporate between the team that built it and the team that runs it.
AI System Inventory
Build and maintain a register of AI systems in use covering purpose, data sources, model or vendor, deployment context, affected parties and criticality. Without this, no other AI control can be applied consistently.
AI Risk Methodology
Define how AI-specific risk is identified and evaluated - including performance drift, bias, explainability limits, misuse, data quality and dependency on third-party models - with criteria and thresholds that produce comparable results.
AI Impact Assessment Framework
Implement a repeatable impact assessment covering effects on individuals, groups and society, applied at a defined trigger point in the lifecycle so it informs decisions rather than documenting them afterwards.
Responsible AI Lifecycle Controls
Embed controls across the lifecycle - data sourcing and quality, design, testing and validation, release approval, monitoring, change management and retirement - with gates that a system must pass before it advances.
Third-Party AI Governance
Extend governance to procured AI: due diligence on model providers, contractual expectations, data handling terms, evaluation before deployment, and ongoing oversight of vendor model changes you do not control.
Transparency & Stakeholder Processes
Establish how AI use is disclosed, how affected parties raise concerns or contest outcomes, and how those channels are resourced and evidenced.
AI Performance Monitoring
Define what is measured after deployment - accuracy, drift, incidents, complaints, human-override rates - along with thresholds and the escalation path when a system moves outside expected behaviour.
Continual Improvement
Run internal audit, management review and corrective action over the AIMS so AI governance improves with experience instead of ossifying at first implementation.