AI Governance (Part 2)

AI Governance (Part 2)

Written by Bryan Altimas

Earlier this week I posted about the #governance of #AI and various #riskmanagement frameworks that can be used (link to earlier post in the comments). These frameworks offer a strong foundation for AI governance significant gaps remain for companies implementing global AI governance. Whilst the EU AI Act emphasises stringent controls and risk management practices for high risk AI systems, for example, other regions have more lenient standards or lack comprehensive AI governance altogether.

The most critical gap lies within organisations themselves, where there is often a lack of clear ownership of AI governance. Boards and executive management
must understand AI benefits and risk to help ensure accountable and responsible roles are clearly defined to avoid fragmented oversight, which can hinder an organisation’s ability to fully understand the broader impact of AI on its operations.

Without clear ownership, key stakeholders, including IT leaders, compliance officers, and business executives, may fail to align AI systems with the organisation’s policies and overall strategy. This misalignment can result in disjointed implementations, inefficiencies, and an unclear understanding of the risk and opportunities associated with AI deployment.

The solution may lie in ISACA's COBIT framework which offers a holistic approach to AI governance. COBIT's primary goal is to help organisations align IT with business objectives, manage risks and ensure the optimal use of resources.

COBIT is structured into five key domains. These domains include 40 objectives designed to manage IT-related activities, ranging from strategic planning to
day-to-day operations and performance monitoring. The five domains are:

- Evaluate, Direct and Monitor (EDM) primarily focused on governance

- Align, Plan and Organise (APO) strategic planning of technology solutions

- Build, Acquire and Implement (BAI) developing and deploying systems

- Deliver, Service and Support (DSS) the ongoing operations of technology and systems once they are deployed

- Monitor, Evaluate and Assess (MEA) the importance of continuous improvement within the organisation’s governance framework.

Under each domain is a range of goals which we can use to design an approach to AI governance that can be used in any country.

Wish to know more? Contact us by LinkedIn messenger or by email at info@riversidecourtconsulting.co.uk with the message AI governance.


Join the Newsletter
Insights from Riverside Court Consulting Ltd into cyber security, data protection and regulatory compliance
Subscribe Now
Categories
Recent Posts

Cyber Security is serious. But it shouldn't be confusing and stressful

crossmenuarrow-right