--- name: ai-governance description: >- Design and operate AI governance: principles, decision rights, risk tiers, lifecycle gates, fairness, transparency, privacy, security, compliance mapping, maturity and board reporting across SaaS, API, self-hosted and agentic systems. Use to admit, update or retire Agent Skills, MCP servers and A2A capabilities; approve an agent for production actions; or decide earned-autonomy promotion, reduction or revocation. Cover GxP, ALCOA+, data integrity, electronic records, assurance and QMS interfaces for life sciences. Do not use for legal interpretation (legal-strategy), data-platform mechanics (data-architect/data-engineering), security implementation (secure-software-engineering), skill package inspection (agent-skills), or executing runtime changes (agent-production-operations). license: MIT compatibility: Agent-agnostic methodology; no external services, APIs, or runtime dependencies. The two scripts are Python 3 standard-library only. metadata: tags: ai-governance, responsible-ai, model-risk, ai-risk-management, governance-operating-model, ai-governance-principles, lifecycle-gates, fairness, transparency, privacy, llm-security, ai-regulation, ai-compliance, board-oversight, third-party-risk, governance-maturity, use-case-risk-tiering, model-cards, ai-audit, ai-oversight, deployment-posture, agentic-governance, tool-authorization, data-egress, memory-governance --- # AI Governance AI governance is the system an organization uses to decide, before a model is built and while it runs, who is accountable for an AI system, what risk it is allowed to carry, what evidence must gate each lifecycle stage, and how the organization reports and audits that posture. This skill teaches an agent to reason about and operate that system: it is a methodology skill, not a tool manual and not legal or security advice. ## Scope: What This Skill Owns | You own | You don't own | |---------|---------------| | Governance principles and how they translate into policy and controls | Drafting or opining on legal interpretation of a regulation | | The governance operating model: councils, stewards, decision rights, RACI, federated vs. centralized | Data-platform mechanics, pipelines, and lineage tooling internals | | Risk frameworks: NIST AI RMF, ISO/IEC 42001 & 23894, model-risk tiering, risk registers | Implementing authentication, authorization, or vulnerability fixes | | Lifecycle stage gates across ideation, build, evaluate, deploy, monitor, retire | CI/CD pipeline and deployment-gate configuration | | Cross-cutting 6L-G governance loop: strategy, impact, implementation, acceptance, operations, learning | Treating an author-developed framework as a regulatory or standards requirement | | Fairness, bias, transparency, explainability, and accountability controls | Product portfolio/roadmap governance cadences | | Privacy and data governance for training and operational data | Capital allocation, org structure, or M&A governance | | GxP AI governance overlay: ALCOA+, data integrity, electronic records, risk-based assurance, QMS interfaces | Legal applicability determinations, validation protocols, SOPs, or quality-system operation | | LLM/agent safety: prompt injection, exposure ladders, tool authorization, memory, egress, red-teaming, supply chain | Host-level or application-level security scanning | | Regulatory landscape and compliance mapping (as guidance, not advice) | Legal drafting, regulatory filings, or attorney-client work product | | Third-party and model due diligence, board reporting, audit | Any authoritative statement of "your system is compliant" | This is a **prevention-and-operations** methodology: it gives the agent frameworks, decision models, and controls to design and run governance, not a claim that a system is compliant or safe. For every engagement, record the operating model, the risk tier, the evidence that gated each stage, and the accountable owner of each accepted exception. ## When To Use Load this skill to answer "how should we govern this AI system?" — standing up or maturing a governance program, tiering use-case risk, designing the operating model and decision rights, reviewing an LLM/agent system for governance and safety gaps, mapping a regulation to a compliance/control plan, scoring governance maturity, or preparing board-level reporting. ## Capability admission and authority decisions For “may this capability enter or remain in our environment?”, read `references/capability-admission-and-update.md` and use `templates/capability-admission-record.md`. For “may this agent act?”, use the earned-autonomy path below. Admission approves a component at a recorded revision and configuration; it does not issue a