En este modulo
- Why you need an AI governance structure
- The AI committee: composition and mandate
- Key roles: CAIO, AI Ethics Officer, AI Risk Manager
- The AI use policy
- AI system approval process
- System inventory and registry
- AI incident management
- Training and literacy programme
- AI governance maturity model
- Ejercicio practico
- Puntos clave
Why you need an AI governance structure
AI enters organizations in a decentralised way. One department adopts a chatbot. Another integrates an assistant into their CRM. The data team builds a predictive model. Marketing contracts a content generation tool. Without governance, each initiative operates in isolation, without coherence, without risk control and without visibility for management.
AI governance is not a bureaucracy that slows down innovation. It is the structure that enables innovation with control. Without it, your organization is exposed to three simultaneous risks: regulatory non-compliance (AI Act, GDPR), operational risks (erroneous decisions, bias, incidents) and reputational risks (public scandal, loss of trust).
Governance is not prohibition
A good governance structure facilitates the use of AI instead of blocking it. It defines clear rules so teams know what they can do, what needs approval and what is prohibited. Teams that work within a clear framework adopt AI faster and with better results than those operating in ambiguity.
The cost of not governing
The AI Act requires "governance measures" as part of the requirements for high-risk systems. But beyond the regulator, corporate customers demand evidence of AI governance in their procurement processes (RFPs, due diligence). Not having AI governance is no longer an option: it is a commercial risk.
The AI committee: composition and mandate
The AI committee is the strategic decision-making body for the use of artificial intelligence in the organization. It is not a technical working group: it is a governance body with the authority to approve, condition or reject AI initiatives.
Recommended composition
- Chair: CTO, CDO or a member of senior management. Must have authority to make binding decisions.
- DPO: mandatory participation in all decisions affecting personal data.
- CISO: cybersecurity and technology risk perspective.
- Legal/compliance officer: regulatory compliance (AI Act, GDPR, sectoral regulation).
- AI/Data Science lead: technical perspective on capabilities and limitations.
- Business representative: at least one functional area director (rotating).
- HR lead: impact on employees, training, change management.
- Guests: external stakeholder representatives, independent experts (per agenda).
Committee mandate
- Approve the AI use policy and its updates.
- Review and approve/reject requests for new AI systems classified as high-risk or processing sensitive data.
- Oversee the organization's AI system inventory.
- Review results of AI audits (internal and external).
- Manage escalated AI incidents.
- Approve the AI training programme.
- Report to the board of directors on AI risks and opportunities.
Frequency and operations
Ordinary meeting: monthly or bimonthly. Extraordinary meeting: in the event of serious incidents or urgent decisions. Secretariat: the AI governance officer prepares the agenda, circulates materials in advance and drafts the minutes. Decisions are formally documented with date, participants, arguments and outcome.
Key roles: CAIO, AI Ethics Officer, AI Risk Manager
Chief AI Officer (CAIO)
Executive responsible for the AI strategy. Not all organizations need a CAIO. In medium-sized organizations, this role can be assumed by the CTO, CDO or CIO with an expanded mandate. In large organizations with business-critical AI, a dedicated CAIO is justified.
Functions: define the AI strategy aligned with business objectives, chair or co-chair the AI committee, manage the AI budget, represent the AI function to the board of directors, coordinate with regulators.
AI Ethics Officer
Responsible for ensuring the organization's AI systems comply with adopted ethical principles. Can be a dedicated role or a function assigned to a compliance professional or the DPO (in smaller organizations).
Functions: lead ethical impact assessments, oversee fairness audits, manage the ethics reporting/inquiry channel for AI, train teams on AI ethics, advise the AI committee on ethical matters.
AI Risk Manager
Responsible for identifying, assessing and mitigating risks associated with AI systems. In organizations with a mature risk function, this role integrates into the existing second line of defence.
Functions: maintain the AI risk register, coordinate risk classification under the AI Act, oversee the Article 9 risk management system, monitor risk indicators in production, report to the AI committee.
Three lines model for AI
- First line (system owners): manage risk day-to-day. Responsible for operating the system per policies, monitoring performance, escalating incidents.
- Second line (AI Risk Manager, compliance, DPO): define policies, provide independent oversight, verify first line compliance.
- Third line (internal audit): independently evaluates the effectiveness of the first two lines.
