AI Governance, Risk & Red Teaming
Strategic · M2 · lesson 2 of 25 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
AI Governance Committee - Charter, Membership, Cadence (2026)
📖
now learning

AI Governance Committee - Charter, Membership, Cadence (2026)

15 min

Maya Okafor was promoted to Chief Risk Officer of Acme Inc on the first Monday of January 2026 with one explicit additional mandate: chair the AI Governance Committee her predecessor had stood up in late 2025 with a one-page charter, a rotating membership list, and a meeting cadence that drifted between "monthly" and "when something breaks." Her first meeting agenda, set the week before by the Chief Legal Officer, contained a single item, approve the deployment of a tier-1 fraud-decisioning agent into the European retail-banking unit, sign-off needed by Friday for a go-live the business had already announced to the board's Innovation Subcommittee. The meeting ran 90 minutes. The committee did not approve. It did not reject either. It discovered, three minutes into Maya's reading of the FRIA, that no one in the room could point to a written enterprise AI risk appetite statement, that the "decision rights" the IT Change Advisory Board had been operating under for AI deployments since 2024 had never been ratified by anyone other than the CIO, that the Chief Compliance Officer believed the committee's decisions were advisory while the Chief Legal Officer believed they were binding, and that the Internal Audit lead present was an active voting member of a body she was supposed to assure independently as third line. The fraud-decisioning agent did not deploy that Friday. The committee adjourned with one homework item, write the charter you should have written before you ever met. Lesson 072 is the L4 pivot. You are no longer building practitioner-tier artifacts (model cards, FRIAs, DDQs, ML-BoMs). You are designing the operating model that decides which artifacts get built, by whom, on what cadence, with what authority, against what risk appetite. This lesson covers why the AI Governance Committee (AIGC) is a regulator expectation in 2026 under ISO 42001 A.3, EU AI Act Article 17, NIST AI RMF Govern, and SR 11-7 + PRA SS1/23; the 15-section charter every AIGC needs; the 8-12-person membership and the decision-rights matrix separating AIGC, IT change-board, and Board AI Subcommittee authority; the cadence, agenda, and metrics dashboard that make the committee operationally real; and the worked Acme Inc 2026 example: 11 members, monthly + quarterly extended, three-month decision log.

Why an AI Governance Committee Is a Regulator Expectation in 2026

The AI Governance Committee is not optional infrastructure in 2026. It is the named or implied accountability forum across every operating standard a regulated organisation must satisfy, and the absence of one is now visible to auditors, notified bodies, and supervisors as a first-order governance defect.

ISO/IEC 42001:2023 A.3 - Leadership and accountability. Annex A control A.3 of the AI Management System standard requires "top management" to demonstrate leadership and commitment to the AIMS: establishing AI policy, ensuring objectives align with strategy, integrating AIMS requirements into business processes, providing resources, and "supporting other relevant management roles to demonstrate their leadership as it applies to their areas of responsibility." A.3 reads as boilerplate until you ask the operational question: what body actually does this work, on what cadence, with what evidence? The 2024-2025 BSI and SCC accredited-certification audits made the answer explicit: auditors expect to read minutes, decision logs, and an action tracker from a standing leadership forum. The AIGC produces them. A.4 (organisational structure and roles) compounds the expectation by requiring documented allocation of AIMS roles; the AIGC charter is where the allocation is ratified.

EU AI Act Article 17 - QMS, top-management responsibility. Article 17(1) requires providers of high-risk AI systems to "put in place a quality management system that ensures compliance with this Regulation." Article 17(2) lists thirteen QMS elements: including risk management per Article 9, post-market monitoring per Article 72, incident reporting per Article 73, accountability framework, and management responsibility. The last item is the AIGC hook. The QMS is signed by management; the AIGC operates the signature meaningfully. Article 17 failures expose to Article 99(3) administrative fines up to €15M or 3% of worldwide annual turnover (whichever is higher). The same fine tier applies to Article 26 deployer obligations and most provider-side breaches, AIGC discipline reduces penalty exposure across the most-fined article cluster of the entire Regulation.

NIST AI RMF Govern 1.1, 1.5, 2.1, 3.1, 4.1, 5.1. The Govern function operates almost entirely through committee-shaped activity. Govern 1.1 requires "legal and regulatory requirements involving AI" to be "understood, managed, and documented." Govern 1.5 requires "ongoing monitoring and periodic review of the risk management process and its outcomes." Govern 2.1 requires "roles, responsibilities, and lines of communication" to be "documented and clear", charter and RACI as evidence. Govern 3.1 covers workforce diversity, equity, inclusion in AI risk decisions, committee composition. Govern 4.1 covers organisational practices fostering critical thinking, committee culture. Govern 5.1 covers stakeholder engagement, committee external interface. The NIST functions read like a job description for an AIGC because that is what they describe.

SR 11-7 + PRA SS1/23 + OCC 2011-12, governance pillar. The model-risk anchor documents (lesson 067) require board-approved governance frameworks, defined roles, three-lines-of-defense discipline, and management oversight. For banks deploying generative AI under SR 11-7's third pillar and SS1/23's Principle 2 governance, the AIGC is typically the named forum where model-risk findings escalate, tier-1 approvals are issued, and the CRO carries management responsibility. The 2024-2025 OCC and PRA Dear CEO letters on generative AI specifically referenced "appropriate governance forums", absence is examiner-visible.

