AI Governance Study

Tailoring AI governance to your organization

A 30-person startup and a global insurer should not run the same AI governance program. Six factors determine the shape of a program, and they explain why copying another organization's setup rarely works.

Domain I · Establish and communicate organizational expectations for AI governance · about 5 min

Why this matters for the exam

A 30-person startup and a global insurer should not run the same AI governance program. Six factors determine the shape of a program, and they explain why copying another organization's setup rarely works.

What you need to know

The last topic laid out the structures and people of governance. This one is about fitting them to a real organization. One size does not fit all, a phrase the course repeats deliberately. Six factors shape the program.

Six factors that shape a governance program

FactorHow it shapes governance
Company sizeCorrelates with how many AI systems the organization runs, and with how many people and how much money it can put behind governance. Smaller organizations often fold AI governance into existing privacy and legal functions and lean on existing risk-assessment tools. Larger organizations more often stand up dedicated AI-specific offices and detailed ML and GenAI processes.
MaturityCorrelates with how much infrastructure the organization has already built to manage AI-introduced risk.
Industry/sectorHighly regulated sectors (health care, insurance, banking) are typically already managing compliance, and regulator guidance shapes how they fold AI in.
Products and servicesThe amount of AI embedded in what the organization sells, whether B2B or B2C, drives how much governance scope is required.
ObjectivesStrategic goals for using AI should be structured around the risks those choices entail. Tying uses to desired business outcomes supports more balanced decisions.
Risk toleranceAI may reduce some existing risks but will almost certainly introduce new ones. A risk assessment only produces a relative score, so the organization still has to decide how that risk fits its values, operations and strategy.

Dedicated AI offices are a large-company pattern, because larger organizations have more people and money to put behind them. Risk tolerance is a separate matter. An organization sets it deliberately, from its values and its stakes.

The six factors applied to two organizations

Here are the six factors applied at two very different organizations. The first is a 30-person health-tech startup whose product is an AI diagnostic aid. The second is a global insurer using AI across many internal functions.

FactorThe startupThe insurer
Company sizeNo dedicated AI office. Governance rides on the regulatory and privacy function the company already needs as a device maker.A dedicated AI governance office with detailed ML and GenAI processes.
MaturityLittle existing risk infrastructure; starts from established templates and external frameworks.Builds on years of model-risk management practice from actuarial work.
Industry/sectorHealth care: medical-device and health-privacy rules shape the program from day one.Insurance: regulators already supervise how models set prices and process claims.
Products and servicesAI is the product. Deep governance scope on one system.AI prices and underwrites the product itself, and is embedded across many internal functions besides. Broad scope across dozens of systems.
ObjectivesOne stated outcome: clinician-usable diagnostic support. Every governance decision is measured against whether it still serves that outcome.AI serves efficiency and accuracy goals; governance weighs each use against its business case.
Risk toleranceDeliberately low. Patient safety and health data leave little room, and size has nothing to do with it.Varies by use, deliberately: more appetite in marketing, far less in claims decisions.

The startup's row for risk tolerance makes the earlier point concrete. The smaller organization runs the stricter tolerance. Tolerance follows an organization's values and what is at stake for it, and headcount does not decide it.

Next up: the people side — winning leadership, training staff, and the legal requirement behind AI literacy.

Remember

  • Six factors shape a governance program: company size, maturity, industry and sector, products and services, objectives, and risk tolerance.
  • Larger companies more often build dedicated AI offices; smaller companies more often fold AI governance into existing privacy and legal functions.
  • Risk tolerance is a deliberate organizational choice. It does not follow from size.
  • A risk assessment gives a relative score only. The organization still has to weigh that score against its own values and strategy.

Practise this topic

Domain I is free in the app, including its practice questions and flashcards, with progress tracking and no card details.

Start studying free

Previous: Governance structures, models and stakeholder roles
Next: Building buy-in: leadership, training, AI literacy and culture
Back to the AIGP study guide.

AI Governance Study is an independent study aid. It does not represent a government entity: it is not affiliated with, endorsed by or authorised by any government, government agency or regulatory authority, and it does not provide government services or legal advice. Laws and frameworks are described in our own words — the official texts are listed at official sources. It is also not affiliated with, endorsed by, or sponsored by the IAPP. The AIGP name is used only to identify the exam this material helps you prepare for.