返回 Papers
AI 扩展计划 / Playbooks

AI Three Lines Governance / Decision Rights / Assurance Playbook

版本: v1.0

459AI_THREE_LINES_GOVERNANCE_DECISION_RIGHTS_ASSURANCE_PLAYBOOK.md

AI Three Lines Governance / Decision Rights / Assurance Operating Model Playbook

版本: v1.0 日期: 2026-06-30 适用对象: experienced CBAP、financial retail PM、product architect、enterprise architect、AI governance lead、risk / compliance partner、internal audit partner、AI platform owner。

本文是一份执行型手册, 用于把 AI use case 的三道防线职责、生命周期 gate、decision rights、evidence forum、challenge memo、issue/action tracking、assurance packet、escalation path 和 architecture governance 连接成可运行的 operating model。本文不构成法律意见、监管解释、审计意见、模型验证结论、内控有效性结论或生产批准。


1. Purpose and When To Use

Use this playbook when an AI initiative has any of these conditions:

TriggerWhy this playbook is needed
AI output affects customers, cases, credit, onboarding, financial crime, complaints or regulated contentDecision rights and control ownership must be explicit before release.
RAG, copilots, agents or vendor models are embedded into business workflowEvidence must connect architecture, controls, issues and gate decisions.
Risk, compliance, privacy, security, model risk, third-party risk or internal audit will review the use caseFirst-line ownership, second-line challenge and third-line assurance must not be blurred.
Project teams say "risk signed off" without naming residual-risk ownerThe operating model needs a clear decision record and challenge memo.
Conditional release or management action is expectedIssue/action tracking needs owner, due date, acceptance criteria, closure evidence and escalation path.
Similar AI issues repeat across teamsArchitecture governance should turn repeat issues into reusable controls and platform standards.

Recommended use cases:

Use caseOperating-model focus
GenAI contact centerRegulated content boundary, escalation, quality review, transcript evidence
AML copilotAnalyst-owned disposition, source-span evidence, typology coverage, case narrative review
Credit decision supportDecision-support boundary, policy consistency, adverse-action evidence, fairness challenge route
KYC onboardingDocument classification, missing-information follow-up, false reject / false accept issue route
AI vendor modelData use terms, model update notice, incident notice, fallback and exit readiness
Enterprise knowledge assistantApproved-source governance, entitlement-aware retrieval, issue routing for stale or sensitive content

Definition:

AI Three Lines operating model = first-line product/ops ownership
  + second-line independent challenge
  + third-line independent assurance
  + lifecycle decision rights
  + evidence forum
  + issue/action tracking
  + architecture governance integration

2. Operating Model

2.1 Core Principles

PrinciplePractical rule
First line owns product and operational riskProduct / operations owner owns outcome, control operation, evidence production and residual-risk proposal.
Second line challenges, conditions and escalatesRisk / compliance / privacy / security / model risk / TPRM define standards and challenge evidence.
Third line assures independentlyInternal audit does not approve releases; it provides independent assurance through audit planning, testing and findings.
Gate decisions bind exact evidenceEvery gate decision references evidence packet version, issue disposition and conditions.
Conditions are managed actionsConditional go decisions require owner, due date, acceptance criteria and closure evidence.
Architecture governance is part of the modelADRs, ARB minutes, reference architecture and platform standards must reflect control and evidence decisions.
Material change reopens reviewModel, prompt, RAG corpus, tool permission, automation, vendor or customer-impacting workflow changes trigger gate analysis.

2.2 Operating Cadence

CadencePurposeParticipantsOutput
Intake triageClassify AI use case and risk tierPM, governance office, EA, relevant second lineuse case record, gate plan
Design evidence reviewChallenge architecture, controls and evidence plan before pilotProduct architect, control owners, risk/compliance, platformdesign decision, issue log
Release evidence forumReview release packet, challenge memo and open issue dispositionFirst line owner, second line challenge owners, governance lead, EAgate decision record
Issue/action reviewTrack conditions, defects, overdue actions and repeat issuesaction owners, governance office, second lineaction status, escalation
Architecture governance reviewConvert repeat risks into standards and reusable platform patternsEA, platform, security, governance officeADR, reference architecture update
Assurance planning touchpointAlign audit universe with high-risk AI areas without making audit an approverinternal audit, governance office, relevant managementassurance plan inputs

3. Template: Three-Lines Role Map

Use this table at intake and update it at each material gate.

