En este modulo

  1. Project overview
  2. AI policy suite
  3. AI committee charter
  4. Risk classification and management methodology
  5. AI audit plan
  6. Training programme
  7. Governance metrics dashboard
  8. Implementation plan
  9. Final project
  10. Puntos clave

Project overview

This module is a capstone project that integrates all concepts from modules TG01 through TG07 into a practical deliverable: a complete AI governance programme ready to implement in a real organization.

This is not an academic exercise. The objective is that upon completing this module you have a package of operational documents that you can present to your organization's management, adapt to the specific context and deploy progressively.

Programme components

A complete AI governance programme includes 6 interrelated components:

  1. Policy suite: the AI framework policy, the acceptable use policy, the data for AI policy and the AI provider policy.
  2. AI committee charter: the constitutive document of the governance body.
  3. Risk methodology: the systematic process for classifying and managing AI system risks.
  4. Audit plan: the periodic compliance verification programme.
  5. Training programme: the strategy for AI literacy and skills development by level.
  6. Metrics dashboard: the indicators that allow measuring the programme's effectiveness.

Adapt to your context

This module provides generic templates and structures. Your job is to adapt them to your organization: size, sector, existing AI systems, maturity level, applicable sectoral regulation. There is no universal governance programme. There is a framework that adapts to each context.

AI policy suite

The policy suite is the set of normative documents that establish the rules of the game for AI use in the organization. It is not a single monolithic document: they are specialised documents that complement each other.

AI framework policy (governing document)

Establishes the vision, principles and governance structure at a high level. This is the document approved by the board of directors or senior management.

Essential content

AI acceptable use policy

The operational document that all employees read. Clear, concrete language, with examples. Defines the 4 use categories (free, regulated, restricted, prohibited) with specific examples for the organization.

Essential content

Data for AI policy

Defines the quality, governance and data protection requirements applicable to AI systems.

Essential content

AI provider policy

Defines the requirements for selecting, contracting and managing providers of AI systems and models.

Essential content

AI committee charter

The charter is the constitutive document of the AI committee. It defines its reason for being, its authority and its operations.

Charter structure

1. Mission

"The AI committee of [organization] has the mission of overseeing the responsible, ethical and regulation-compliant use of artificial intelligence in all activities of the organization, ensuring that AI systems generate business value without putting individuals' rights or regulatory compliance at risk."

2. Authority

The committee has the authority to approve or reject the acquisition, development and deployment of AI systems classified as restricted use. It can condition use on additional requirements. It can order the suspension of an AI system presenting unacceptable risks. It can request information from any area of the organization.

3. Composition

Permanent members (with vote): chair (CTO/CDO), DPO, CISO, legal officer, AI lead, business representative, HR lead. Guests (without vote): per agenda.

4. Quorum and decision-making

Quorum: simple majority of permanent members. Decisions: by consensus; if no consensus, by simple majority with the chair's casting vote. The DPO has veto power on personal data protection matters.

5. Operations

Frequency: monthly ordinary meeting. Notice: at least 5 working days in advance with attached materials. Minutes: drafted by the committee secretariat (AI governance officer), approved at the following meeting. Urgent decisions: written electronic voting procedure with a 48-hour deadline.

6. Reporting

Quarterly report to senior management/board with: activity summary, systems assessed, incidents managed, key metrics, emerging risks.

7. Charter review

Annual review. Changes approved by senior management/board.

Risk classification and management methodology

The methodology defines the systematic process for classifying and managing AI system risks in accordance with the AI Act and corporate risk frameworks.

Phase 1: Inventory and triage

Identify all AI systems (internal, SaaS, embedded). For each system, determine whether it meets the Article 3(1) definition of the AI Act. Initial triage: candidate for high-risk or not. Tool: standardised inventory form (15 fields, see TG05).

Phase 2: Classification

For each candidate system, walk through the complete decision tree (see TG02): exclusions, prohibitions, Annex I, Annex III, Art. 6(3) exceptions, transparency, minimal risk. Document the complete reasoning in the standardised classification form. Approve the classification by the AI governance officer.

