University/AI Architect/Lesson 2 of 4

AI Governance and Risk

16 min

Objective

Build the framework that lets an organisation adopt AI responsibly and defensibly: policy, risk assessment, compliance and accountability — so AI creates value without creating liability.

▷

Watch

Video lesson

What is AI Governance? — IBM Technology

▤

Read

The concept

At the architect level the question stops being "can we build it?" and becomes "should we, and how do we do it defensibly?" Governance is the set of policies, processes and accountability that answers that. Done well it's what turns AI from a liability into a capability you can sell — enterprise buyers increasingly ask for exactly this evidence, and being able to produce it is a commercial advantage rather than a compliance chore.

Start with an acceptable-use policy, and make it specific enough to act on. What may AI be used for, what may it not, what data may go into which tools, and who is accountable for each system. Vague policies produce shadow usage: if the official line is a blanket ban, people paste customer data into a personal account on their phone instead, and now you have the same risk with none of the visibility. A workable policy names sanctioned tools, states plainly what must never be pasted anywhere, and gives people a fast route to get something approved.

Then risk-tier your use cases, because treating everything identically is what makes governance a roadblock. A marketing draft is low risk. An internal summarisation tool is low-to-medium. Anything that materially affects a person — hiring, credit, housing, insurance, medical triage, education access — is high risk, and demands human oversight, bias testing, documentation and an appeals route. Tiering lets low-risk experimentation stay fast while the consequential systems get real scrutiny, which is the only version of governance that survives contact with a business.

Know the regimes that actually apply to you. Data-protection law governs what you may do with personal data regardless of whether AI is involved — lawful basis, minimisation, and the fact that a model provider processing your data is a processor you're responsible for choosing. The EU AI Act works on risk tiers, with prohibited practices, obligations on high-risk systems, and transparency duties for general-purpose models; sector rules in finance, health and employment often bite harder and sooner than AI-specific law. And the direction of travel everywhere is toward disclosure and human review of consequential automated decisions.

Accountability makes the rest real. Every AI system gets a named owner — a person, not a team — who is answerable for its behaviour. Keep an inventory of systems, what they do, what data they touch, and their risk tier, because you cannot govern what you haven't listed, and the first task in any audit is producing that list. Attach the audit trail from Level 4, so you can reconstruct what a system did and why.

Plan for the bad day before it happens. Who is called when a model produces something harmful, how is it turned off, who talks to the affected person, and what's the disclosure obligation. An incident process written calmly in advance is worth enormously more than one improvised under pressure.

Two things worth naming explicitly. Human oversight has to be genuine: a person who rubber-stamps a hundred model decisions an hour is not oversight, and regulators have begun saying so. Give reviewers the context, the time and the authority to actually overturn a decision. And be careful about vendor claims — "we don't train on your data" belongs in the contract, not the marketing page, alongside retention periods, sub-processors and where data is stored.

The architect's job is to make the responsible path the easy path. Sanctioned tools that are genuinely good, a fast approval route, templates and defaults that are safe, and evidence — evals, logs, documentation — generated as a by-product of building rather than assembled in a panic before a security review. Governance that fights the organisation loses; governance that makes the right thing the convenient thing sticks.

✦

Ask

Your AI Tutor

✦AI Tutor
Ask anything about this lesson. I'll explain at your level — switch modes above any time.
?

Check

Quick quiz

1.Which use case demands the most governance scrutiny?

2.Good governance should be designed so that…

3.Accountability for an AI system requires, at minimum…

4.The EU AI Act is an example of…

⌘

Practice

Assignment

Your task

Draft a one-page AI governance starter for an organisation: an acceptable-use statement (2–3 rules), a simple risk-tiering of three real use cases (low/medium/high with why), and for the high-risk one, the specific controls you'd require. Paste it.

0 words · saved on this device

Rate your work (0/4)

A strong submission ticks every box. Be honest — this is how you learn.

★

Remember

Key takeaways

  • ◆Governance is policy, risk tiering, compliance and accountability — and it's a commercial asset.
  • ◆Blanket bans create shadow usage; name sanctioned tools and a fast approval route.
  • ◆Tier by impact: anything materially affecting a person needs oversight, bias testing and appeal.
  • ◆Keep an inventory with a named owner per system — you can't govern what isn't listed.
  • ◆Make oversight genuine, get vendor data promises into the contract, and write the incident plan early.

Read it, done the quiz, finished the task? Mark it complete.