Role areaFirst line product / opsSecond line risk / complianceThird line internal auditEvidence
Accountable ownerBusiness sponsor: Head of Financial Crime Operations; product owner: AML Copilot Product Owner; operations owner: AML Investigation ManagerChallenge functions: Financial Crime Compliance, Model Risk, Privacy, Security, Third-Party RiskAudit relationship owner: Internal Audit Financial Crime Technology Directorowner attestation, AI inventory record
Business outcomeDefines benefit, scope, users, process change and operating capacityChallenges whether outcome creates unmanaged risk or policy conflictMay assess whether governance representations are reliablePRD, value case, operating model
Risk tier and scopeProposes risk tier and automation boundaryChallenges risk tier, customer impact and policy mappingMay use risk tier for audit universe planningrisk tier worksheet
Control ownershipOwns control design and operating performanceChallenges control adequacy and failure conditionTests selected controls if in audit scopecontrol matrix
Evidence ownershipProduces evidence packet and maintains evidence freshnessChallenges completeness, relevance and expiryUses evidence for independent assuranceevidence packet index
Gate decisionMakes go / no-go / conditional-go recommendation within authorityNo objection, condition, object or escalateNo release approval; assurance note if relevantgate decision record
Issue closureOwns management actions and closure evidenceChallenges severity, due date and closure sufficiencyValidates closure for audit findings where applicableissue/action log
Architecture governanceImplements approved architecture and control pointsChallenges policy and risk fit of architectureReviews governance consistency if auditedADR, ARB minutes

Completed example:

Role areaGenAI contact center example
First lineContact center director owns agent-assist operating process; AI product owner owns release packet; quality operations owns sampling control.
Second lineCompliance challenges regulated answer boundaries; privacy challenges transcript retention; conduct risk challenges vulnerable customer escalation.
Third lineInternal audit does not approve launch; it records the use case for possible future review of governance and control operation.

4. Template: Lifecycle Decision-Rights Matrix

GateDecision questionFirst line decision rightSecond line challenge rightThird line assurance roleRequired evidencePossible decision
IntakeShould this be registered and assessed as AI?Accept use case scope and ownerChallenge AI classification, risk tier and policy functions in scopeNone or audit universe awarenessuse case record, risk tier worksheetproceed, reclassify, reject
DesignIs design fit for controlled pilot?Approve design proposal and control owner mapChallenge control design, architecture, data use and evidence planReview artifacts only if assurance planning requiresarchitecture view, control matrix, evidence planproceed, redesign, escalate
PilotIs limited pilot controlled enough?Approve pilot scope, users, traffic and exit criteriaChallenge pilot population, restrictions, monitoring and stop ruleMay observe governance, not approve pilotpilot plan, eval summary, SOP, issue logpilot, reduce scope, no-go
ReleaseCan production release occur?Make go / no-go recommendation and accept residual-risk proposalNo objection, condition, objection or escalationDoes not sign release; may reference prior findingsrelease packet, challenge memo, open issue dispositiongo, conditional go, no-go, escalate
ScaleCan traffic, automation or scope expand?Request scale based on value and control evidenceChallenge evidence under expanded population and capacityMay include in audit planscale memo, operating evidence, action agingscale, hold, reduce, rework
Material changeCan changed model, prompt, RAG, tool or vendor proceed?Classify change and request approvalChallenge materiality and regression evidenceMay test change process if auditedchange impact, regression eval, ADR updateapprove, require gate, rollback
Incident / stopShould system pause, degrade or rollback?Execute stop rule and remediationChallenge severity, customer impact and closureIndependently review incident handling laterincident record, replay packet, action planpause, rollback, continue with controls
RetireCan capability or dependency be decommissioned?Retire product scope and operational dependencyChallenge retention, obligations and customer impactMay test retirement controlsretirement ADR, retention evidenceretire, extend support, remediate

Decision vocabulary:

DecisionMeaning
GoEvidence sufficient, issues within authority, controls ready
Conditional goRelease allowed only with named actions, due dates and review trigger
No-goBlocker issue or evidence gap prevents release
Reduce scopePilot or release continues with lower-risk users, channels, actions or data
EscalateAuthority exceeded or first / second line disagreement requires senior decision
Pause / rollbackProduction control failure, incident or material drift requires stop action
RetireUse case, model or vendor dependency exits with retention and obligation evidence

5. Template: Evidence Forum Agenda

Use for design, release, scale and material-change gates.

