Lesson 6 · AI Governance Basics
Practical governance scenario and knowledge check
- Length
- 29 minutes across 7 sections
- You will be able to apply
- The Governance Walk
- You will produce
- Draft the first version of your governance walk record · Live-Control Assurance Brief · Commit Statement
- You will work
- 3 gated questions
Personalize the practice
Apply this to your environment
These details adapt the application prompts and coach questions. They do not affect your score.
Governance is what happens on the day nobody is watching.
Core question
workbench
Draft the first version of your governance walk record
Required practiceBefore you see the worked walkthrough, open a live-control assurance record for the OmniCorp system you would least like an external reviewer to pick. Write the first version now, while the evidence is still incomplete.
Graduate practice
Signature experience outcomes
- Integrate accountability, risk tiering, approved-use, and escalation controls into one assurance judgment.
- Differentiate control design from evidence that a control operates under pressure.
- Adjudicate conflicting stakeholder claims using named evidence.
- Produce a testable remediation sequence with owners and dates.
Five instruments so far. The Single Name Test locates accountability. The Refusal Test tells you which principles are real. The Approved Route keeps data where it belongs. The Highest Dimension gives an honest tier. Recognise, Contain, Preserve, Escalate handles failure. Each was taught against one system. This lesson runs all five against one system, in order, and then asks the question that decides whether any of it matters.
That question is not whether the controls exist. It is whether they have ever been observed operating when nobody was preparing for a review.
The pathology: Paper Governance
An organisation with mature-looking governance has a register, tiering criteria, a policy, an incident process and named owners. All of it is real. None of it has been exercised. The register was populated in a workshop and has not been reconciled against reality since. The incident process has never received an entry. The named owners were assigned by a spreadsheet.
The counter is to test each instrument by its traffic rather than its existence.
The control exists on a register but nothing has ever passed through it and no date attaches.
- Decorative
- The control exists on a register but nothing has ever passed through it and no date attaches.
- Operating
- The control has traffic: a question answered, a refusal dated, a request processed, a tier revised.
The Governance Walk
Definition
Take one live AI system and walk the five instruments in order, asking of each not whether it exists but what has passed through it. A name that has never been asked a question. A principle that has never refused anything. A route whose request lane has never received a request. A tier that has never been revised. An incident process with no entries. Five instruments, five traffic questions, and the answer you are looking for is a date.
The walk takes about an hour and produces a list of the instruments that are decorative. That list is the finding. A control with no traffic is not evidence of a quiet environment: it is an unread sensor.
When to Use It
Walk one system a quarter, choosing the one that would be most embarrassing to have examined by someone else. Walk any system before it is cited externally as evidence of your governance, because citing an untested control is how a defensible position becomes an indefensible one.
Walk it also after any reorganisation. Every instrument in the set depends on a person, and people move.
How to Apply It
- Ask the named owner a real question, cold, and record how many escalations it took to answer.
- Ask which principle has refused something on this system, with a date and a cost.
- Check the request lane's last entry and its actual turnaround, not its published one.
- Check when the tier was last revised and what triggered it, then check the incident log for near misses.
| Instrument | Decorative when | Operating when |
|---|---|---|
| Single Name Test | A name exists on the register | That person has been asked and answered without escalating |
| Refusal Test | Principles are published | A dated refusal with a stated cost attaches to this system |
| Approved Route | A policy names permitted tools | The request lane has recent traffic and a measured turnaround |
| Highest Dimension | A tier was assigned at launch | The tier has been revised, with the trigger recorded |
| Recognise to Escalate | An incident process is documented | Near misses are being logged by people who fixed them |
Worked example 1 of 3
Alan Brixmoor walked an OmniCorp Public correspondence system that had been cited in two external assurance returns.
- Alan Brixmoor
- Who is the named owner, and when were they last asked anything about it?
- Service manager
- It is me. Nobody has asked me anything about it since we went live.
- Alan Brixmoor
- Which principle has refused anything on this system?
- Service manager
- None that I know of.
- Alan Brixmoor
- Last entry in the request lane?
- Service manager
- There has never been one.
- Alan Brixmoor
- Incident log?
- Service manager
- Empty. Which I had been treating as good news.
Five instruments, one with traffic: the tier had been revised eight months earlier when volume rose. The other four were decorative, on a system already described externally as governed. Nothing had gone wrong. Nothing had been observed either.
Why This Works
Asking for traffic rather than existence removes the possibility of a satisfying answer that means nothing. Does this system have a named owner is answerable from a register in four seconds. When was that person last asked a question about it cannot be answered from a register at all, and the silence that follows is more informative than any document.
Walking five instruments together also exposes the dependency between them, which is invisible one at a time. An empty incident log usually means the request lane is unused, which usually means the route does not cover real work, which usually means the named owner has never been asked anything, because nobody is bringing them problems. The instruments fail as a set.
