A structured learning path for governance, risk, compliance, legal and assurance professionals responsible for establishing oversight, managing AI-related risk and demonstrating that organisational controls operate in practice.

Clear governance. Proportionate controls. Credible assurance.


This path is designed for professionals responsible for translating organisational expectations, regulatory requirements and recognised standards into effective governance, risk-management and assurance arrangements.
AI governance depends on more than policies and formal statements. Organisations need clear accountability, proportionate controls and reliable evidence that governance arrangements operate throughout the AI lifecycle.

Responsibilities, decision rights and escalation routes should remain clear across business, technical, legal and assurance functions.

AI-related risks should be identified, assessed and managed in proportion to their potential impact and organisational context.

Policies and controls should be supported by credible evidence that they are implemented, monitored and reviewed in practice.
Governance and compliance professionals do not need to design AI models. They do need to understand how existing responsibilities, controls and assurance processes should respond when artificial intelligence is introduced into organisational activities.
Responsibility should be clearly allocated across governing bodies, executive leadership, business owners, technical teams and control functions.
Different AI uses create different levels of potential impact and therefore require different levels of review, approval, control and monitoring.
AI governance should connect with existing risk, compliance, data protection, cybersecurity, procurement and operational-control arrangements.
Organisations should retain sufficient evidence to demonstrate how significant AI activities were assessed, approved, monitored and reviewed.
Applicable laws, regulatory expectations and recognised standards should inform governance decisions without being treated as interchangeable or universally applicable.
Governance weaknesses may remain hidden until an AI-related incident, audit, client request or regulatory challenge occurs. The following indicators may suggest that existing arrangements do not provide sufficient control or assurance.
01 ⚠️ Policy Without Operational Evidence
The organisation has published an AI policy but cannot demonstrate how its requirements are applied across actual systems, vendors and employee use.
02 ⚠️ Unclear Ownership
Responsibility is distributed across legal, IT, risk and business teams without a clearly accountable owner for significant AI uses.
03 ⚠️ Uniform Treatment of Different Risks
Low-impact productivity tools and higher-impact decision systems are subject to the same level of review, regardless of their potential consequences.
04 ⚠️ Fragmented Control Environment
AI-related controls operate separately from procurement, data protection, cybersecurity, operational risk and existing assurance processes.
05 ⚠️ Limited Vendor Oversight
AI suppliers are approved without sufficient understanding of data handling, system limitations, model changes, subcontractors or ongoing monitoring responsibilities.
06 ⚠️ Weak Audit Trail
The organisation cannot reliably reconstruct how an AI use was evaluated, approved, changed or monitored over time.
Effective governance begins with questions that test whether responsibilities, controls and evidence are sufficiently clear, proportionate and integrated into normal organisational practice.
Governance teams should have a credible basis for distinguishing routine, lower-impact uses from activities that may materially affect people, customers, safety, legal obligations, finances or organisational reputation.
Accountability should remain clear across the full lifecycle, including procurement, development, deployment, operational use, change and retirement. Technical ownership alone does not establish business accountability.
AI risks should not be managed through an isolated process where established mechanisms for enterprise risk, operational risk, information security, privacy and compliance are already relevant.
Policies, committee minutes and management assurances should be supported by evidence of assessment, approval, review, monitoring, training, incident management and corrective action where appropriate.
Organisations should understand how vendors handle data, manage model changes, communicate limitations, use subcontractors and support ongoing oversight throughout the commercial relationship.
Applicable obligations and recognised practices may evolve over time. Governance arrangements should include responsibility for identifying relevant changes and assessing their organisational implications.
Clients, regulators, auditors, investors and other stakeholders may request evidence of responsible AI governance. The organisation should be able to explain its approach clearly and support its statements with credible evidence.
Effective governance creates clear responsibility, proportionate control and credible assurance without unnecessarily preventing responsible innovation.
Effective AI governance is demonstrated through accountable decisions, integrated controls and verifiable evidence, not through policy documentation alone.
Significant AI uses have identified owners who understand and accept responsibility for their purpose, risks, controls and outcomes.
The intensity of review, approval and monitoring reflects the potential impact and organisational context of each AI use.
AI governance is connected with existing legal, risk, compliance, data, security, procurement and operational processes.
Important assessments, approvals, changes, exceptions and incidents are documented sufficiently to support review and accountability.
Leadership confidence is supported by evidence that controls are implemented, monitored and improved where weaknesses are identified.
Relevant legal, regulatory and standards developments are monitored and assessed for their impact on organisational governance arrangements.
This learning path provides role-specific guidance to support informed discussion, stronger oversight and better decisions around artificial intelligence. Effective AI governance requires an organisation-specific understanding of objectives, risks, responsibilities, existing controls and operating conditions.
AGP helps organisations translate AI governance principles into a practical and proportionate approach aligned with their activities, risk profile and level of AI adoption.