Skip to main content

Governance Operating: Four Questions, One Control System

Governance · Operating · Runtime →

This is the estate operating model for G.A.I.N Governance. Principles live in G.A.I.N Governance. Same domain, other view: Runtime (PGAR on the request path).

THE CLAIM

AI Governance is how we ensure it. Responsible AI defines outcomes. Regulatory AI defines obligations. AI Risk names what can go wrong. This blueprint is the control system across the estate: policy, inventory, approval, owners, monitoring, and evidence. It is not PEP/PDP.

Two views, one domain

ViewQuestionAudienceBlueprint
Operating (this page)How do we ensure it across the estate?Exec, risk, compliance, enterprise architectsYou are here
RuntimeHow does one request stay governed on the path?Platform, security/IAM, SREGovernance Runtime

Do not split these into two G.A.I.N subjects. G.A.I.N AIOM still answers who owns which plane. This page answers which control capabilities those owners must run.

Layer model

Should we? → Responsible AI (outcomes)
Must we? → Regulatory AI (obligations)
What can go wrong? → AI Risk (threats and residual risk)
How do we ensure it? → AI Governance (this operating model)

Staff Responsible, Regulatory, and Risk as sibling workstreams under Governance. Do not merge them into one slogan.

Capability tree

AI Governance
├── AI Strategy & Policy
├── AI Risk Management
├── Responsible AI
│ ├── Ethical · Accountable · Transparent · Explainable · Trustworthy
├── Regulatory Compliance
├── Model / AI Lifecycle Governance
├── Security & Privacy
├── Human Oversight
├── Controls & Guardrails
├── Monitoring & Assurance
└── Audit & Evidence

CapabilityEnsuresTypical owner
Strategy and policyIntentional use; banned uses; appetiteAI Governance lead + exec sponsor
Risk managementThreats known, treated, residual acceptedRisk
Responsible AIOutcomes match values and harm boundariesEthics + product + risk
Regulatory complianceObligation register mapped to controlsLegal / Compliance
LifecycleInventory, change, retirementAI Platform
Security and privacyAttack surface and data dutiesSecurity + Privacy
Human oversightHITL where risk demandsProduct + Risk
Controls and guardrailsRuntime enforcementAI Platform (Runtime)
Monitoring and assuranceDrift, quality, control healthPlatform + Risk
Audit and evidenceReconstructable decisionsCompliance + Platform

Control path

Every use case travels the same path. Runtime is one stage, not a second governance.


  • Approve before scale: no inventory, no owner, no go-live.
  • Runtime stage: Runtime blueprint and Runtime playbooks.
  • Evidence is continuous: not a binder assembled for the auditor visit.

Bank example: refund agent

LensOperating model forces the question
ResponsibleFair treatment, named owners, explainability
RegulatoryWhich obligations apply, and what proof?
RiskFraud, bias, injection, drift: mitigate and accept residual on purpose
GovernanceInventory, approval, access, runtime guardrails, monitoring, escalation, evidence pack

Miss this page and you may have ethics slides and a policy PDF while the agent ships with no inventory entry. Miss Runtime and the agent has an inventory entry but no PEP on the tool path.

What this page is not

  • Not a second G.A.I.N subject
  • Not org-chart design (AIOM)
  • Not PEP, SARAC, or five trust boundaries (Runtime)
  • Operating how-to: Operating playbooks (inventory, obligation map, evidence pack)
ResourceUse when
G.A.I.N GovernancePrinciples and G · A · I · N mapping
G.A.I.N AIOMWho owns application, control, runtime, knowledge planes
Governance blueprintsTwo views, one subject
RuntimeFive boundaries, SARAC, three verdicts
Operating playbooksInventory, obligation map, evidence pack
Runtime playbooksFoundation, assurance, boundary