En este modulo
Project overview
This module is a capstone project that integrates all concepts from modules TG01 through TG07 into a practical deliverable: a complete AI governance programme ready to implement in a real organization.
This is not an academic exercise. The objective is that upon completing this module you have a package of operational documents that you can present to your organization's management, adapt to the specific context and deploy progressively.
Programme components
A complete AI governance programme includes 6 interrelated components:
- Policy suite: the AI framework policy, the acceptable use policy, the data for AI policy and the AI provider policy.
- AI committee charter: the constitutive document of the governance body.
- Risk methodology: the systematic process for classifying and managing AI system risks.
- Audit plan: the periodic compliance verification programme.
- Training programme: the strategy for AI literacy and skills development by level.
- Metrics dashboard: the indicators that allow measuring the programme's effectiveness.
Adapt to your context
This module provides generic templates and structures. Your job is to adapt them to your organization: size, sector, existing AI systems, maturity level, applicable sectoral regulation. There is no universal governance programme. There is a framework that adapts to each context.
AI policy suite
The policy suite is the set of normative documents that establish the rules of the game for AI use in the organization. It is not a single monolithic document: they are specialised documents that complement each other.
AI framework policy (governing document)
Establishes the vision, principles and governance structure at a high level. This is the document approved by the board of directors or senior management.
Essential content
- Statement of purpose: why the organization adopts AI and why it needs governance. Link to the business strategy.
- Guiding principles: the values guiding AI use. Reference to international frameworks (HLEG, OECD). Commitment to transparency, non-discrimination, human oversight, privacy, security.
- Scope: who it applies to, which systems it covers, what is excluded.
- Governance structure: AI committee, key roles (CAIO, DPO, AI Risk Manager), three lines model.
- Regulatory compliance: reference to the AI Act, GDPR, NIS2/DORA (if applicable), sectoral regulation.
- Review and updates: review frequency (annual minimum), change approval process, maintenance owner.
AI acceptable use policy
The operational document that all employees read. Clear, concrete language, with examples. Defines the 4 use categories (free, regulated, restricted, prohibited) with specific examples for the organization.
Essential content
- Approved tools: list of approved AI tools for each use category. Updated quarterly.
- Data rules: what data can be entered into external AI tools (nothing confidential, no customer data, no employee data), what data can only be processed in approved internal tools.
- Generated content: rules on use of AI-generated content. Mandatory human review before publication. Fact verification. Disclosure when required.
- Intellectual property: the organization's position on copyright of AI-generated content. Restrictions on using AI to generate content that infringes third-party rights.
- User responsibilities: the user is responsible for reviewing and validating all AI output. AI does not exempt from professional responsibility.
- Inquiry channel: where to ask if you are unsure whether a use is permitted.
Data for AI policy
Defines the quality, governance and data protection requirements applicable to AI systems.
Essential content
- Training data quality requirements (representativeness, completeness, accuracy) per Article 10 of the AI Act.
- Data bias assessment process.
- Special category data processing (Art. 10(5) AI Act + Art. 9 GDPR).
- AI data retention and deletion (periods, process).
- Data subject rights in AI contexts (access, rectification, objection, explanation).
- AI data security (encryption, access control, anonymisation).
AI provider policy
Defines the requirements for selecting, contracting and managing providers of AI systems and models.
Essential content
- Pre-contractual assessment criteria (due diligence checklist).
- Mandatory contractual clauses (transparency, audit, security, data, SLA, exit strategy).
- New provider approval process.
- Continuous monitoring of provider performance and risks.
- Exit procedure if the provider fails to comply or the relationship ends.
AI committee charter
The charter is the constitutive document of the AI committee. It defines its reason for being, its authority and its operations.
Charter structure
1. Mission
"The AI committee of [organization] has the mission of overseeing the responsible, ethical and regulation-compliant use of artificial intelligence in all activities of the organization, ensuring that AI systems generate business value without putting individuals' rights or regulatory compliance at risk."
2. Authority
The committee has the authority to approve or reject the acquisition, development and deployment of AI systems classified as restricted use. It can condition use on additional requirements. It can order the suspension of an AI system presenting unacceptable risks. It can request information from any area of the organization.
3. Composition
Permanent members (with vote): chair (CTO/CDO), DPO, CISO, legal officer, AI lead, business representative, HR lead. Guests (without vote): per agenda.
4. Quorum and decision-making
Quorum: simple majority of permanent members. Decisions: by consensus; if no consensus, by simple majority with the chair's casting vote. The DPO has veto power on personal data protection matters.
5. Operations
Frequency: monthly ordinary meeting. Notice: at least 5 working days in advance with attached materials. Minutes: drafted by the committee secretariat (AI governance officer), approved at the following meeting. Urgent decisions: written electronic voting procedure with a 48-hour deadline.