Article 4 of the AI Act: AI literacy
Article 4 requires providers and deployers to ensure their staff have a sufficient level of "AI literacy". This obligation has been applicable since February 2025. Designating roles is not enough: you must ensure that the persons holding them have the necessary competence.
The AI use policy
The AI use policy is the foundational governance document. It defines what is permitted, what needs approval and what is prohibited regarding the use of AI in the organization.
Recommended structure
1. Scope and definitions
Who it applies to (all employees, contractors, vendors), what "AI system" means for policy purposes, which systems are covered (including third-party SaaS).
2. Guiding principles
The ethical principles adopted by the organization. Reference to applicable international frameworks (HLEG, OECD, UNESCO). Concrete commitments: transparency, non-discrimination, human oversight, privacy.
3. Use classification
- Free use: personal productivity tools (writing assistants, AI search) without confidential or customer data. No prior approval required.
- Regulated use: systems that process organisational data, customer data or influence business decisions. Requires area manager approval and registration in the AI inventory.
- Restricted use: high-risk systems, systems processing sensitive data, systems making automated decisions with significant effects. Requires AI committee approval, DPIA/FRIA, pre-deployment fairness audit.
- Prohibited use: uses falling within the Article 5 prohibitions of the AI Act. Social scoring, subliminal manipulation, emotion recognition at work, etc.
4. Data and privacy
Rules on what data can be entered into AI systems. Explicit prohibition on entering confidential data, PII or trade secrets into public AI tools (ChatGPT free, etc.). Requirements for contracts with AI providers (no-training clauses, data localisation, security).
5. Intellectual property
The organization's position on use of AI-generated content: mandatory human review before publication, responsibility to verify originality, treatment of generated output as a draft (not a final product).
6. Responsibilities
Who approves what. Who monitors. Who responds to incidents. Escalation chain.
7. Non-compliance and sanctions
Consequences of policy non-compliance. From additional training to disciplinary measures, depending on severity.
AI system approval process
Before acquiring, developing or deploying a new AI system, the organization must follow a structured approval process. The complexity of the process is proportionate to the system's risk.
Approval workflow
Stage 1: Request
The requesting area completes an AI request form: system description, purpose, data to be processed, affected persons, provider, estimated cost, preliminary risk classification.
Stage 2: Triage
The AI governance officer assesses the request and classifies it: free use (proceeds directly), regulated use (requires abbreviated assessment) or restricted use (requires full assessment).
Stage 3: Assessment
For regulated use: formal risk classification, AI policy compliance check, provider contract review, inventory registration. For restricted use: all of the above plus integrated DPIA/FRIA, pre-deployment fairness audit, ethical impact assessment, AI committee review.
Stage 4: Decision
Regulated use: approval by the AI governance officer (or delegate). Restricted use: approval by the AI committee. The decision can be: approved, approved with conditions, deferred (more information required), or rejected (with justification).
Stage 5: Implementation and monitoring
If approved: implement conditions, register in the inventory, schedule periodic reviews, configure monitoring. If approved with conditions: verify that conditions are met before deployment.
System inventory and registry
The AI system inventory is the backbone of governance. Without a complete and up-to-date inventory, you cannot govern what you do not know about.
Inventory fields
- Unique system identifier.
- Name and version.
- Provider (internal or external).
- Internal owner (system owner).
- Functional description.
- AI Act risk classification (prohibited/high/limited/minimal).
- Annex III area (if applicable).
- Data processed (categories).
- GDPR legal basis.
- DPIA/FRIA completed (yes/no, date).
- Approval date.
- Approval conditions.
- Status (under evaluation, approved, in production, retired).
- Next scheduled review.
- Registration in EU database (if applicable, for high-risk).
Maintenance
The inventory must be updated: when a new system is added, when an existing system is substantially modified, when a system is retired, when the risk classification changes, at least quarterly (general review). The AI governance officer is the custodian of the inventory.
AI incident management
An AI incident is any unplanned event related to an AI system that causes or may cause harm to persons, to the organization or to regulatory compliance. Examples: discriminatory decision, system failure affecting critical services, personal data leakage through a model, generated content damaging reputation.
Incident management process
Detection and notification
Anyone can report an AI incident through a dedicated channel (email, form, phone line). Automated monitoring systems alert to anomalies (drift, performance degradation, fairness alerts). The system operator must report to the AI governance officer within a maximum of 24 hours.
