AI governance: assign a decision-maker to each risk decision

By Pascal Bouman··3 min read
Product team maps ownership and dependencies in an AI stack

Relevant ownership lies in the decision

The useful question is not who holds all the AI roles, but who is allowed to make or reverse a specific choice: may this workflow send customer data to this model, is human oversight needed, and when is the workflow switched off? NIST describes governance and oversight tasks as the work of actors with management, fiduciary, and legal authority and responsibility. This does not support a prescribed org chart, but it does support the principle that authority must be visible at the point of decision.

Use the four functions to organize, not as a checklist

The NIST AI RMF Playbook organizes suggestions under Govern, Map, Measure, and Manage. These suggestions are voluntary, and the Playbook explicitly is not a checklist that must be followed in full. Use the functions to examine a single workflow: determine the objective and stakeholders, describe the data flow and potential harm, test the output, and manage the outcome with a stop or escalation decision. The appropriate level of depth depends on the specific application and context.

AI workflow with checkpoints for logging, review, and fallback

A decision card for one AI workflow

For the next change, create a card with six fields: the decision, the decision-maker, the relevant workflow and data, the required evidence, the stop threshold, and the reassessment date. For example, before a model may draft customer emails, the product owner documents which evaluation examples were reviewed; security gets an explicit stop threshold in the event of an access incident; following a change to the model, prompt, or data source, a new assessment takes place. Use this as a working rule: "For each AI workflow, document: decision, authorized owner, data used, test evidence, stop threshold, and next reassessment." This turns an abstract owner into a verifiable action.

What a card does not solve

The card makes a decision traceable, but it does not provide authority, expertise, or time. "A decision card does not replace authority, expertise, or available time; rehearse the stop threshold and adjust the evidence burden to the potential harm." Therefore, for a meaningful workflow, schedule a short exercise: have the designated decision-maker assess an error signal, stop the workflow, and document what is required to restart it. For a simple internal application, the same card can remain brief; the source passages provide no universal thresholds, legal classifications, or guarantees about outcomes.

Dependency register for AI workflows

Further reading

Your personal AI research team

Developments move too fast to keep up with everything yourself.

You need a research team that tracks changes, checks sources and decides what matters for your work.

Choose what you want to follow and receive only the updates that matter to you.

Updates tailored to your interests
Researched by specialist agents
Relevant insights, not daily noise

What do you want to follow?

You receive a confirmation email first and only join after clicking it. See the privacy policy.

Latest articles

Recent knowledge base articles selected for this page.