Enterprise AI governance

AI governance begins with deciding who is allowed to decide.

Governance is not a policy document sitting beside the technology. It is the operating system for accountability: who owns the AI use case, what the system may access, which actions it may take, where a person must intervene, and what evidence proves the boundary was respected.

TEMRIK's architecture direction is to translate approved governance rules into enforceable controls around data, models, agents, tools and consequential action.

accountability · policy · risk · authority · evidence · exceptions · incidents · evaluation

Governance execution path

01

Board / executive policy

Objectives · risk appetite · prohibited uses · accountability

02

AI governance rules

Risk class · data class · model conditions · decision rights

03

TEMRIK policy layer

Architecture direction: machine-enforceable operating boundary

04

Data / model / agent / tool / action

Every material capability is evaluated against policy

05

Allow / restrict / approve / escalate / deny

A visible control decision, not silent model discretion

06

Audit

Decision, approver, exception and outcome evidence

What governance is

Governance is the system that turns accountability into repeatable decisions.

Good AI governance connects strategy, risk, ownership, policy, technical controls, human authority, evidence and review. NIST treats governance as a cross-cutting function across the AI lifecycle; ISO/IEC 42001 frames it as a management system that is continually improved.

Purpose
Owner
Risk class
Data boundary
Model conditions
Agent authority
Tool rights
Human approval
Evaluation
Incident path
Evidence
Review

Policy on paper vs policy in execution

Interactive explorer

Turn policy into an operating decision.

Select a governance area to see the rule, business example, TEMRIK control, human owner and evidence that should remain afterwards.

Selected control

Model policy

Rules governing which model paths may be used.

Policy rule

Approved model classes by workload and data type.

Business example

Sensitive contract analysis must use an approved route.

TEMRIK control

Routing policy outside the prompt.

Human owner

AI / technology owner

Evidence retained

Model route + policy result.

Policy on paper

“Do not send confidential data to unapproved AI.”

  • Relies on memory and judgement.
  • May be bypassed by an agent, integration or tool.
  • Can be difficult to test or audit.
  • Often says what people should do without defining what the system can do.

Policy in execution

The confidential-data rule becomes an operating boundary.

Classify data
Check tenant + user
Check approved provider
Restrict retrieval
Restrict tools
Require approval
Log exception
Deny when boundary fails

A policy the AI cannot be forced to follow is not yet an operating control.

Responsibility matrix

The model cannot own accountability.

Accountability stays with the organisation. The precise structure varies by size and jurisdiction, but every material AI system needs visible owners for purpose, risk, technical control and consequential decisions.

Board / governing body

Set risk appetite, oversight expectations and material accountability.

Oversight

Executive owner

Own enterprise AI policy, resources, risk acceptance and escalation.

Accountable

Business process owner

Define the purpose, operating rules, exceptions and acceptable outcomes.

Responsible

Risk / legal / privacy / security

Map obligations, controls and assurance requirements.

Control

Technical owner

Implement identity, data, model, agent, tool and observability controls.

Implementation

Human approver

Retain decision rights for actions that remain outside delegated AI authority.

Authority

Internal audit / assurance

Test whether declared controls are operating as intended.

Assurance

AI risk classes

Govern the use case, not just the model name.

The same model can support a low-consequence drafting task or a consequential workflow affecting money, customers, employees, rights, contracts or safety. Risk classification should follow the actual context, authority and impact.

Class 1

Assistive

Drafting, summarising, retrieval and low-consequence support.

Standard
Class 2

Operational

AI participates in bounded internal workflows with defined controls.

Enhanced
Class 3

Consequential

AI can materially affect customers, money, rights, contracts, safety or regulated activity.

High
Class 4

Restricted

Use case is prohibited, legally constrained, outside policy, or lacks sufficient control.

Deny / redesign

Governance domains

Every capability needs a defined boundary.

Model governance

Approved providers, use cases, data classes, retention conditions, evaluation criteria and change review.

Data governance

Purpose, classification, provenance, access, minimisation, retention and authorised retrieval.

Agent governance

Identity, owner, purpose, tools, delegation rights, action ceiling, expiry, stop conditions and revocation.

Tool governance

Allowed systems, operations, parameters, credentials, write permissions, rate limits and high-risk actions.

Action governance

Which outputs may remain advisory, which require approval and which actions may be pre-authorised.

Evidence governance

What must be recorded so material decisions, approvals, exceptions and incidents can be reconstructed.

The model may propose. The operating architecture decides whether the proposal may become an action.

TEMRIK policy layer

A governance rule should resolve to a control decision.

TEMRIK's policy-layer concept is designed to sit outside the model. The model should not be trusted to decide whether its own authority is valid.

LIVE CONTROL: human approvalCONFIGURABLE: policy boundariesPROVIDER DEPENDENT: model controlsARCHITECTURE DIRECTION: policy engine
ALLOW

Inside declared purpose, approved data class, approved tool and delegated authority.

