AI Governance Study

Governance structures, models and stakeholder roles

Someone has to own AI governance, and where that ownership sits changes how the work gets done. Organizations solve this in three standard ways, and each way pulls in a different set of people. The design of the oversight body at the top decides whether any

Domain I · Establish and communicate organizational expectations for AI governance · about 6 min

Why this matters for the exam

Someone has to own AI governance, and where that ownership sits changes how the work gets done. Organizations solve this in three standard ways, and each way pulls in a different set of people. The design of the oversight body at the top decides whether any of it has effect.

What you need to know

The last topic covered the roles around an AI system. This one covers how governance is organized inside the organization: the structure, the people, and the oversight body at the top.

Setting up the structure

Start slowly and build out. Use existing structures rather than reinventing them: AI governance should integrate with security and privacy governance. Building a parallel structure duplicates work, and integrating helps win organization-wide buy-in. The starting questions are practical. Is there already an AI governance structure in place? Who writes AI policies and procedures? Who oversees development, testing and selection?

Find an executive champion to sponsor the governance work. A champion increases its organizational weight and helps recruit the other stakeholders.

Three governance models

Organizations place governance in one of three shapes. The difference between them is how much authority sits at the center and how much sits with local teams.

Centralized Decentralized Hybrid

Centralized: everything flows through one point. Decentralized: authority is delegated with no central hub. Hybrid: central policy, local implementation.

ModelDescription
CentralizedOne team or person is responsible for AI-related affairs; everything flows through that single point.
Decentralized ("local governance")Decision-making authority is delegated to lower levels of the organization, away from a central authority. Fewer tiers, wider span of control, and decisions can flow bottom-up as well as top-down.
HybridCombines the two. Typically one individual holds main responsibility centrally, while local entities implement and support the central body's policies and directives.

Whichever model an organization uses, clearly defined roles and responsibilities let everyone know their part, where to go for help, and how to empower others as AI products move through development, evaluation and release.

The people a governance program pulls in

Privacy, ethics, responsible-AI and legal personnel all look at overlapping parts of one question: legal and policy compliance. They have to work together. Designers, developers, marketers and managers belong in the conversation too, because it is where policy goals, business goals and technical reality get reconciled.

AreaRoles and teams commonly named
OversightChief privacy officer; chief ethics officer / ethics board; office for responsible AI
Legal & riskLegal advisors; risk management officer
BuildEngineering and data management; architecture steering groups; AI project managers
Operate & supportProcurement; human resources; marketing and sales; security/IT

In smaller organizations, several of these may be the same person or office. Three more groups belong in the program:

Designing an oversight body that works

An oversight body is only effective if five things are designed deliberately:

In practice Meta's Oversight Board is one of the only real-world bodies with genuinely binding authority: it can override the company's content-moderation decisions. Its design shows where that authority comes from. A purpose trust funds an LLC, which keeps the board independent and indirectly funded. Those are exactly the external-structure and resourcing choices described above.
Case study Two boards show how the design choices fail. Google's AI ethics advisory council (ATEAC) folded within a week, after controversial member appointments sparked resignations and petitions. That is a membership failure. Axon's AI and Policing Technologies Ethics Board saw 9 of its 11 members resign after Axon announced taser-drone plans without consulting the board first. That is a decision-making failure: the board had no binding role in the decisions it existed to oversee.

Next up: tailoring these structures to your organization — the six factors that decide what your program should look like.

Remember

  • Three governance models: centralized (one point of responsibility), decentralized (authority delegated to lower levels), hybrid (central policy, local implementation).
  • Integrate AI governance with existing security and privacy governance rather than duplicating it, and find an executive champion early.
  • Cross-functional stakeholders are required because privacy, ethics, legal and technical teams each see part of the same compliance question.
  • An oversight body is only as effective as five design choices: responsibilities, legal structure, membership, decision-making (especially bindingness), and resources.

Practise this topic

Domain I is free in the app, including its practice questions and flashcards, with progress tracking and no card details.

Start studying free

Previous: Roles across the AI value chain: developer, provider, deployer and user
Next: Tailoring AI governance to your organization
Back to the AIGP study guide.

AI Governance Study is an independent study aid. It does not represent a government entity: it is not affiliated with, endorsed by or authorised by any government, government agency or regulatory authority, and it does not provide government services or legal advice. Laws and frameworks are described in our own words — the official texts are listed at official sources. It is also not affiliated with, endorsed by, or sponsored by the IAPP. The AIGP name is used only to identify the exam this material helps you prepare for.