Classification and triage
Classify the incident by severity:
- Critical: actual harm to persons, serious incident under Art. 73 AI Act, personal data breach.
- High: significant risk of harm, detected bias with potential impact, human oversight failure.
- Medium: operational anomaly without immediate harm, performance degradation.
- Low: minor issue, negative user feedback without significant impact.
Response and containment
For critical incidents: activate the response team, consider system suspension, notify the AI committee, assess the need for notification to the market surveillance authority (15 days under Art. 73) and to the data protection authority (72 hours if there is a personal data breach).
Investigation
Root cause analysis. Review of system logs, input data, decisions made. Assessment of actual and potential impact. Complete documentation of findings.
Remediation and lessons learned
Implement corrective actions. Update the risk classification if appropriate. Update the DPIA/FRIA. Communicate lessons learned to the AI committee and relevant teams. Update procedures to prevent recurrence.
Training and literacy programme
Article 4 of the AI Act establishes the AI literacy obligation. This obligation has been applicable since February 2025 and affects both providers and deployers.
Training levels
Level 1: General awareness (all employees)
What is AI. The organization's AI use policy. Which AI tools are approved and for what. Basic risks (privacy, bias, misinformation). Where to report incidents. Recommended duration: 2-4 hours. Frequency: annual, with updates for policy changes.
Level 2: Operational use (AI system users)
Specific training on the AI system they oversee or operate. System capabilities and limitations. Human oversight procedures. How to interpret system outputs. When to escalate. Recommended duration: 8-16 hours (depending on system complexity). Frequency: at onboarding and upon substantial system changes.
Level 3: Governance and compliance (AI committee, DPO, compliance)
AI Act in detail. Risk classification process. DPIA/FRIA. Fairness audits. Incident management. Harmonised standards. Recommended duration: 24-40 hours. Frequency: annual, with updates for regulatory changes.
Level 4: Technical (developers, data scientists)
Technical requirements of the AI Act (Arts. 9-15). Bias detection and mitigation techniques. Explainability implementation (SHAP, LIME). Technical documentation per Annex IV. Testing and validation. Recommended duration: 40+ hours. Frequency: continuous, integrated into professional development.
AI governance maturity model
A maturity model allows you to assess where your organization stands and plan the evolution towards a governance level appropriate to the risk of your AI systems.
Level 1: Ad hoc
No AI policy. Teams adopt AI individually. No system inventory. No centralised oversight. No specific training. Most organizations are here.
Level 2: Initial
A basic AI use policy exists. An AI governance officer has been designated. A system inventory is being started. Awareness training for all employees. Reactive processes (action taken upon incidents).
Level 3: Defined
The AI committee is constituted and operational. The inventory is complete and up to date. High-risk systems have DPIAs/FRIAs. There is an approval process for new systems. Level-based training implemented. Incident management documented.
Level 4: Managed
AI governance metrics defined and monitored. Periodic fairness audits. Continuous monitoring of performance and bias. Integration with the corporate risk function. Regular reporting to the board. Data-driven continuous improvement.
Level 5: Optimised
AI governance integrated into organizational culture. Responsible innovation as a strategic value. Active participation in regulatory sandboxes. Contribution to sector standards and codes of practice. Peer benchmarking. Recognised leadership in AI governance.
Where to aim
For most organizations, the target by August 2026 should be Level 3 (Defined). Level 4 (Managed) is the target at 12-18 months after. Level 5 (Optimised) is a long-term objective (3-5 years) and is only necessary for organizations that make AI a central competitive advantage.
Ejercicio practico
- Define the composition of your AI committee (names/roles). Draft a 1-page mandate with: scope, authority, meeting frequency, decision mechanism.
- Draft section 3 (use classification) of your AI use policy. Define at least 5 concrete examples for each category (free, regulated, restricted, prohibited).
- Design the new AI system request form (10-15 fields that capture the information needed for triage).
- Assess your organization against the 5-level maturity model. Identify your current level and the 3 priority actions to advance to the next level.
- Design the training programme for the 4 levels: topics, duration, audience, frequency and assessment method for each level.
Output: an AI governance package with committee mandate, use policy (partial), request form, maturity assessment and training programme.
