Sheet 06
Governance rhythm
Governance is mostly a calendar problem. Most of the delay in a review is waiting for a meeting, not thinking — so the meetings are scheduled in advance, the agendas are standing, and the material goes out five business days ahead. What is left is the part that genuinely requires judgment.
The rhythm
Six cadences, weekly through annual. Each one names what goes into it, what comes out, what gets decided there, and where it escalates when the decision belongs somewhere else.
- CAD-01
Weekly intake triage
- Frequency
- Weekly, 30 minutes
- Chaired by
- AI Program Manager
- Escalates to
- Structured review, or the governance committee for elevated requests
Who is there
- AI Program Manager
- IT & Security representative
- Risk representative on call
What goes in
- New intake submissions
- Requests returned for clarification
- Anything escalated during the week
What comes out
- Pathway assignment with recorded reasons
- Clarifying questions sent back same day
- Review scheduling
What is decided here
- Which pathway a request enters
- Whether a request is complete enough to review
- What guidance answers a standard request without further review
- CAD-02
Biweekly pilot check-in
- Frequency
- Every two weeks, 45 minutes
- Chaired by
- AI Program Manager
- Escalates to
- AI Governance Committee for anything changing scope, risk, or cost
Who is there
- Pilot business owners
- Program coordinator
- Functional reviewers as needed
What goes in
- Pilot status
- Measurement progress
- Blockers and dependencies
- Incidents and near-misses
What comes out
- Updated pilot records
- Escalations with named owners
- Confirmation that decision dates still hold
What is decided here
- Operational adjustments within approved scope
- Whether a dependency needs escalation
- Whether a pilot is drifting from its guardrails
- CAD-03
Monthly AI Governance Committee
- Frequency
- Monthly, 60 minutes
- Chaired by
- Director of Technology
- Escalates to
- Executive leadership for strategy, investment, and firmwide policy
Who is there
- Director of Technology
- Information Security
- Risk, Legal & Privacy
- People & Culture
- Data & Reporting
- Practice group representatives
- Finance & Procurement
- AI Program Manager (coordinator, not voting)
What goes in
- Material distributed five business days ahead
- Elevated-pathway use cases ready for decision
- Pilot outcome summaries and recommendations
- Exception requests and expiring exceptions
- Open action status
What comes out
- Decision records with reasoning and conditions
- Assigned actions with owners and dates
- Escalations to leadership
What is decided here
- Approval to pilot for elevated use cases
- Scale, modify, pause, or retire recommendations
- Exceptions to published guidance, with expiry dates
- Changes to the triage model or pathway expectations
- CAD-04
Monthly enablement and adoption review
- Frequency
- Monthly, 45 minutes
- Chaired by
- AI Program Manager
- Escalates to
- Governance committee where a barrier is caused by policy or tooling rather than knowledge
Who is there
- AI champion network
- Training coordinator
- Practice group representatives
- IT & Security
What goes in
- Training completion and feedback
- Office-hours themes
- Adoption barriers
- License utilization
What comes out
- Updated guidance and quick references
- Training calendar adjustments
- Barrier themes for leadership reporting
What is decided here
- What recurring questions become published guidance
- Training format and scheduling changes
- Where champion support is needed next
- CAD-05
Quarterly leadership program review
- Frequency
- Quarterly, 60 minutes
- Chaired by
- Director of Technology
- Escalates to
- Firm leadership as required
Who is there
- Executive leadership
- Director of Technology
- Governance committee chairs
- AI Program Manager
What goes in
- Portfolio status
- Outcomes with evidence labels
- Investment and utilization
- Risk themes
- Roadmap
What comes out
- Direction on priorities and investment
- Confirmed roadmap for the next quarter
What is decided here
- Program priorities and resourcing
- Investment direction and portfolio-level trade-offs
- Strategic response to emerging capability or risk
- CAD-06
Annual policy and program review
- Frequency
- Annually, half day
- Chaired by
- Director of Technology with Risk, Legal & Privacy
- Escalates to
- Executive leadership for approval of material policy change
Who is there
- All governance committee members
- Functional policy owners
- AI Program Manager
What goes in
- Full year of decisions, exceptions, incidents, and outcomes
- Regulatory and market developments
- Program measures against objectives
What comes out
- Updated policy and guidance
- Revised triage model
- Program objectives for the coming year
What is decided here
- Policy and guidance revisions
- Changes to pathway definitions and review expectations
- Retirement of controls that no longer earn their cost
Who decides what
Five marks rather than RACI letters, because the distinction that matters here is between coordinating something, recommending it, reviewing it, approving it, and being the person who still owns it a year later.
Read the first column
Across all twelve activities, the AI Program Manager column contains no approval anywhere. It coordinates, it recommends, and it owns two things outright — the quality of the program’s records and the delivery of enablement. Everything consequential is approved by whoever is accountable for that domain.