6. Reporting
Quarterly report to senior management/board with: activity summary, systems assessed, incidents managed, key metrics, emerging risks.
7. Charter review
Annual review. Changes approved by senior management/board.
Risk classification and management methodology
The methodology defines the systematic process for classifying and managing AI system risks in accordance with the AI Act and corporate risk frameworks.
Phase 1: Inventory and triage
Identify all AI systems (internal, SaaS, embedded). For each system, determine whether it meets the Article 3(1) definition of the AI Act. Initial triage: candidate for high-risk or not. Tool: standardised inventory form (15 fields, see TG05).
Phase 2: Classification
For each candidate system, walk through the complete decision tree (see TG02): exclusions, prohibitions, Annex I, Annex III, Art. 6(3) exceptions, transparency, minimal risk. Document the complete reasoning in the standardised classification form. Approve the classification by the AI governance officer.
Phase 3: Risk assessment
For high-risk and restricted-use systems, conduct a risk assessment covering:
- Risks to fundamental rights (FRIA, Art. 27).
- Data protection risks (DPIA, Art. 35 GDPR).
- Ethical risks (bias, fairness, explainability, autonomy).
- Operational risks (availability, integrity, continuity).
- Cybersecurity risks (adversarial attacks, exfiltration, manipulation).
Phase 4: Mitigation and residual risk
For each significant risk, define mitigation measures (technical, organisational, contractual). Assess the residual risk after mitigation. Determine whether the residual risk is acceptable. If not acceptable, escalate to the AI committee for a decision (additional mitigation, exceptional acceptance, system rejection).
Phase 5: Continuous monitoring
Define key risk indicators (KRIs) for each high-risk system. Configure automatic alerts (drift, degradation, disparity). Periodic reviews of the risk profile (quarterly for high-risk, annually for others). Reclassification upon triggers (see TG02).
AI audit plan
The audit plan defines the strategy for periodic verification of the governance programme and of individual AI systems.
Auditable universe
The auditable universe includes: each high-risk AI system (audited individually), the AI governance programme as a whole (policies, committee, processes), data and privacy controls applied to AI, cybersecurity controls for AI systems, AI provider management.
Audit frequency
- Critical high-risk systems: annual internal audit, external audit every 2-3 years.
- Non-critical high-risk systems: internal audit every 2 years.
- Governance programme: annual internal review, external audit every 3 years.
- Critical AI providers: annual contractual compliance review.
Methodology (summary)
Follow the 5-phase methodology described in TG06: planning, information gathering, analysis and evaluation, report, follow-up. Apply the article-by-article AI Act checklist. Collect documentary, technical, testimonial and observational evidence.
Resources
Audit team with AI, legal and cyber competencies. Specific training of the audit team on the AI Act and harmonised standards. Support tools: digitalised checklists, findings management platform, access to system logs and metrics.
Typical annual calendar
- Q1: audit cycle planning. Auditable universe update. Audit team training.
- Q2: audits of critical high-risk systems. Governance programme review.
- Q3: provider audits. Non-critical high-risk system audits.
- Q4: findings follow-up. Annual audit report to the AI committee. Next cycle planning.
Training programme
The training programme operationalises the AI literacy requirement of Article 4 of the AI Act and builds a culture of responsible AI use.
Programme structure
Level 1: Fundamentals (all employees)
- Format: self-paced e-learning + 1-hour live session.
- Duration: 3-4 hours total.
- Content: what is AI, the organization's AI use policy, approved tools, data rules, basic risks, inquiry channel.
- Assessment: final questionnaire (threshold: 80% correct).
- Frequency: onboarding + annual refresher.
- Evidence: completion record with date and questionnaire result.
Level 2: Operators (specific AI system users)
- Format: live in-person or virtual training, system-specific.
- Duration: 8-16 hours (depending on system complexity).
- Content: system capabilities and limitations, human oversight procedure, output interpretation, anomaly detection, escalation protocol.
- Assessment: practical case + questionnaire.
- Frequency: at system onboarding + refresher upon substantial system changes.
- Evidence: attendance record, assessment result, competency certification.
Level 3: Governance (AI committee, DPO, compliance, risk)
- Format: structured course (in-person or virtual), practical workshops.
- Duration: 24-40 hours spread over 3-6 months.
- Content: AI Act in detail, risk classification, DPIA/FRIA, auditing, NIS2/DORA, ethics, harmonised standards.
- Assessment: practical project (similar to this module's capstone project).
- Frequency: initial training + updates for regulatory changes.
- Evidence: formal certification, assessed project, continuing education hours record.
Level 4: Technical (developers, data scientists, MLOps)
- Format: technical workshops, hands-on labs, continuous training.
- Duration: 40+ hours, distributed throughout the year.
- Content: AI Act technical requirements, fairness testing (SHAP, LIME), Annex IV technical documentation, data governance, AI cybersecurity, adversarial testing.