runtime grant. Link the two records in one review when both decisions are needed. Reuse current evidence and existing authorized scope; request a new decision only for a material change or an unmet approval condition. ### Earned autonomy When setting agent promotion/demotion thresholds or reviewing earned autonomy, read `references/earned-autonomy.md` and use `templates/earned-autonomy-decision.md`. Support accountable humans making capability/environment/action-class decisions; the agent cannot grant itself authority. [site-reliability-engineering](../site-reliability-engineering/SKILL.md) supplies operational evidence and [agent-production-operations](../agent-production-operations/SKILL.md) implements the approved control plan. This five-level autonomy ladder is separate from the Six-Level Governance framework. ## Reference Files (load on demand, one per task) Progressive disclosure: load only the reference relevant to the current question. | Load when | Reference | |---|---| | Framing what AI governance is and its principles; governance vs. compliance vs. risk | [references/foundations-and-principles.md](references/foundations-and-principles.md) | | Designing the operating model, councils, stewards, decision rights, RACI, maturity, culture | [references/governance-operating-model.md](references/governance-operating-model.md) | | Applying NIST AI RMF, ISO/IEC 42001 & 23894, model-risk tiering, inherent vs. residual risk | [references/risk-management-and-frameworks.md](references/risk-management-and-frameworks.md) | | Placing stage gates across ideation, data, build, evaluate, deploy, monitor, retire | [references/ai-lifecycle-governance.md](references/ai-lifecycle-governance.md) | | Applying the Six-Level Governance framework, evidence loop, maturity, and posture overlay | [references/six-level-governance-framework.md](references/six-level-governance-framework.md) | | Fairness metrics and their limits, bias sources, trade-offs, algorithmic justice | [references/fairness-bias-accountability.md](references/fairness-bias-accountability.md) | | Explainability (XAI) methods, when explanation is required, disclosure, auditability | [references/transparency-and-explainability.md](references/transparency-and-explainability.md) | | Training/operational data governance, ownership, lineage, quality, consent, PETs, agentic memory, and purpose-aware egress | [references/privacy-and-data-governance.md](references/privacy-and-data-governance.md) | | AI used in GLP, GCP, GMP, GDP, or pharmacovigilance contexts; ALCOA+, data integrity, electronic records, audit trails, validation/assurance, and QMS interfaces | [references/gxp-and-data-integrity.md](references/gxp-and-data-integrity.md) | | Trust boundaries, prompt injection, exposure ladders, excessive agency, tool authorization, containment, supply chain, red-teaming | [references/llm-and-agent-security.md](references/llm-and-agent-security.md) | | Current law by jurisdiction, compliance mapping, enforcement, horizon scanning | [references/regulatory-landscape.md](references/regulatory-landscape.md) | | Vendor/model due diligence, supply chain, board reporting, metrics, audit | [references/procurement-third-party-and-board-oversight.md](references/procurement-third-party-and-board-oversight.md) | | Admitting, updating, disabling or retiring Skills, MCP servers or A2A capabilities | [references/capability-admission-and-update.md](references/capability-admission-and-update.md) | | Granting, promoting, reducing, suspending or revoking scoped agent authority | [references/earned-autonomy.md](references/earned-autonomy.md) | | Tracing any idea to its informing books and research notes; bibliography | [references/source-index.md](references/source-index.md) | ## Templates (fillable) Use these to turn the methodology into working artifacts. | Use when | Template | |---|---| | Recording capability admission, configuration changes, overlap and exit | [templates/capability-admission-record.md](templates/capability-admission-record.md) | | Recording scoped authority, evidence, counterevidence and independent approval | [templates/earned-autonomy-decision.md](templates/earned-autonomy-decision.md) | | Standing up the governance council and its terms of reference | [templates/governance-charter.md](templates/governance-charter.md) | | Registering a use case and classifying it at intake | [templates/use-case-intake-form.md](templates/use-case-intake-form.md) | | Running a NIST-aligned risk assessment and tiering worksheet | [templates/model-risk-assessment.md](templates/model-risk-assessment.md) | | Documenting a released model: intended use, data, performance, fairness, limitations | [templates/model-card.md](templates/model-card.md) | | Conducting