| name | responsible-aipom-governance-advisor |
| description | Diagnose the most consequential missing AI governance condition across ownership, authority, controls, escalation, oversight, and trust evidence; recommend the next motion. |
| type | interactive |
| category | governance-and-accountability |
| phase | 1 |
| status | active |
| operating_level | ["organization","portfolio","product-team","initiative"] |
| audience | ["CPO","CTO","Product Operations","Product Manager","Team Lead","Legal","Privacy","Security","Risk","AI Governance"] |
| best_for | ["Preparing consequential AI work","Resolving policy-practice gaps","Choosing a practical governance intervention"] |
| evidence_required | ["Decision and accountability records","AI actions and consequences","Control and incident evidence","Applicable obligations and policies"] |
| produces | ["Governance posture diagnosis","Critical gap and constrained decisions","Recommended control motion and owner"] |
| assessment_questions | ["GOV-01","GOV-02","GOV-03","GOV-04","GOV-05"] |
| maturity_move | {"from":"emerging","to":"repeatable"} |
| estimated_time | 45-75 min |
| group_size | 3-10 |
| depends_on | [] |
| combine_with | ["aipom-accountability-charter","aipom-autonomy-boundary-designer","aipom-risk-control-incident-playbook"] |
| sources | ["https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10","https://oecd.ai/en/dashboards/ai-principles/P9","https://eur-lex.europa.eu/eli/reg/2024/1689/oj"] |
Responsible AIPOM Governance Advisor
What Is It
Diagnose which governance condition most constrains responsible value: ownership, decision rights, autonomy, controls, escalation, cross-functional review, or trust evidence. Recommend a practical next intervention.
Why Use It
Principles and committees do not govern behavior by themselves. Governance becomes operational when named people make decisions through usable controls with evidence, escalation, and learning.
When to Use It
Use before launch or increased autonomy, after incidents, when governance slows work without clarifying decisions, or when policy and product-team practice diverge.
What It Produces
- Evidence-based governance diagnosis
- Critical gaps and constrained actions
- Policy-practice disagreements
- Recommended component skill, owner, and evidence plan
Who Should Participate
Include the accountable product or business owner, Product Manager, technical owner, operators, and legal, privacy, security, safety, risk, or governance partners proportionate to the context.
Evidence to Bring
Bring real approvals, actions, permissions, policies, control tests, exceptions, incidents, audit evidence, complaints, and examples of escalation or rollback.
How to Do It
- Define scope, operating level, affected people, and decision.
- Extract owners, AI actions, consequences, obligations, controls, and evidence.
- Diagnose ownership, authority, control, escalation, review, and assurance gaps.
- Separate legal requirements from recommended practice and flag jurisdiction.
- Identify any critical gap that constrains launch, scale, data use, or autonomy.
- Present intervention options and recommend the smallest effective motion.
- Assign a human owner, evidence expected, and review trigger.
Facilitation Protocol
Support guided, context-dump, and best-guess modes. Ask one consequential question at a time. Preserve legal, leadership, and practitioner disagreement. Do not infer compliance from missing evidence.
Decision Logic
- Use an accountability charter when decision rights and owners are unclear.
- Use an autonomy boundary when AI action authority is unclear.
- Use a behavior contract when acceptable conduct is undefined.
- Use a risk-control incident playbook when detection, rollback, or response is weak.
- Use a trust assurance pack when evidence exists but cannot be communicated or reviewed.
- Pause the constrained action when a non-negotiable condition is unresolved.
Completion Criteria
Finish with scope, requirements versus recommendations, evidence, critical gaps, constrained decisions, intervention, human owner, escalation, and unresolved specialist questions.
Key Concepts
- Human accountability remains human.
- Governance should be proportionate to consequence and evidence.
- A policy is not proof of control operation.
- Trust evidence must be inspectable and current.
Organizational Applications
Use for agent launches, sensitive decisions, vendor systems, portfolio standards, incidents, and governance operating-model redesign.
Common Pitfalls
- Treating a committee as an owner
- Applying one control level to all uses
- Calling documentation compliance
- Designing review without operator authority or capacity
- Averaging away a critical gap
- Presenting legal guidance without jurisdiction or counsel
Combine With
Route to the accountability, autonomy, behavior, incident, or assurance component that matches the root condition.
Assets and Templates
Sources
- NIST, AI RMF 1.0, January 26, 2023. Supports organizational governance and lifecycle risk management. Accessed July 16, 2026.
- OECD.AI, Accountability Principle. Supports role-based accountability, traceability, and ongoing risk management. Accessed July 16, 2026.
- European Union, Regulation (EU) 2024/1689. Supports risk-proportionate human oversight for covered high-risk systems. Accessed July 16, 2026. This advisor is not legal advice and does not establish compliance.