Agenda itemOwnerEvidenceDecision needed
1. Confirm gate and decision authorityGovernance leaddecision-rights matrixConfirm who can decide, challenge and escalate
2. Confirm use case scope and changesPMuse case record, change noteConfirm scope, automation boundary and customer impact
3. Review architecture and control pointsProduct architect / EAarchitecture diagram, ADRConfirm policy decision point, evidence capture and issue route
4. Review control ownershipFirst line control ownerscontrol matrixConfirm owner, frequency, failure condition and evidence
5. Review eval / test / pilot evidenceAI platform / delivery leadeval report, pilot findingsConfirm release criteria and failure disposition
6. Review second-line challenge memoChallenge ownerschallenge memoConfirm no objection, conditions, objections or escalation
7. Review issue/action logGovernance leadissue registerClassify blockers, conditions, accepted issues and overdue actions
8. Decide gate outcomeAccountable first line ownerevidence packetRecord go, conditional go, no-go, reduce scope or escalate
9. Confirm ADR and review triggersArchitectADR, review triggersUpdate architecture decision and material-change triggers
10. Confirm management action follow-upAction ownersaction trackerAssign closure evidence and next review date

Forum discipline:

  • Do not review every artifact page by page; use evidence index and exception-based review.
  • Do not allow verbal closure of issues; closure requires acceptance criteria and evidence.
  • Do not combine risk acceptance with unclear owner language; record first-line accountable owner.
  • Do not treat internal audit attendance as release approval.

6. Template: Second-Line Challenge Memo

Concrete memo example:

# Second-Line Challenge Memo: AML Copilot Release Gate

Date: 2026-06-30
Gate: release
Challenge functions: Financial Crime Compliance, Model Risk, Privacy, Security
First-line accountable owner: Financial Crime Operations Director

## 1. Scope Reviewed

- Use case: AML copilot drafts sourced investigation timelines and narrative suggestions for alert types A and B.
- Channel / user population: L2 AML analysts in the retail banking investigations queue.
- Automation boundary: The copilot cannot close alerts, change disposition, file SARs or send customer communications.
- Customer / employee / regulatory impact: Analyst productivity and case narrative quality; regulatory sensitivity through case record content.
- Model / RAG / agent / vendor components: Enterprise LLM gateway, approved AML procedure corpus, case timeline retriever, narrative drafting copilot.
- Evidence packet version: AML-COPILOT-REL-2026-06-30-v1.

## 2. Challenge Summary

| Area | Challenge position | Required condition or rationale |
|---|---|---|
| Risk tier and scope | conditional no objection | High-risk operational support is acceptable for pilot-to-production only because final disposition remains analyst-owned. |
| Control design | condition | Narrative evidence must bind each saved paragraph to source-span ids and analyst approval event. |
| Evidence sufficiency | condition | Current eval report is sufficient for common typologies but needs 30-case source-span sample before broad scale. |
| Operational readiness | no objection | SOP, reviewer training and fallback to manual narrative drafting are documented. |
| Change and incident readiness | condition | Material changes to AML corpus, prompt or narrative template must reopen release gate. |

## 3. Material Concerns

| Concern id | Concern | Severity | Gate impact | Suggested action |
|---|---|---|---|---|
| C-001 | Paragraph-level source-span evidence is incomplete for high-risk typology narratives. | high | conditional release only | Add event capture and produce 30-case source-span review sample. |
| C-002 | Material-change trigger for AML corpus updates is not reflected in ADR. | medium | condition | Update ADR with corpus, prompt and workflow materiality rules. |

## 4. Conditions for Proceeding

| Condition id | Condition | Owner | Due date | Closure evidence |
|---|---|---|---|---|
| CON-001 | Capture source ids, passage ids, analyst edit diff and approval event for every narrative saved to case record. | AML Copilot Product Owner | 2026-07-15 | Event extract, 30-case sample workbook, reviewer sign-off. |
| CON-002 | Update ADR with material-change triggers for corpus, prompt, workflow and vendor gateway changes. | Product Architect | 2026-07-10 | Approved ADR-AML-COPILOT-004. |

## 5. Residual Concerns and Review Triggers

- Residual concern: Analysts may over-rely on fluent narrative drafts despite source support.
- Review trigger: Source-span error above 2% in monthly sample, any unsupported SAR-related phrase, or material corpus update.
- Escalation trigger: Any production narrative saved without source-span event.

## 6. Challenge Position

Final position: conditional no objection for controlled production release, no broad scale until CON-001 and CON-002 close.