Final policy, legal, privacy, security, budget, and risk decisions belong to their authorized owners. The AI Program Manager coordinates the work, prepares the material, and tracks the outcome — the program manager does not approve on their behalf.
| Activity | AI Program Manager | Director of Technology | Security | Risk / Legal / Privacy | Data | HR | Business owner | Finance / Procurement | Governance committee |
|---|---|---|---|---|---|---|---|---|---|
| Intake and pathway assignmentAny reviewer can challenge a pathway assignment; disputes go to the committee. | Coordinates | Reviews | Reviews | Reviews | No role | No role | Recommends | No role | Reviews |
| Security review of a proposed toolSecurity's determination stands on its own; the program tracks the conditions. | Coordinates | Reviews | Approves | Reviews | Reviews | No role | Recommends | No role | Reviews |
| Client data and contractual suitabilityClient agreements vary; this is never a program judgment. | Coordinates | No role | Reviews | Approves | Reviews | No role | Recommends | No role | Reviews |
| Use of AI in employment or recruiting processesHR owns the process; Risk concurs; the committee approves the pilot. | Coordinates | Reviews | Reviews | Approves | No role | Owns outcome | Recommends | No role | Approves |
| Approval to run a pilotStandard pathway needs no approval; structured and elevated do. | Recommends | Approves | Reviews | Reviews | Reviews | Reviews | Owns outcome | Reviews | Approves |
| Pilot operation and outcomesThe business owner runs it. The program keeps it visible and on schedule. | Coordinates | Reviews | No role | No role | Reviews | No role | Owns outcome | No role | Reviews |
| Vendor contract and spendThe program supplies utilization and business-case inputs only. | Coordinates | Recommends | Reviews | Reviews | No role | No role | Recommends | Approves | Reviews |
| Exceptions to published guidanceEvery exception carries compensating controls and an expiry date. | Coordinates | Reviews | Approves | Approves | No role | No role | Recommends | No role | Reviews |
| Scale, modify, pause, or retireRecommendation from the program and the owner; decision by the committee. | Recommends | Approves | Reviews | Reviews | Reviews | Reviews | Owns outcome | Reviews | Approves |
| Policy and guidance contentThe program drafts and publishes; the functional owner approves the substance. | Coordinates | Reviews | Approves | Approves | Reviews | Reviews | No role | No role | Approves |
| Training and enablement deliveryContent owned with the relevant function; delivery coordinated by the program. | Owns outcome | Reviews | Reviews | Reviews | No role | Reviews | Recommends | No role | No role |
| Program records and leadership reportingThe program owns record quality; leadership owns what to do about it. | Owns outcome | Reviews | No role | No role | Reviews | No role | Recommends | Reviews | Reviews |
What each mark means
- Coordinates
- Convenes the right people, prepares the material, tracks the outcome. Carries no decision authority.
- Recommends
- Puts forward a position with reasoning. Someone else decides on it.
- Reviews
- Examines the request within their own remit and can raise an objection that has to be resolved.
- Approves
- Holds the authority to say yes or no. The decision is recorded in their name.
- Owns outcome
- Accountable for whether the thing actually works after the decision is made and everyone else has moved on.
- —
- No formal role in this activity. Not consulted by default.
Decision rights by role
The matrix says what happens in each activity. This says what each role decides in general, and what the program brings them.
- SR-APM
AI Program Manager
Technology
What this role decides
- Which pathway a request enters, subject to challenge by any reviewer
- Meeting agendas, sequencing, and what is ready for a decision
- Program documentation standards and record quality
Program interface: Runs intake, triage coordination, pilot tracking, enablement, and leadership reporting.
- SR-DOT
Director of Technology
Technology
What this role decides
- Program priorities and sequencing
- Technology strategy alignment and platform direction
- Escalation path to executive leadership
Program interface: Chairs the governance committee, sponsors the program, and takes recommendations to leadership.
- SR-SEC
Information Security
IT & Security
What this role decides
- Security review outcomes and required controls
- Tenant, identity, and data-flow configuration
- Whether a tool may connect to firm systems
Program interface: Reviews structured and elevated requests; sets conditions the program then tracks.
- SR-RSK
Risk, Legal & Privacy
Risk
What this role decides
- Contractual, professional liability, and privacy positions
- Whether client data may be used with a given tool
- Records retention expectations
Program interface: Reviews elevated requests and any use of client-confidential or personal data.
- SR-DAT
Data & Reporting
Data
What this role decides
- Data source suitability, quality, and access scope
- Whether a corpus is fit for retrieval or reuse
Program interface: Advises on data readiness; owns the standards library used by knowledge search.
- SR-HR
People & Culture
HR
What this role decides
- Any use of AI that touches hiring, evaluation, or employment decisions
- Employee communications about workforce impact
- Training requirements tied to role
Program interface: Co-owns elevated people-related use cases and the manager enablement pathway.
- SR-BIZ
Business owner
Practice group or shared service
What this role decides
- Whether the problem is worth solving and worth their team's time
- Acceptance of the outcome and ongoing operation after pilot
Program interface: Owns the use case, the pilot participants, and the result. Nothing proceeds without one.
- SR-FIN
Finance & Procurement
Finance
What this role decides
- Spend approval and contract execution
- Vendor terms, renewal, and license allocation
Program interface: Receives business-case inputs and utilization data from the program.
- SR-GOV
AI Governance Committee
Cross-functional
What this role decides
- Approval to pilot for elevated-pathway use cases
- Firmwide scale, modify, pause, and retire recommendations
- Exceptions to published guidance
Program interface: Meets monthly on material sent five business days ahead. The program prepares; the committee decides.
What these meetings produce
A cadence with no output is a status meeting. Each of these produces a record someone can read a year later, when the person who decided has moved on and the question is why.
- Governance meeting agenda — the standing structure, with a worked example.
- Decision log — every decision with its owner, its reasoning, and the alternatives that were rejected.
- Exception log — time-limited departures from guidance, each with compensating controls and an exit plan.