AI governance fails when it remains a document. It succeeds when it becomes a repeatable operating model that business, risk, technology and delivery teams can run together.
This guide outlines a practical structure for enterprise AI governance: a living inventory of use cases and systems; proportionate risk classification; approval pathways matched to impact; lifecycle monitoring; and evidence that leadership and assurance teams can trust.
We distinguish policy intent from operating controls. Policy states what must be true. Operating controls define who acts, what artefacts are produced, which systems record status and how exceptions are handled.
Generative and agentic systems introduce new failure modes — including over-reliance, prompt injection exposure, uncontrolled tool use and opaque reasoning. Governance models must therefore cover both traditional machine learning and newer interaction patterns under one institutional framework.
The guide closes with a staged adoption path: establish intake and inventory, classify risk, stand up approval and monitoring routines, then connect governance reporting to CoE prioritisation and board oversight.
Inventory quality is the first bottleneck. Record the decision supported, data classes touched, model or vendor involved, accountable owner, residual risk tier and current lifecycle stage. Incomplete inventories make every later control performative.
Risk classification should be proportionate. Low-impact advisory assistants should not carry the same approval burden as systems that influence credit, hiring, benefits or public services. Clear tiers prevent both under-control of high-impact systems and bureaucracy that drives shadow AI.
Evidence is what leadership actually reviews. Status dashboards, exception queues, evaluation summaries and change records must be available in a form assurance teams can test. If evidence cannot be produced on a predictable cadence, the operating model is not yet real.