Summary view:

FieldAML copilot release example
ConcernDraft investigation narrative lacks paragraph-level source-span evidence for high-risk typologies.
SeverityHigh
Gate impactConditional go for pilot only; production release blocked until evidence is available.
ConditionEvery saved narrative must capture source ids, analyst edit diff and approval event for a 30-case sample.
Closure evidenceEvent extract, sample review workbook and updated ADR showing evidence collector design.

7. Template: Issue / Action Log

FieldDescriptionExample
Issue idUnique issue identifierISS-KYC-2026-014
Use case / gateAI use case and lifecycle gateKYC onboarding / pilot
Issue typeevidence gap, control design gap, operation failure, policy deviation, unresolved challenge, issue aging, repeat findingcontrol design gap
Issue statementSpecific problem, not vague risk languageMissing-info email draft can be sent without reviewer approval in edge case path
Severitycritical, high, medium, lowhigh
Gate impactblocker, condition, monitor, accepted risk, escalateblocker
Root cause hypothesisWhy it existsworkflow branch bypassed approval state
Action statementConcrete management actionAdd approval state check before send event and negative test for all branches
Action ownerNamed roleKYC product owner
Due dateDate2026-07-10
Acceptance criteriaTestable closure rule100% negative tests block unapproved send; sample trace shows approval event before send
Closure evidenceEvidence requiredtest report, trace sample, ADR update
Second-line viewchallenge / closure opinionCompliance confirms approval path is sufficient
Escalation triggerWhen to escalateoverdue by 7 days or any production bypass
Statusopen, in progress, ready for review, closed, reopened, escalatedin progress

Issue severity guide:

SeverityDefinitionTypical action
CriticalCustomer harm, regulatory breach, unauthorized write action or severe evidence failure likely or observedstop, rollback, executive escalation
HighMaterial control gap or unresolved second-line objection for high-risk use caserelease blocker or conditional pilot only
MediumControl or evidence gap with compensating control and limited exposureconditional release with due date
LowDocumentation, clarity or low-risk evidence improvementtrack to next gate

8. Template: Assurance Packet

Assurance packet is the minimum set of artifacts that lets reviewers understand what was decided, on what evidence, by whom, with which issues and review triggers.

SectionRequired contentOwner
Cover pageuse case id, gate, date, decision, accountable owner, evidence packet versionGovernance lead
Scope and boundarybusiness objective, user group, data, model, RAG, agent, tool, vendor, automation boundaryPM / architect
Three-lines role mapfirst-line owners, second-line challenge owners, third-line assurance roleGovernance lead
Architecture viewcontext diagram, policy decision points, evidence collector, issue route, fallbackProduct architect / EA
Control matrixcontrol objective, activity, owner, evidence, frequency, failure conditionControl owners
Eval / test summarytest scope, thresholds, failures, defect disposition, unresolved limitsAI platform / delivery
Challenge memosecond-line position, objections, conditions, residual concernsSecond line owners
Issue/action logblocker, condition, accepted issue, action status and agingGovernance lead
Gate decision recorddecision, rationale, conditions, review triggers, escalation pathFirst line owner + governance lead
ADRarchitecture decision, tradeoffs, consequences, review triggersArchitect
Operating evidence planpost-release evidence cadence, issue review cadence, scale criteriaOperations owner

Quality bar:

  • Every claim in executive narrative links to evidence.
  • Every material issue has owner, due date and acceptance criteria.
  • Every conditional go has explicit follow-up forum or review date.
  • Every architecture tradeoff appears in an ADR.
  • Every high-risk action has policy and evidence route.

9. Template: Escalation Path

TriggerFirst responseEscalation ownerDecision authorityEvidence required
Release blocker unresolvedHold gate or reduce scopeGovernance leadBusiness sponsor + risk acceptance authorityblocker issue, impact, options
First / second line disagreementDocument positions and optionsGovernance chairDelegated executive / risk committeedecision memo, challenge memo
Conditional action overdueNotify owner and sponsorGovernance officePortfolio governance / sponsoraction aging report
Production control failurePause affected function or activate fallbackIncident commanderIncident management authorityincident record, trace, customer impact
Repeat issue across use casesCreate platform standard candidateEnterprise architectArchitecture review boardtrend, root cause, proposed standard
Vendor material changeFreeze change or restrict useVendor owner / TPRMThird-party risk authority + sponsorvendor notice, impact analysis
Audit finding overdueFollow audit issue routeManagement action ownerAudit issue governanceaction status, closure evidence

Escalation decision memo:

FieldContent
Decision requiredgo, no-go, reduce scope, accept risk, extend due date, pause, rollback
Optionsoption A / B / C with benefit, risk and operational impact
First-line positionaccountable owner recommendation
Second-line positionno objection, condition, objection or escalation rationale
Assurance considerationrelevant audit finding or assurance concern, if any
Evidencepacket ids, issue ids, ADR ids
Final decisionselected option, owner, expiry, review trigger

10. PM / BA / Architecture Questions

PM Questions

QuestionStrong answer should include
Who owns the business outcome and residual-risk proposal?Named first-line owner and delegated decision authority
Which lifecycle gate are we at?Intake, design, pilot, release, scale, change, incident or retire
What is the AI allowed and not allowed to do?Automation boundary, prohibited actions and human workflow
What evidence proves value and control readiness together?KPI, KRI, KCI and evidence packet links
What happens if second line objects?Escalation path and decision authority
What conditions can we accept without weakening control?Action owner, due date, acceptance criteria and review trigger

BA Questions

QuestionStrong answer should include
What claims must be verifiable at the gate?Claim-to-control-to-evidence mapping
Which process states create control evidence?Workflow state model, event dictionary and evidence owner
Which exceptions are allowed and how are they closed?Exception taxonomy, owner, expiry and compensating control
How is issue severity determined?Gate impact, customer impact, policy deviation and evidence failure criteria
What is the minimum sufficient evidence packet?Artifact list with owners and version ids
How are management actions tested before closure?Acceptance criteria and closure evidence

Architecture Questions

QuestionStrong answer should include
Where are policy decisions enforced?Policy decision point, enforcement point and decision log
Where is evidence generated by design?Trace store, evidence collector, event schema and retention tags
How do RAG / agent / copilot components map to controls?Source inventory, tool registry, approval binding and UX state
Which architecture changes reopen the gate?Model, prompt, RAG corpus, tool permission, vendor, automation and workflow materiality
How do issues become platform improvements?Repeat issue trend, reference architecture standard and ADR
How can audit or independent reviewers query evidence without joining delivery tools manually?Evidence packet index, access control and query path

11. Release Checklist

Use this as a gate-entry checklist. A release meeting should not begin until the required items exist.

CheckPass criteriaGate-entry signal
Use case registeredAI inventory record has owner, scope, risk tier and automation boundaryMissing record defers forum
Three-lines role map completeFirst-line owner, second-line challenge owners and third-line role are documentedMissing owner blocks gate
Decision authority confirmedGate decision owner and escalation authority are knownMissing authority escalates before forum
Architecture view completeRAG / agent / copilot / policy / evidence / issue route are shownMissing view blocks architecture approval
Control matrix completeEach material control has owner, activity, evidence, frequency and failure conditionMissing material control blocks release
Eval and test evidence readyThresholds, failures and defect disposition are documentedUnresolved high-risk failure blocks release
Evidence packet indexedEvidence ids and versions are linked to claims and controlsUnindexed evidence returns to owner
Challenge memo completeSecond-line position, conditions and objections are documentedMissing memo limits gate to design discussion
Issue/action log currentBlockers, conditions, accepted issues and overdue actions are visibleUnknown blockers defer decision
Operational readiness confirmedSOP, training, support, fallback and escalation are readyMissing readiness reduces scope or blocks
ADR updatedMaterial tradeoffs, decision and review triggers recordedMissing ADR blocks architecture sign-off
Material change rule definedModel, prompt, RAG, tool, vendor and scope changes trigger reviewMissing rule blocks scale
Post-release cadence setEvidence, issue, quality and scale review cadence definedMissing cadence turns go into no-go

No-go signals:

  • No named first-line owner.
  • Second-line objection unresolved and not escalated.
  • Critical or high blocker lacks closure plan.
  • Evidence packet cannot support the proposed gate decision.
  • Architecture lacks evidence capture for material control.
  • Conditional go has no owner, due date or closure evidence.
  • Internal audit is being asked to approve release.

12. Executive Narrative

Use this narrative for steering committee or portfolio review. Keep the wording factual and avoid saying "risk approved."

We are requesting conditional go for the AML copilot at the release gate.

The first-line accountable owner is the Financial Crime Operations Director, who owns the business outcome, operational process, control operation and residual-risk proposal. The use case is limited to L2 analyst support for alert types A and B. The AI is not permitted to close alerts, change disposition, file SARs or send customer communications.