- Assessment: practical implementation in a real system or sandbox.
- Frequency: continuous, integrated into professional development.
- Evidence: practice portfolio, technical certifications, continuing education record.
Governance metrics dashboard
A governance programme without metrics is a programme without visibility. The metrics dashboard allows the AI committee and senior management to assess the programme's effectiveness and make informed decisions.
Inventory and classification metrics
- Total registered AI systems: absolute number, monthly trend.
- Distribution by risk level: prohibited (should be 0), high, limited, minimal.
- Systems pending classification: should trend towards 0.
- Inventory coverage: percentage of business areas with complete inventory.
- Shadow AI detected: unregistered systems identified in audits or sweeps.
Compliance metrics
- High-risk systems with complete DPIA/FRIA: target 100%.
- High-risk systems with up-to-date audit: percentage per audit plan.
- Open non-conformities: number, by severity (major/minor), average closure time.
- Completed conformity assessments: before placing on the market/putting into service.
- EU database registrations: for high-risk systems that require it.
Risk metrics
- Reported AI incidents: number, by severity, by system.
- Average incident response time: from detection to containment.
- Fairness alerts triggered: number of alerts for disparity between groups.
- Drift alerts triggered: number of data/model drift alerts.
- Human intervention rate: percentage of decisions where the operator modifies the system's recommendation (per high-risk system).
Training metrics
- Level 1 training coverage: percentage of employees with completed training. Target: 100%.
- Level 2 training coverage: percentage of operators with completed specific training. Target: 100%.
- Pass rate: percentage passing the assessment on first attempt.
- AI training hours per capita: indicator of skills development investment.
Provider metrics
- Assessed AI providers: percentage with completed due diligence.
- Contracts with AI Act clauses: percentage of updated contracts.
- Providers with documented exit strategy: percentage.
- Provider-originated incidents: number and severity.
Report what matters
Not all metrics need to go to the board of directors. The quarterly board report should include a maximum of 5-7 high-level indicators: total systems, compliance coverage, serious incidents, emerging risks and training status. The detail stays with the AI committee.
Implementation plan
Implementing an AI governance programme from scratch is a 6-12 month project, depending on the organization's size and the number of existing AI systems.
Phase 1: Foundations (months 1-2)
- Approve the AI framework policy by senior management.
- Constitute the AI committee. Approve the charter.
- Designate the AI governance officer.
- Begin the AI system inventory.
- Launch Level 1 training for all employees.
Phase 2: Classification and assessment (months 3-5)
- Complete the AI system inventory.
- Classify all systems (decision tree, documentation).
- Conduct DPIAs/FRIAs for identified high-risk systems.
- Approve the acceptable use policy.
- Launch Level 2 training for high-risk system operators.
Phase 3: Controls and monitoring (months 6-8)
- Implement continuous monitoring for high-risk systems (performance, fairness, drift).
- Establish the AI incident management process.
- Review contracts with AI providers (AI Act, NIS2/DORA clauses).
- Approve the data for AI policy and the provider policy.
- Configure the metrics dashboard.
Phase 4: Verification and improvement (months 9-12)
- Execute the first round of internal AI audits.
- Remediate identified non-conformities.
- Launch Level 3 training for the AI committee and compliance.
- Assess the governance maturity level achieved.
- Prepare the first annual AI governance report for senior management.
- Plan the next cycle.
Critical success factors
- Senior management sponsorship: without visible CEO/CTO support, the programme will not gain traction. The AI committee's first decision should be communicated internally with explicit management backing.
- Pragmatism: do not seek perfection in the first cycle. An 80% inventory is infinitely better than no inventory. Iterate.
- Communication: the governance programme must be perceived as an enabler, not a blocker. Communicate the benefits: clarity, risk reduction, access to new regulated customers.
- Resources: assign realistic time and budget. A part-time (50%) AI governance officer is the minimum for a medium-sized organization.
Final project
Design a complete AI governance programme for an organization (your real organization or a fictitious one). The deliverable must include the following documents:
- AI framework policy (3-5 pages): vision, principles, scope, governance structure, regulatory compliance.
- Acceptable use policy (2-3 pages): use classification with at least 15 concrete examples, data rules, generated content, inquiry channel.
- AI committee charter (2 pages): mission, authority, composition, quorum, operations, reporting.
- Risk classification methodology (3-4 pages): adapted decision tree, classification form, reclassification process.
- Annual audit plan (2 pages): auditable universe, frequency, resources, calendar.
- Training programme (2-3 pages): 4 levels with content, duration, assessment, frequency and evidence.
- Metrics dashboard (1-2 pages): 15-20 KPIs organized by domain, with targets and measurement frequency.
- Implementation plan (1-2 pages): 4 phases, activities, deadlines and responsible parties.
