The context

This institution had twelve AI systems in various stages of development when the engagement began. Two were in production. Four were in extended pilot. Six were in development. The approval process for moving any system from pilot to production had no defined path, and the typical time from “pilot complete” to “production approved” was fourteen weeks, mostly spent waiting for ad-hoc committee reviews with no clear decision authority.

The brief was to design a governance framework that would get the institution’s AI systems to production faster, with demonstrably lower risk.

The framework design

The framework starts with a risk classification. Every AI system is classified as Tier 1, Tier 2 or Tier 3 based on four factors: the directness of customer impact, the reversibility of the system’s decisions, the regulatory exposure, and the volume of decisions made.

Tier 1 systems (low impact, fully reversible, no regulatory exposure, low volume) require sign-off from the business unit head only. Approval time target: two weeks.

Tier 2 systems (moderate impact, partially reversible, limited regulatory exposure) require sign-off from the business unit head and the chief risk officer. Approval time target: four weeks. A documented human oversight mechanism is required.

Tier 3 systems (customer-facing decisions with material impact, significant regulatory exposure, high volume) require sign-off from the chief risk officer, the general counsel and the CEO. Approval time target: eight weeks. An external review by a qualified AI risk auditor is required before sign-off.

The framework also defines a review cadence. Tier 1 systems are reviewed annually. Tier 2 systems are reviewed semi-annually. Tier 3 systems are reviewed quarterly. Review triggers additional to the cadence include: a significant model update, a material change in decision volume, a post-incident finding, or a change in applicable regulation.

What made it work

The framework’s effectiveness came from two design decisions that are not obvious in the abstract.

Single named owner for every system. Every AI system has a named business owner who is personally accountable for the system’s outputs. The owner is not the AI team. It is the business leader whose function benefits from the system. This single decision eliminated the accountability vacuum that had been producing fourteen-week approval delays: most of those delays were spent resolving questions about who was responsible for the decision.

Pre-approval templates. For each tier, we produced a standard documentation template that a team must complete before seeking approval. The templates define exactly what information the approver needs, in a format designed for the approver’s role. A Tier 1 submission template takes a business analyst four hours to complete. A Tier 3 submission template takes two weeks and involves the AI team, legal, risk and the business unit. The templates replaced the ad-hoc document requests that were eating most of the approval time.

The outcome

Twelve months after framework implementation: average approval time for Tier 1 and Tier 2 systems is six weeks, down from fourteen. All four systems that were in extended pilot at framework launch have reached production. Three of the six systems in development have been reclassified as Tier 1 and are on track for approval. One system was classified as Tier 3 and is currently in the eight-week approval process.

The chief risk officer’s assessment at the twelve-month review: “We now know which AI systems we have, who owns them, and what to do when one of them goes wrong. We did not know any of those things before.”

What I would do differently

The risk classification needed more nuance in the Tier 2 category. Several systems that were classified as Tier 2 had characteristics (particularly around explainability requirements) that made them closer to Tier 3 in regulatory exposure. A four-tier classification would have been more accurate, at the cost of more complexity.

I would also have pushed harder for the AI team’s role to be defined in the framework. The framework defines business ownership clearly, but the boundary between “the AI team’s responsibility” and “the business owner’s responsibility” was left ambiguous and produced friction in practice.