Worked example 2 of 3Optional depth
Marisa Delgado walked the OmniCorp Financial hardship pre-screening system and found the inverse pattern: four instruments with heavy traffic and one entirely dead. The named owner was asked things constantly, the tier had been revised twice, the request lane was busy, and near misses were logged weekly. No principle had ever refused anything on it. On examination, that was accurate rather than negligent, since nothing had yet been proposed that any principle would decline. She recorded it as untested rather than as passing, which is the honest state and the one that stops an untested control being cited as a working one.
Worked example 3 of 3Optional depth
Trevor Okafor walked an OmniCorp Retail description generator and found every instrument had traffic, which he initially read as a clean result. Reading the dates changed it: all the traffic clustered in the eight weeks after the fabricated-certification incident, and there had been nothing in the four months since. Governance that operates for two months after an incident and then stops is not a control, it is a reaction, and its traffic pattern is the shape of institutional memory decaying. He set a quarterly walk on that system specifically.
Edge Cases and NuancesOptional depth
A genuinely new system has no traffic and should be recorded as untested rather than decorative, with a date by which it will have been exercised. Traffic can also be manufactured, in the sense that a request lane fed by its own administrator to demonstrate use is not traffic. Some instruments legitimately have low volume: a refusal is a rare event, so an annual cadence is a fair standard where a monthly one is not. And a walk performed by the person who owns the system will find less than one performed by somebody else, which is the third condition of the Single Name Test reappearing at the level of the governance itself.
When was the named owner last asked a substantive question about this system?
- Single Name Test
- When was the named owner last asked a substantive question about this system?
- Refusal Test
- Which principle has refused something on this system, with a date and a cost?
- Approved Route
- When was the request lane last used, and what was the actual turnaround?
- Highest Dimension
- When was the tier last revised, and what triggered it?
- Recognise to Escalate
- Are near misses being logged by the people who fixed them?
Knowledge check
An organisation's incident log for an AI system has been empty for eighteen months. What does the Governance Walk conclude from this?
Common Failure Modes
The walk end to end
Dr. Naomi Ellery walked the OmniCorp Health referral pre-population system, the one she had spent eight weeks constructing ownership for two lessons earlier. She chose it because it was the system she would least like an external reviewer to choose.
Single Name Test: the clinical lead was the named owner and had been asked a substantive question eleven days earlier, which he had answered without escalating. Traffic. Refusal Test: the auto-send option had been declined at a cost of roughly forty clinician hours a month, dated. Traffic. Approved Route: the request lane had four entries in the quarter, one of which had produced a new route for a neighbouring team. Traffic.
Highest Dimension: the tier had been set at launch and never revised, despite referral volume roughly doubling. Decorative, and the same frozen-tier pattern that appears whenever growth is the trigger nobody watches. Recognise to Escalate: the log held two entries, both raised by the same clinician. Two entries from one person across a service of forty is not a working process, it is one conscientious individual.
Three operating, two failing, on the system she had personally rebuilt. Naomi's response was not to defend it. She set a volume-triggered re-tier, and for the incident log she did the only thing that reliably works: she asked six clinicians directly what they had quietly corrected in the last month, received nine answers, and logged all nine as near misses with their names attached and their permission. The log stopped being empty because somebody went and asked, which is the general form of the correction.
Decision point
Jo Halvorsen at OmniCorp Studio walks her own AI use and finds four of five instruments with no traffic. She is the named owner and nobody has ever asked her anything, no principle has refused anything this year, the request lane is her own message thread and has never been used by anyone but her, and there are no logged incidents. The tier has been revised once. The practice has eleven people and no governance function. What do you conclude, and what do you do?
Self-check
Mark the level that describes you today. Nothing is submitted.
| Behaviour | Ready | Developing | Not yet |
|---|---|---|---|
| Reading an empty control | |||
| Conducting the walk | |||
| Distinguishing untested from decorative |
Signature learning object
Live-Control Assurance Brief
Prepare an assurance brief for a skeptical executive. Use evidence from the Governance Walk, name dissent rather than averaging it away, and make a bounded decision. This is a portfolio-ready learning object, not a checklist of policy existence.
Commit
Commit Statement
Complete every line in your own words, then sign and date it. Attach your walk, including the instruments with no date against them.
| Window | Field application |
|---|---|
| Days 1 to 7 | Walk the five instruments against the system you would least like examined, and write a date or a blank against each. |
| Days 8 to 21 | Take the deadest instrument and generate real traffic through it by asking people rather than by writing a reminder. |
| Days 22 to 30 | Ask somebody who does not own the system to walk it, and compare their findings with yours. |
Five instruments and a quarterly walk are governance one person can run over the systems they can see. They do not give you a portfolio view, delegated decision rights that hold when functions disagree, independent assurance, evidence retention that survives a change of leadership, or an answer to a regulator asking who approved what and when. Turning a walk you can perform into an operating model an organisation can be held to is the capability the paid programs develop next.
Learner feedback