Puntos clave
Puntos clave from TG05
- AI governance is not bureaucracy: it is the structure that enables innovation with control. Without it, AI enters the organization in an uncontrolled manner.
- The AI committee is a decision-making body, not a working group. It needs authority, multidisciplinary composition (including the DPO) and formal operations.
- The AI use policy classifies uses into 4 levels (free, regulated, restricted, prohibited). Each level has an approval process proportionate to the risk.
- The AI system inventory is the backbone. You cannot govern what you do not know about. It must include AI Act classification, DPIA, status and next review.
- Training has 4 levels (awareness, operational, governance, technical). Article 4 of the AI Act requires ensuring AI literacy since February 2025.
Guia de estudio — Conceptos clave de TG05
Por que necesitas una estructura de gobernanza de IA
- El coste de no gobernar: El AI Act exige "medidas de gobernanza" como parte de los requisitos para sistemas de alto riesgo. Pero mas alla del regulador, los clientes corporativos exigen evidencia de gobernanza de IA en sus procesos de compra (RFPs, due diligence). No tener gobernanza de IA ya no es una opcion: es un riesgo comercial.
El comite de IA: composicion y mandato
- Presidente:CTO, CDO o un miembro de la alta direccion. Debe tener autoridad para tomar decisiones vinculantes.
- DPO:participacion obligatoria en todas las decisiones que afecten a datos personales.
- CISO:perspectiva de ciberseguridad y riesgo tecnologico.
- Responsable legal/compliance:cumplimiento regulatorio (AI Act, RGPD, normativa sectorial).
- Responsable de IA/Data Science:perspectiva tecnica sobre capacidades y limitaciones.
- Representante de negocio:al menos un director de area funcional (rotativo).
Roles clave: CAIO, AI Ethics Officer, AI Risk Manager
- Primera linea (propietarios del sistema):gestionan el riesgo en el dia a dia. Responsables de operar el sistema conforme a las politicas, monitorear el rendimiento, escalar incidentes.
- Segunda linea (AI Risk Manager, compliance, DPO):definen las politicas, proporcionan oversight independiente, verifican que la primera linea cumple.
- Tercera linea (auditoria interna):evalua la eficacia de las dos primeras lineas de manera independiente.
- Articulo 4 del AI Act: alfabetizacion en IA: El articulo 4 obliga a proveedores e implementadores a garantizar que su personal tenga un nivel suficiente de "alfabetizacion en IA" (AI literacy). Esta obligacion es aplicable desde febrero de 2025. No basta con designar roles: hay que asegurar que las personas que los desempenan tienen la competencia necesaria.
La politica de uso de IA
- - Uso libre:herramientas de productividad personal (asistentes de escritura, busqueda IA) sin datos confidenciales ni de clientes. No requiere aprobacion previa.
- Uso regulado:sistemas que procesan datos de la organizacion, datos de clientes o influyen en decisiones de negocio. Requiere aprobacion del responsable de area y registro en el inventario de IA.
- Uso restringido:sistemas de alto riesgo, sistemas que procesan datos sensibles, sistemas que toman decisiones automatizadas con efectos significativos. Requiere aprobacion del comite de IA, DPIA/FRIA, auditoria de fairness pre-despliegue.
- Uso prohibido:usos que encajen en las prohibiciones del articulo 5 del AI Act. Social scoring, manipulacion subliminal, reconocimiento de emociones en el trabajo, etc.
Inventario y registro de sistemas
- Identificador unico del sistema.
- Nombre y version.
- Proveedor (interno o externo).
- Responsable interno (owner del sistema).
- Descripcion funcional.
- Clasificacion de riesgo AI Act (prohibido/alto/limitado/minimo).
Gestion de incidentes de IA
- Critico:dano real a personas, incidente grave a efectos del art. 73 AI Act, violacion de datos personales.
- Alto:riesgo significativo de dano, sesgo detectado con impacto potencial, fallo en supervision humana.
- Medio:anomalia operativa sin dano inmediato, degradacion de rendimiento.
- Bajo:incidencia menor, feedback negativo de usuario sin impacto significativo.
Siguiente: TG06 - AI System Auditing
With the governance structure in place, the next step is to verify it: internal AI audit methodology, article-by-article checklists, evidence collection and preparation for third-party audits.
Ir al modulo TG06