Logiciel Solutions Contact Us
Success Stories Tech News Investors Contact Us
playbook

AI Governance Operations Runbook.

A governance programme is built once and operated forever. Blueprints describe the built state, and almost nothing describes the operated state, which is why so many programmes look strong at month six and have quietly stopped by month eighteen. This is the operated state: the recurring procedures, who runs them, what they consume and what they produce. Every procedure produces a dated artifact, because a procedure with no output cannot be shown to have run, and every one names its most common failure, because those failures are predictable and each has a cheap structural fix.

In depth

Unscheduled Work Does Not Survive A Busy Quarter.

01

What happens by default: the programme is built but never scheduled.

Nothing becomes recurring work with a named owner. Triage slips to fortnightly, then monthly, and teams start building before tiering. The register gets reconciled against itself rather than an independent sweep, so coverage is always 100% and always wrong. The monthly meeting becomes a status update with no decisions in it. Risk acceptances pile up with expiry dates in the past, which means acceptance has quietly become permanent approval by default.

In shortRisk acceptances pile up with expiry dates in the pa…
02

What operating discipline does: it puts every procedure in a calendar.

Each gets an individual owner before any of them runs, and each one produces a dated artifact. The independent sweep is run by somebody who does not own the register. The monthly meeting gets cancelled when there is nothing to decide, rather than held hollow and teaching people it is optional. And the handover pack gets assembled now, while what is obvious to you is still obvious, because the largest continuity risk at this scale is that one person leaves.

In shortAnd the handover pack gets assembled now, while what…
The detail

What Makes This A Runbook, Not A Process Diagram.

Three things separate a documented process from an operated one. Each is a small discipline that compounds over a year.

Zone · 01

Every step has a definition of done

Assign a tier is not a step. Assign a tier and name the specific rubric dimension that set it, with the justification recorded on the ticket, is a step, because the second can be audited and the first cannot. Pairing every action with what done looks like is the difference between a process that can be handed over and one that lives in somebody's head.

Zone · 02

A named failure mode per procedure

Triage slips, so give it a standing slot and a queue view on the owner's own dashboard. The response pack ossifies, so make updating it a required step before a deal record can close. Reassessment only happens at renewal, so subscribe to provider changelogs and treat a deprecation as a trigger. Each failure is predictable and each fix is structural rather than exhortation.

Zone · 03

The response pack compounds

Answer from the pack first, so sixty to eighty percent of questions need no engineering involvement. Batch genuinely new questions rather than forwarding them one at a time. Add every new answer back before the deal record closes. Flag anything three customers have asked, because a recurring question is a roadmap item rather than a documentation problem.

By the numbers

The figures that make it a board-level conversation.

150
person-days a year to operate the programme, about 0.68 of a full-time equivalent
90-100
net-new person-days once you subtract effort already being spent unsystematically
40-60%
the reduction in customer security review time once the response pack compounds
Inside the report

What you'll take away.

01

Step 1 - Put all ten procedures in a shared calendar

With an individual owner on each, before running any of them. This single act predicts survival at month eighteen better than any maturity score.

02

Step 2 - Run triage weekly and reconcile quarterly

Thirty minutes a week to tier and route new use cases, and half a day a quarter to reconcile the register against a sweep run by somebody who does not own it.

03

Step 3 - Report four metrics monthly, the score quarterly

Registry coverage, high-risk control completeness, intake bypass rate and evidence freshness, with three sentences on what moved and what you are doing about the worst one.

04

Step 4 - Assemble the handover pack while it is obvious

Ten items a new owner needs on day one, from a register current within thirty days to the calendar of procedures with owners on each.

Questions

Frequently asked.

How much time does running AI governance actually take?

Roughly 150 person-days a year spread over six people, about 0.68 of a full-time equivalent. The AI risk owner carries the largest share at roughly a day a week. Everyone else is between two and four hours a month, except product owners who contribute per review. Roughly a third of the total is effort already being spent unsystematically.

What should the monthly governance meeting cover?

Six items in sixty minutes: the four metrics with their change, high-risk decisions with rationale, any open risk acceptance closed or extended with an explicit date, incident review ending in a named control change, horizon items, and actions. The minutes are the decision log. If there is nothing to decide, cancel it.

How do we keep the AI register from going stale?

Feed it from a trigger rather than by hand: procurement, architecture review, the deploy pipeline. Then reconcile quarterly against an independent sweep from SSO logs, SaaS spend, egress telemetry and dependency scanning. The sweep must be run by someone who does not own the register.

What metrics should we report to the board?

Registry coverage, high-risk control completeness, intake bypass rate and evidence freshness, monthly, with three sentences on what moved. Not the maturity score monthly: it moves slowly, invites debate about scoring rather than action, and gives leadership no lever. Send that quarterly.

What happens if the person running this leaves?

That is the largest continuity risk at this scale, which is why there is a handover pack. Ten items: register current within thirty days, the complete decision log, open risk acceptances with expiry dates, the evidence index, the policy set with version history, the response pack, vendor assessments, the last four scorecards, named contacts, and the procedure calendar.

How do we know if the programme has quietly stopped?

Three tells. The register has not changed in six weeks, which usually means intake is being bypassed. Every risk acceptance has an expiry date in the past, meaning acceptance has become permanent approval. Or the monthly meeting has had no decisions for two months, which usually means triage stopped.

Get the playbook

Have it emailed to you.

Drop your details and we'll send AI Governance Operations Runbook straight to your inbox - no spam, unsubscribe anytime.

Download playbook
Next step

Schedule it, or it stops.

Bring us your operating calendar and we will pressure-test it against the procedures that usually slip first. A working session, not a sales pitch. SECTION 7 - FAQ - 5 to 8 questions

Talk to our engineers