RESTRICT

Proceed only with narrowed data, tool scope, model, amount, recipient or action.

APPROVE

Pause for an authorised human before consequential release.

ESCALATE

Route uncertainty, exception, conflict or material risk to a named owner.

DENY

Block activity outside policy, authority or legal / security boundary.

Human decision rights

Human oversight must be specific enough to operate.

“Human in the loop” is too vague unless the organisation defines who the human is, what they must review, which evidence is required, the authority they hold, how conflicts are handled and what happens when they decline or do not respond.

Recommend

AI can analyse and propose; a person decides.

Prepare

AI can assemble a draft action; a person authorises release.

Act within ceiling

Pre-authorised low-consequence action inside explicit limits.

Escalate

Exceptions, uncertainty and conflicts route to a named owner.

Revoke

Human authority can suspend the agent, tool, provider or workflow.

Evidence and audit

Governance that cannot be evidenced is difficult to assure.

The objective is not to expose private model reasoning. It is to retain operational evidence showing the declared purpose, applicable boundary, material inputs, approvals, exceptions and released actions.

AI system / use-case register
Named accountable owner
Purpose and intended users
Risk classification
Approved models and providers
Data classes and retrieval boundaries
Agent and tool permissions
Evaluation results
Human approval requirements
Exceptions and risk acceptances
Incidents and corrective actions
Change history and review dates

Exceptions, incidents and change

Governance is tested when the normal path breaks.

Exceptions

Record the request, business reason, risk owner, compensating controls, expiry and approval. Exceptions should not silently become permanent policy.

Incidents

Define reporting, containment, evidence preservation, affected-system review, notification duties, corrective action and reactivation criteria.

Change

Reassess when the provider, model, data source, tool, permissions, use case, regulation or consequence profile materially changes.

Evaluation

Policy needs tests, not only statements.

Evaluation should test whether the system performs its intended work and whether it respects the governance boundary under normal, edge, malicious and failure conditions.

Task quality
Data minimisation
Policy compliance
Tool selection
Permission boundary
Human escalation
Adversarial input
Missing evidence
Provider failure
Incident containment
Audit reconstruction
Revocation

Regulatory mapping

Build one control architecture. Map it to the obligations that actually apply.

NIST, ISO, OECD, the EU AI Act, UK management guidance and Australian guidance are not interchangeable legal instruments. They do, however, converge on recurring governance themes: accountability, risk management, documentation, oversight, transparency, security, evaluation and lifecycle review.

NIST AI RMF

Voluntary risk-management framework; GOVERN spans the lifecycle.

ISO/IEC 42001

Certifiable management-system standard. TEMRIK does not claim certification.

OECD AI Principles

International principles supporting human-centric, trustworthy AI and accountability.

EU AI Act

Binding EU regulation with obligations that vary by role and AI-system category.

UK AIME

Practical organisational management guidance and self-assessment.

Australia

Current government guidance emphasises accountability, risk management and human oversight; existing law continues to apply.

Governance maturity

Mature governance moves from advice to operating evidence.

01

Ad hoc

Teams use AI with local judgement and limited visibility.

02

Documented

Policies, approved tools, registers and named owners exist.

03

Controlled

Policy is translated into identity, access, tool, model and approval controls.

04

Measured

Evaluations, incidents, exceptions and operating evidence are routinely reviewed.

05

Adaptive

Controls change with risk, regulation, provider capability and operating evidence.

TEMRIK governance architecture

The policy should sit above the model, the agent and the tool.

Explore the TEMRIK AI control plane: an architecture for keeping company data, operating rules, agent permissions, human authority and evidence independent of whichever model is selected for the work.

Product reality matters. Some controls are live today; others are configurable, provider-dependent or architecture direction. TEMRIK does not claim ISO/IEC 42001 certification, regulatory approval or universal enforcement across every third-party system.

Policy

Purpose · risk · data · model · agent · tool · action

Control

Allow · restrict · approve · escalate · deny

Authority

Named human decision rights and revocation

Evidence

Audit trail, exceptions, incidents and evaluation

Research basis

Current primary sources, linked directly.

Governance requirements depend on jurisdiction, sector, role and use case. These references inform the architecture and should be rechecked when designing a specific customer deployment.

Free field guide

27 Rules of Peace

Governance gets easier when the rules of the work are explicit.

TEMRIK's free field guide explores evidence, decision rights, escalation and practical playbooks for keeping human authority visible when AI enters operational workflows.

Governance boundary

Map your AI governance boundary.

Start with one real workflow. Define the owner, risk class, data boundary, models, agents, tools, human decision rights, evidence and escalation path before authority expands.

AI can become more capable.The organisation should remain accountable for what it is allowed to do.