A governance programme is built once and operated forever. Blueprints describe the built state, and almost nothing describes the operated state, which is why so many programmes look strong at month six and have quietly stopped by month eighteen. This is the operated state: the recurring procedures, who runs them, what they consume and what they produce. Every procedure produces a dated artifact, because a procedure with no output cannot be shown to have run, and every one names its most common failure, because those failures are predictable and each has a cheap structural fix.
Three things separate a documented process from an operated one. Each is a small discipline that compounds over a year.
Assign a tier is not a step. Assign a tier and name the specific rubric dimension that set it, with the justification recorded on the ticket, is a step, because the second can be audited and the first cannot. Pairing every action with what done looks like is the difference between a process that can be handed over and one that lives in somebody's head.
Triage slips, so give it a standing slot and a queue view on the owner's own dashboard. The response pack ossifies, so make updating it a required step before a deal record can close. Reassessment only happens at renewal, so subscribe to provider changelogs and treat a deprecation as a trigger. Each failure is predictable and each fix is structural rather than exhortation.
Answer from the pack first, so sixty to eighty percent of questions need no engineering involvement. Batch genuinely new questions rather than forwarding them one at a time. Add every new answer back before the deal record closes. Flag anything three customers have asked, because a recurring question is a roadmap item rather than a documentation problem.
With an individual owner on each, before running any of them. This single act predicts survival at month eighteen better than any maturity score.
Thirty minutes a week to tier and route new use cases, and half a day a quarter to reconcile the register against a sweep run by somebody who does not own it.
Registry coverage, high-risk control completeness, intake bypass rate and evidence freshness, with three sentences on what moved and what you are doing about the worst one.
Ten items a new owner needs on day one, from a register current within thirty days to the calendar of procedures with owners on each.
Roughly 150 person-days a year spread over six people, about 0.68 of a full-time equivalent. The AI risk owner carries the largest share at roughly a day a week. Everyone else is between two and four hours a month, except product owners who contribute per review. Roughly a third of the total is effort already being spent unsystematically.
Six items in sixty minutes: the four metrics with their change, high-risk decisions with rationale, any open risk acceptance closed or extended with an explicit date, incident review ending in a named control change, horizon items, and actions. The minutes are the decision log. If there is nothing to decide, cancel it.
Feed it from a trigger rather than by hand: procurement, architecture review, the deploy pipeline. Then reconcile quarterly against an independent sweep from SSO logs, SaaS spend, egress telemetry and dependency scanning. The sweep must be run by someone who does not own the register.
Registry coverage, high-risk control completeness, intake bypass rate and evidence freshness, monthly, with three sentences on what moved. Not the maturity score monthly: it moves slowly, invites debate about scoring rather than action, and gives leadership no lever. Send that quarterly.
That is the largest continuity risk at this scale, which is why there is a handover pack. Ten items: register current within thirty days, the complete decision log, open risk acceptances with expiry dates, the evidence index, the policy set with version history, the response pack, vendor assessments, the last four scorecards, named contacts, and the procedure calendar.
Three tells. The register has not changed in six weeks, which usually means intake is being bypassed. Every risk acceptance has an expiry date in the past, meaning acceptance has become permanent approval. Or the monthly meeting has had no decisions for two months, which usually means triage stopped.
Drop your details and we'll send AI Governance Operations Runbook straight to your inbox - no spam, unsubscribe anytime.
Bring us your operating calendar and we will pressure-test it against the procedures that usually slip first. A working session, not a sales pitch. SECTION 7 - FAQ - 5 to 8 questions
Talk to our engineers