Phase 3: Risk assessment

For high-risk and restricted-use systems, conduct a risk assessment covering:

Phase 4: Mitigation and residual risk

For each significant risk, define mitigation measures (technical, organisational, contractual). Assess the residual risk after mitigation. Determine whether the residual risk is acceptable. If not acceptable, escalate to the AI committee for a decision (additional mitigation, exceptional acceptance, system rejection).

Phase 5: Continuous monitoring

Define key risk indicators (KRIs) for each high-risk system. Configure automatic alerts (drift, degradation, disparity). Periodic reviews of the risk profile (quarterly for high-risk, annually for others). Reclassification upon triggers (see TG02).

AI audit plan

The audit plan defines the strategy for periodic verification of the governance programme and of individual AI systems.

Auditable universe

The auditable universe includes: each high-risk AI system (audited individually), the AI governance programme as a whole (policies, committee, processes), data and privacy controls applied to AI, cybersecurity controls for AI systems, AI provider management.

Audit frequency

Methodology (summary)

Follow the 5-phase methodology described in TG06: planning, information gathering, analysis and evaluation, report, follow-up. Apply the article-by-article AI Act checklist. Collect documentary, technical, testimonial and observational evidence.

Resources

Audit team with AI, legal and cyber competencies. Specific training of the audit team on the AI Act and harmonised standards. Support tools: digitalised checklists, findings management platform, access to system logs and metrics.

Typical annual calendar

Training programme

The training programme operationalises the AI literacy requirement of Article 4 of the AI Act and builds a culture of responsible AI use.

Programme structure

Level 1: Fundamentals (all employees)

Level 2: Operators (specific AI system users)

Level 3: Governance (AI committee, DPO, compliance, risk)

Level 4: Technical (developers, data scientists, MLOps)

Governance metrics dashboard

A governance programme without metrics is a programme without visibility. The metrics dashboard allows the AI committee and senior management to assess the programme's effectiveness and make informed decisions.

Inventory and classification metrics

Compliance metrics

Risk metrics

Training metrics

Provider metrics

Report what matters

Not all metrics need to go to the board of directors. The quarterly board report should include a maximum of 5-7 high-level indicators: total systems, compliance coverage, serious incidents, emerging risks and training status. The detail stays with the AI committee.

Implementation plan

Implementing an AI governance programme from scratch is a 6-12 month project, depending on the organization's size and the number of existing AI systems.

Phase 1: Foundations (months 1-2)

Phase 2: Classification and assessment (months 3-5)

Phase 3: Controls and monitoring (months 6-8)

Phase 4: Verification and improvement (months 9-12)

Critical success factors

Final project

Capstone project TG08: AI Governance Programme

Design a complete AI governance programme for an organization (your real organization or a fictitious one). The deliverable must include the following documents:

  1. AI framework policy (3-5 pages): vision, principles, scope, governance structure, regulatory compliance.
  2. Acceptable use policy (2-3 pages): use classification with at least 15 concrete examples, data rules, generated content, inquiry channel.
  3. AI committee charter (2 pages): mission, authority, composition, quorum, operations, reporting.
  4. Risk classification methodology (3-4 pages): adapted decision tree, classification form, reclassification process.
  5. Annual audit plan (2 pages): auditable universe, frequency, resources, calendar.
  6. Training programme (2-3 pages): 4 levels with content, duration, assessment, frequency and evidence.
  7. Metrics dashboard (1-2 pages): 15-20 KPIs organized by domain, with targets and measurement frequency.
  8. Implementation plan (1-2 pages): 4 phases, activities, deadlines and responsible parties.

Evaluation criteria: completeness (covers all components), internal coherence (documents reference each other), practicality (implementable, not pure theory), regulatory adequacy (complies with AI Act, GDPR, NIS2/DORA if applicable), context adaptation (reflects the characteristics of the chosen organization).

Recommended total length: 20-30 pages.