The release packet includes the AML copilot architecture view, control matrix, eval/test evidence, second-line challenge memo, issue/action log and ADR-AML-COPILOT-004. Second-line functions reviewed the packet and recorded conditional no objection. The material conditions are paragraph-level source-span evidence for saved narratives and an ADR update for corpus, prompt, workflow and vendor material-change triggers, each with owner, due date and closure evidence.

The main value case is reduced narrative preparation time and improved case evidence consistency. The main risk/control considerations are unsupported narrative claims, analyst over-reliance and material corpus change. Open issues are classified as two release conditions and no unresolved blocker. The decision requested is conditional production release for the defined population, with review triggers for corpus update, prompt change, vendor gateway change, source-span sample failure, incident signal or scale request.

Internal audit is not approving this release. The use case will be visible to audit for future assurance planning because it affects financial crime case records.

Scenario-specific examples:

Use caseExecutive narrative emphasis
GenAI contact centerInternal agent-assist scope, regulated content escalation, transcript evidence and quality sampling
AML copilotAnalyst-owned final disposition, source-span narrative evidence and typology coverage
Credit decision supportDecision-support boundary, policy consistency and adverse-action / fairness challenge route
KYC onboardingHuman review for rejection, missing-info workflow, false reject / accept issue route
AI vendor modelData-use terms, model update notice, fallback and exit plan
Enterprise knowledge assistantApproved-source governance, entitlement-aware retrieval and sensitive-corpus restrictions

13. Interview Drills

Drill 1: Explain Three Lines for AI in 30 seconds

Good answer:

For AI, Three Lines governance means first-line product and operations teams own the business outcome, controls and residual-risk proposal; second-line risk and compliance teams challenge policy fit, control design and evidence sufficiency; third-line internal audit provides independent assurance and does not approve release. The practical architecture artifact is a lifecycle gate model with decision records, evidence packets, challenge memos, issue/action logs and ADRs.

Drill 2: What is the most common failure?

Good answer:

The most common failure is saying "risk signed off" without defining who owns the release decision and residual risk. That blurs accountability. I would separate first-line decision, second-line challenge position and third-line assurance role in the gate record, then bind the decision to exact evidence and issue dispositions.

Drill 3: How would you apply this to an AML copilot?

Good answer:

The first line is financial crime operations, which owns analyst workflow, narrative quality and final disposition. Second line financial crime compliance challenges typology coverage, SAR boundary, source evidence and escalation rules. Internal audit does not approve release; it may later test whether governance and controls operated. The release packet should include source-span evidence for narratives, analyst approval events, issue/action log, eval coverage and an ADR stating the copilot cannot close alerts or file SARs.

Drill 4: How do you keep this from becoming bureaucracy?

Good answer:

I would make the model risk-tiered. Low-risk internal knowledge use gets a light gate. High-risk customer-impacting, credit, AML, KYC or agentic tool-use scenarios get full evidence forum and challenge memo. The key is reusable platform evidence: policy decision logs, trace events, control matrix templates and ADRs. That reduces meeting load while improving assurance readiness.

Drill 5: What would you ask the CTO to fund?

Good answer:

I would ask for an enterprise AI governance control plane: AI inventory, policy decision logging, evidence collector, trace store, issue/action register, ADR integration and material-change detection for model, prompt, RAG corpus, tools and vendor dependencies. This turns Three Lines from manual committee work into platform-supported governance.

14. Source Anchors

SourceOfficial linkExecution translation
IIA Three Lines Modelhttps://www.theiia.org/en/content/position-papers/2020/the-iias-three-lines-model-an-update-of-the-three-lines-of-defense/Separate management ownership, risk/compliance challenge and internal audit assurance.
Basel Committee Corporate Governance Principles for Bankshttps://www.bis.org/bcbs/publ/d328.htmAlign AI governance with banking governance, risk management, control environment and internal audit expectations.
COSO Internal Control Overviewhttps://www.coso.org/guidance-on-icTranslate AI controls into control environment, risk assessment, control activities, information/communication and monitoring language.
NIST AI Risk Management Frameworkhttps://www.nist.gov/itl/ai-risk-management-frameworkUse Govern / Map / Measure / Manage to structure AI risk lifecycle and management action.
ISO/IEC 42001 AI Management Systemhttps://www.iso.org/standard/81230.htmlTreat AI governance as a management system with scope, operation, performance evaluation and improvement.
ISO/IEC 23894 AI Risk Managementhttps://www.iso.org/standard/77304.htmlAnchor AI risk management, treatment and review vocabulary.