Learning path · Enterprise Patterns & Governance · 89
AI Governance
Policies, roles, and review boards governing model selection, data use, eval evidence, and incident response.
Why it matters
- Required for regulated industries and enterprise procurement.
- Clarifies who approves new tools and datasets.
- Connects red teaming and evals to release gates.
Key ideas
- Risk tiers
- Approval workflows
- Model inventory
Top resources
- 01DocsNIST
AI Risk Management Framework
Why this resource. The framework most enterprise AI policies now cite.
Covers in this concept
- govern
- map
- measure
- manage
- 02DocsOWASP
OWASP Top 10 for LLM Applications
Why this resource. Technical risks the board pack should name in engineer language.
Covers in this concept
- LLM threats
AI governance maintains model inventories, risk classifications, and documentation for auditors—intended use, eval results, known failures. High-risk features pass legal and security review with rollback plans. Incidents trigger root cause across data, prompts, and tools—not blame on a single engineer. Maintain a living risk register linking models, datasets, and incidents so audit questions do not require archaeology across Slack. Link governance tickets to model versions and dataset hashes for reproducible audits.
Updated 2026-08-09 · Full learning path