vendor/model supply-chain due diligence | [templates/third-party-due-diligence.md](templates/third-party-due-diligence.md) | | Preparing executive/board AI-governance reporting | [templates/board-ai-governance-report.md](templates/board-ai-governance-report.md) | | Reviewing SaaS/API/self-hosted boundaries and agentic tools, actions, egress, memory, and evidence | [templates/agentic-governance-review.md](templates/agentic-governance-review.md) | ## Scripts Executable, flag-driven, stdlib-only Python CLIs with tests. Both accept a JSON input path and emit deterministic output; `--json` prints one JSON object on stdout; `--dry-run` previews without changing anything. Exit 0 on success; the maturity scorer also exits 1 on a critical posture, and both scripts exit 1 on input errors. | Use when | Script | |---|---| | Scoring an organization's governance maturity from dimension scores (1-5); emits maturity level + gaps | [scripts/governance-maturity.py](scripts/governance-maturity.py) | | Classifying an AI use case into a risk tier and its required controls | [scripts/use-case-risk-tier.py](scripts/use-case-risk-tier.py) | | Verifying the maturity scorer (unit + behavior tests) | [scripts/test_governance_maturity.py](scripts/test_governance_maturity.py) | | Verifying the risk-tier classifier (unit + behavior tests) | [scripts/test_use_case_risk_tier.py](scripts/test_use_case_risk_tier.py) | ## Evaluation and Configuration - **Eval manifest:** [evals/evals.json](evals/evals.json) holds the output-quality cases (operating model design, use-case risk tiering, 6L-G and deployment-posture review, agentic security and privacy review, impact-assessment closure, LLM-app governance review, fairness/accountability review, regulatory compliance mapping, board governance reporting, and GxP/data-integrity governance) used to grade this skill. - **Configuration:** [pytest.ini](pytest.ini) overrides the repository's root coverage settings so the subprocess-based skill tests run cleanly; do not add a second override. - **Entry points:** this [SKILL.md](SKILL.md) is the router; [README.md](README.md) is the human-facing overview for people evaluating whether to install the skill. ## When Not To Use Do not load this skill for work that belongs to a neighbor methodology or to execution: - **Regulatory/legal strategy.** Interpreting what a law or regulation *means*, structuring compliance legal risk, or preparing legal positions is `legal-strategy` work. This skill maps obligations to controls and records a defensible governance posture; it does not opine on the law. Prefer `legal-strategy` when the ask is legal interpretation, and return here to turn the resulting obligations into a control plan. - **Product operations and governance.** Recurring product decision cadences (intake, portfolio, roadmap, experiment, launch, lifecycle reviews) with evidence standards belong to `product-operations-and-governance`, not to this skill. This skill governs the *AI system's risk and accountability*, not the product portfolio cadence. - **Data-governance mechanics.** Building data catalogs, lineage pipelines, or platform storage internals is `data-architect` / `data-engineering` work. This skill consumes data governance as a control input but does not operate the data platform. - **Implementation-time security.** Writing authentication, authorization, input validation, or dependency hardening for an application is `secure-software-engineering` work. This skill sets the AI governance and safety controls and the risk tier; it does not implement the security mechanisms. - **Legal, financial, or security advice.** Nothing in this skill is legal, financial, or security advice. Regulatory and standards material must be re-verified against primary sources at the time of use. - **Other one-off decisions.** Use `adr-authoring` or `product-methodology` for general architectural or product decisions. Individual AI capability admission and authority decisions remain in this skill. ## Related Skills (routing) | When you need... | Route to | |---|---| | Regulatory and board-legal strategy, legal interpretation | [legal-strategy](../legal-strategy/SKILL.md) | | Data-governance mechanics: catalogs, lineage, platform internals | [data-architect](../data-architect/SKILL.md) or [data-engineering](../data-engineering/SKILL.md) | | Implementing application and system security controls | [secure-software-engineering](../secure-software-engineering/SKILL.md) | | Recurring product decision cadences and evidence standards | [product-operations-and-governance](../product-operations-and-governance/SKILL.md) | | A single durable architectural decision record | [adr-authoring](../adr-authoring/SKILL.md) |