Evaluation criteria: completeness (covers all components), internal coherence (documents reference each other), practicality (implementable, not pure theory), regulatory adequacy (complies with AI Act, GDPR, NIS2/DORA if applicable), context adaptation (reflects the characteristics of the chosen organization).
Recommended total length: 20-30 pages.
Puntos clave
Puntos clave from TG08 and the complete track
- An AI governance programme has 6 components: policies, committee, risk methodology, audit plan, training and metrics. All 6 are necessary; none is sufficient on its own.
- The policy suite has 4 documents: framework policy (strategic), acceptable use (operational), data for AI (technical) and AI providers (contractual).
- Metrics transform governance from "we do things" to "we can demonstrate our things work". A dashboard with 15-20 KPIs covers inventory, compliance, risk, training and providers.
- Implementation is a 6-12 month project in 4 phases: foundations, classification, controls and verification. The critical success factor is senior management sponsorship.
- The target for August 2026 is to reach Maturity Level 3 (Defined). This means: operational committee, complete inventory, high-risk systems assessed, training deployed and first audit cycle completed.
Guia de estudio — Conceptos clave de TG08
Vision general del proyecto
- Suite de politicas:la politica marco de IA, la politica de uso aceptable, la politica de datos para IA y la politica de proveedores de IA.
- Charter del comite de IA:el documento constitutivo del organo de gobernanza.
- Metodologia de riesgos:el proceso sistematico para clasificar y gestionar los riesgos de los sistemas de IA.
- Plan de auditoria:el programa de verificacion periodica del cumplimiento.
- Programa de formacion:la estrategia de alfabetizacion y capacitacion en IA por niveles.
- Dashboard de metricas:los indicadores que permiten medir la eficacia del programa.
Suite de politicas de IA
- - Declaracion de proposito:por que la organizacion adopta IA y por que necesita gobernanza. Vinculacion con la estrategia de negocio.
- Principios rectores:los valores que guian el uso de IA. Referencia a marcos internacionales (HLEG, OECD). Compromiso con transparencia, no discriminacion, supervision humana, privacidad, seguridad.
- Ambito de aplicacion:a quien aplica, que sistemas cubre, que queda excluido.
- Estructura de gobernanza:comite de IA, roles clave (CAIO, DPO, AI Risk Manager), modelo de tres lineas.
- Cumplimiento regulatorio:referencia al AI Act, RGPD, NIS2/DORA (si aplica), normativa sectorial.
- Revision y actualizacion:frecuencia de revision (anual minimo), proceso de aprobacion de cambios, responsable del mantenimiento.
Metodologia de clasificacion y gestion de riesgos
- Riesgos para derechos fundamentales (FRIA, art. 27).
- Riesgos de proteccion de datos (DPIA, art. 35 RGPD).
- Riesgos eticos (sesgo, fairness, explicabilidad, autonomia).
- Riesgos operacionales (disponibilidad, integridad, continuidad).
- Riesgos de ciberseguridad (ataques adversariales, exfiltracion, manipulacion).
Plan de auditoria de IA
- Sistemas de alto riesgo criticos:auditoria interna anual, auditoria externa cada 2-3 anos.
- Sistemas de alto riesgo no criticos:auditoria interna cada 2 anos.
- Programa de gobernanza:revision interna anual, auditoria externa cada 3 anos.
- Proveedores criticos de IA:revision anual de cumplimiento contractual.
- Q1:planificacion del ciclo de auditorias. Actualizacion del universo auditable. Formacion del equipo auditor.
- Q2:auditorias de los sistemas de alto riesgo criticos. Revision del programa de gobernanza.
Programa de formacion
- - Formato:e-learning autoguiado + sesion presencial de 1 hora.
- Duracion:3-4 horas totales.
- Contenido:que es la IA, politica de uso de IA de la organizacion, herramientas aprobadas, reglas de datos, riesgos basicos, canal de consultas.
- Evaluacion:cuestionario final (umbral: 80% aciertos).
- Frecuencia:onboarding + refresco anual.
- Evidencia:registro de completacion con fecha y resultado del cuestionario.
Dashboard de metricas de gobernanza
- Total de sistemas de IA registrados:numero absoluto, tendencia mensual.
- Distribucion por nivel de riesgo:prohibido (debe ser 0), alto, limitado, minimo.
- Sistemas pendientes de clasificacion:deberia tender a 0.
- Cobertura del inventario:porcentaje de areas de negocio con inventario completo.
- Shadow AI detectada:sistemas no registrados identificados en auditorias o barridos.
- Sistemas de alto riesgo con DPIA/FRIA completa:objetivo 100%.
You have completed the AI Governance track
Congratulations. With the 8 modules of this track you have the knowledge and the tools to design and implement a complete AI governance programme. The next step is to move from theory to practice in your organization.
Team training