LEARNING PATH

Governance, Risk & Compliance

A structured learning path for governance, risk, compliance, legal and assurance professionals responsible for establishing oversight, managing AI-related risk and demonstrating that organisational controls operate in practice.

Clear governance. Proportionate controls. Credible assurance.

Explore the policies, responsibilities, controls and evidence required for responsible AI governance

Who Should Follow This Path?

This path is designed for professionals responsible for translating organisational expectations, regulatory requirements and recognised standards into effective governance, risk-management and assurance arrangements.

Governance Professionals

Risk Managers

Compliance & Legal Teams

Int. Audit and Assurance

Why This Matters

AI governance depends on more than policies and formal statements. Organisations need clear accountability, proportionate controls and reliable evidence that governance arrangements operate throughout the AI lifecycle.

Gold organisation chart icon showing connected governance roles, leadership responsibility and organisational oversight.

Governance Structure

Responsibilities, decision rights and escalation routes should remain clear across business, technical, legal and assurance functions.

Gold shield with control sliders and risk gauge representing AI risk management, control settings and governance oversight.

Risk Control

AI-related risks should be identified, assessed and managed in proportion to their potential impact and organisational context.

Gold checklist and verification badge icon representing audited evidence, compliance review and assurance.

Evidence and Assurance

Policies and controls should be supported by credible evidence that they are implemented, monitored and reviewed in practice.

Key Areas for Governance, Risk and Compliance

Governance and compliance professionals do not need to design AI models. They do need to understand how existing responsibilities, controls and assurance processes should respond when artificial intelligence is introduced into organisational activities.

01 Governance Roles and Accountability

Responsibility should be clearly allocated across governing bodies, executive leadership, business owners, technical teams and control functions.

02 Risk Classification and Proportionality

Different AI uses create different levels of potential impact and therefore require different levels of review, approval, control and monitoring.

03 Policy and Control Integration

AI governance should connect with existing risk, compliance, data protection, cybersecurity, procurement and operational-control arrangements.

04 Evidence and Auditability

Organisations should retain sufficient evidence to demonstrate how significant AI activities were assessed, approved, monitored and reviewed.

05 Regulatory and Standards Alignment

Applicable laws, regulatory expectations and recognised standards should inform governance decisions without being treated as interchangeable or universally applicable.

Warning Signs to Recognise

Governance weaknesses may remain hidden until an AI-related incident, audit, client request or regulatory challenge occurs. The following indicators may suggest that existing arrangements do not provide sufficient control or assurance.

01 ⚠️ Policy Without Operational Evidence

The organisation has published an AI policy but cannot demonstrate how its requirements are applied across actual systems, vendors and employee use.

02 ⚠️ Unclear Ownership

Responsibility is distributed across legal, IT, risk and business teams without a clearly accountable owner for significant AI uses.

03 ⚠️ Uniform Treatment of Different Risks

Low-impact productivity tools and higher-impact decision systems are subject to the same level of review, regardless of their potential consequences.

04 ⚠️ Fragmented Control Environment

AI-related controls operate separately from procurement, data protection, cybersecurity, operational risk and existing assurance processes.

05 ⚠️ Limited Vendor Oversight

AI suppliers are approved without sufficient understanding of data handling, system limitations, model changes, subcontractors or ongoing monitoring responsibilities.

06 ⚠️ Weak Audit Trail

The organisation cannot reliably reconstruct how an AI use was evaluated, approved, changed or monitored over time.

Questions Governance Professionals Should Be Asking

Effective governance begins with questions that test whether responsibilities, controls and evidence are sufficiently clear, proportionate and integrated into normal organisational practice.

1. Which AI uses require formal governance attention?

Governance teams should have a credible basis for distinguishing routine, lower-impact uses from activities that may materially affect people, customers, safety, legal obligations, finances or organisational reputation.

2. Who is accountable for each material AI use?

Accountability should remain clear across the full lifecycle, including procurement, development, deployment, operational use, change and retirement. Technical ownership alone does not establish business accountability.

3. Are AI-related risks integrated into existing risk-management processes?

AI risks should not be managed through an isolated process where established mechanisms for enterprise risk, operational risk, information security, privacy and compliance are already relevant.

4. What evidence demonstrates that controls operate in practice?

Policies, committee minutes and management assurances should be supported by evidence of assessment, approval, review, monitoring, training, incident management and corrective action where appropriate.

5. How are third-party AI risks being addressed?

Organisations should understand how vendors handle data, manage model changes, communicate limitations, use subcontractors and support ongoing oversight throughout the commercial relationship.

6. How are regulatory and standards developments being monitored?

Applicable obligations and recognised practices may evolve over time. Governance arrangements should include responsibility for identifying relevant changes and assessing their organisational implications.

7. Can the organisation explain its AI governance approach externally?

Clients, regulators, auditors, investors and other stakeholders may request evidence of responsible AI governance. The organisation should be able to explain its approach clearly and support its statements with credible evidence.

What Effective Governance, Risk and Compliance Looks Like

Effective governance creates clear responsibility, proportionate control and credible assurance without unnecessarily preventing responsible innovation.

Effective AI governance is demonstrated through accountable decisions, integrated controls and verifiable evidence, not through policy documentation alone.

01 Clear Accountability

Significant AI uses have identified owners who understand and accept responsibility for their purpose, risks, controls and outcomes.

02 Proportionate Governance

The intensity of review, approval and monitoring reflects the potential impact and organisational context of each AI use.

03 Integrated Controls

AI governance is connected with existing legal, risk, compliance, data, security, procurement and operational processes.

04 Traceable Decisions

Important assessments, approvals, changes, exceptions and incidents are documented sufficiently to support review and accountability.

05 Credible Assurance

Leadership confidence is supported by evidence that controls are implemented, monitored and improved where weaknesses are identified.

06 Continuing Regulatory Awareness

Relevant legal, regulatory and standards developments are monitored and assessed for their impact on organisational governance arrangements.

From Awareness to Organisational Action

This learning path provides role-specific guidance to support informed discussion, stronger oversight and better decisions around artificial intelligence. Effective AI governance requires an organisation-specific understanding of objectives, risks, responsibilities, existing controls and operating conditions.

Need Support Applying This to Your Organisation?

AGP helps organisations translate AI governance principles into a practical and proportionate approach aligned with their activities, risk profile and level of AI adoption.