Puntos clave

Puntos clave from TG08 and the complete track

  1. An AI governance programme has 6 components: policies, committee, risk methodology, audit plan, training and metrics. All 6 are necessary; none is sufficient on its own.
  2. The policy suite has 4 documents: framework policy (strategic), acceptable use (operational), data for AI (technical) and AI providers (contractual).
  3. Metrics transform governance from "we do things" to "we can demonstrate our things work". A dashboard with 15-20 KPIs covers inventory, compliance, risk, training and providers.
  4. Implementation is a 6-12 month project in 4 phases: foundations, classification, controls and verification. The critical success factor is senior management sponsorship.
  5. The target for August 2026 is to reach Maturity Level 3 (Defined). This means: operational committee, complete inventory, high-risk systems assessed, training deployed and first audit cycle completed.
Guia de estudio — Conceptos clave de TG08

Vision general del proyecto

  • Suite de politicas:la politica marco de IA, la politica de uso aceptable, la politica de datos para IA y la politica de proveedores de IA.
  • Charter del comite de IA:el documento constitutivo del organo de gobernanza.
  • Metodologia de riesgos:el proceso sistematico para clasificar y gestionar los riesgos de los sistemas de IA.
  • Plan de auditoria:el programa de verificacion periodica del cumplimiento.
  • Programa de formacion:la estrategia de alfabetizacion y capacitacion en IA por niveles.
  • Dashboard de metricas:los indicadores que permiten medir la eficacia del programa.

Suite de politicas de IA

  • - Declaracion de proposito:por que la organizacion adopta IA y por que necesita gobernanza. Vinculacion con la estrategia de negocio.
  • Principios rectores:los valores que guian el uso de IA. Referencia a marcos internacionales (HLEG, OECD). Compromiso con transparencia, no discriminacion, supervision humana, privacidad, seguridad.
  • Ambito de aplicacion:a quien aplica, que sistemas cubre, que queda excluido.
  • Estructura de gobernanza:comite de IA, roles clave (CAIO, DPO, AI Risk Manager), modelo de tres lineas.
  • Cumplimiento regulatorio:referencia al AI Act, RGPD, NIS2/DORA (si aplica), normativa sectorial.
  • Revision y actualizacion:frecuencia de revision (anual minimo), proceso de aprobacion de cambios, responsable del mantenimiento.

Metodologia de clasificacion y gestion de riesgos

  • Riesgos para derechos fundamentales (FRIA, art. 27).
  • Riesgos de proteccion de datos (DPIA, art. 35 RGPD).
  • Riesgos eticos (sesgo, fairness, explicabilidad, autonomia).
  • Riesgos operacionales (disponibilidad, integridad, continuidad).
  • Riesgos de ciberseguridad (ataques adversariales, exfiltracion, manipulacion).

Plan de auditoria de IA

  • Sistemas de alto riesgo criticos:auditoria interna anual, auditoria externa cada 2-3 anos.
  • Sistemas de alto riesgo no criticos:auditoria interna cada 2 anos.
  • Programa de gobernanza:revision interna anual, auditoria externa cada 3 anos.
  • Proveedores criticos de IA:revision anual de cumplimiento contractual.
  • Q1:planificacion del ciclo de auditorias. Actualizacion del universo auditable. Formacion del equipo auditor.
  • Q2:auditorias de los sistemas de alto riesgo criticos. Revision del programa de gobernanza.

Programa de formacion

  • - Formato:e-learning autoguiado + sesion presencial de 1 hora.
  • Duracion:3-4 horas totales.
  • Contenido:que es la IA, politica de uso de IA de la organizacion, herramientas aprobadas, reglas de datos, riesgos basicos, canal de consultas.
  • Evaluacion:cuestionario final (umbral: 80% aciertos).
  • Frecuencia:onboarding + refresco anual.
  • Evidencia:registro de completacion con fecha y resultado del cuestionario.

Dashboard de metricas de gobernanza

  • Total de sistemas de IA registrados:numero absoluto, tendencia mensual.
  • Distribucion por nivel de riesgo:prohibido (debe ser 0), alto, limitado, minimo.
  • Sistemas pendientes de clasificacion:deberia tender a 0.
  • Cobertura del inventario:porcentaje de areas de negocio con inventario completo.
  • Shadow AI detectada:sistemas no registrados identificados en auditorias o barridos.
  • Sistemas de alto riesgo con DPIA/FRIA completa:objetivo 100%.

You have completed the AI Governance track

Congratulations. With the 8 modules of this track you have the knowledge and the tools to design and implement a complete AI governance programme. The next step is to move from theory to practice in your organization.

Team training