OECD + UNESCO + DORA + NIS2 nexus. The 2019 OECD AI Principles (revised 2024) and the November 2021 UNESCO Recommendation both call for "responsible stewardship of trustworthy AI" with named accountability, language that 2025-2026 public-sector procurement now translates into supplier-attestation questions about "the governance body responsible for AI risk." Vendors without an AIGC charter lose points. Separately, DORA (in force January 2025 for EU financial entities) and NIS2 (national transposition 2024-2025) require board-level oversight of ICT and cybersecurity risk including AI systems; the AIGC charter must name the cyber-resilience touchpoint or duplicate work drifts apart at the first incident.

The L4 pivot. Levels 1-3 trained practitioner artifacts, read a model card; write a FRIA; build a DDQ; review an ML-BoM. Level 4 trains the operating model that decides which artifacts get built, by whom, with what authority, against what risk appetite. The AIGC is the central node. Without its charter, membership, agenda, decision rights, and escalation pathways, the practitioner artifacts will continue to be produced: but they will not be acted on, ratified, or defensible at examination.

The AI Governance Committee Charter - Fifteen Sections

The AIGC charter is the foundational governance artifact. ISO 42001 auditors, notified bodies under EU AI Act conformity assessment, and regulated-industry examiners all expect to read it. The 2026 standard structure runs to fifteen sections; abbreviated charters covering only purpose and membership are common failure modes. The full structure follows.

Section 1 - Purpose. A single paragraph stating why the AIGC exists. Standard 2026 language: "The AIGC is the executive-level cross-functional forum accountable for the oversight of AI risk, compliance, and ethical use across [Organisation], operating as the second-line governance forum within the AI three-lines-of-defense model and reporting into the [Board AI Subcommittee / Board Risk Committee] quarterly. The AIGC is established to satisfy the leadership accountability requirements of ISO/IEC 42001:2023 Annex A.3, EU AI Act Article 17, NIST AI RMF Govern, and applicable MRM supervisory guidance including SR 11-7, OCC Bulletin 2011-12, and PRA SS1/23 where in scope."

Section 2 - Scope. All AI systems and GPAI models in scope of the AI policy stack regardless of risk tier; all GPAI deployments (provider or deployer); all third-party AI services in the vendor inventory; all in-development systems. Out of scope: pure rule-based automation without ML; statistical models governed exclusively under existing MRM frameworks (with AIGC notification on classification disputes). Explicit dual-listing, a model can be in scope of MRM and AIGC simultaneously, with AIGC on AI-specific risk and MRM on model-risk discipline.

Section 3 - Authority. The decision rights delegated by board or CEO, and the limits. Standard language: "The AIGC has authority to (a) ratify the enterprise AI risk appetite statement; (b) approve or reject tier-1 AI system deployments and tier-1 substantial modifications; (c) ratify changes to the AI policy stack; (d) accept findings from independent model validation, internal audit, and red-team at tier-1 severity; (e) authorise the organisation's posture on regulator engagement related to AI; (f) require remediation across business units. The AIGC may escalate to the Board AI Subcommittee. The AIGC does not have authority to override applicable law, regulation, or board-approved enterprise risk appetite without explicit board authorisation."

Section 4 - Membership composition. The named roles and the rationale for each. The 8-to-12-member structure with chair, vice-chair, secretary, voting members, and observer status is the 2026 default, see the next H2 for the detailed composition rationale.

Section 5 - Role-specific responsibilities. What each member brings and is accountable for. Chair: agenda ratification, meeting facilitation, decision certification, board reporting. Each voting member: domain expertise contribution, escalation from their function, ratification authority on decisions. Secretary: minutes, decision log, action tracker, document retention. Observer (Internal Audit): third-line independence preservation; attendance for visibility without voting authority.

Section 6 - Decision rights matrix. A RACI-style table mapping decision types to bodies: AIGC, IT Change Advisory Board, Board AI Subcommittee, business-unit head, model owner. The matrix is the dispute-resolution device that prevented (or did not prevent) the 90-minute Acme debate that opens this lesson. See the next H2 for the full matrix.

Section 7 - Cadence. Standing meetings monthly. Extended sessions quarterly with metrics dashboard review and three-month outlook. Ad-hoc trigger-based sessions for tier-1 approvals on a 5-business-day window. Emergency sessions on regulator inquiry or serious incident under Article 73, within 48 hours of notification. Annual offsite for risk appetite refresh and charter review.

Section 8 - Quorum and decision threshold. Quorum at 60% of voting members with chair or vice-chair present. Standard decisions by simple majority of present voting members. Risk-appetite ratification and AI policy stack ratification by two-thirds majority. Tier-1 deployment approval by simple majority but recorded individually with named dissent. Reserved decisions to chair (e.g., emergency-incident interim action pending next session) explicitly enumerated.

Section 9 - Standing agenda template. Eight items, fixed order, used as the meeting opener every session unless the chair documents an explicit variation. See the cadence-and-agenda H2 below for the full template.

Section 10 - Escalation triggers to the AIGC. The defined conditions that route a matter into AIGC consideration: tier-1 deployment approval; substantial modification per Article 25(1)(a) or Article 43(4); serious incident under Article 73; fairness slice failure beyond policy thresholds; regulator inquiry; vendor breach affecting an AI system; ICT third-party concentration risk per DORA Article 28; AI literacy training compliance below threshold; FRIA backlog above threshold; red-team finding at tier-1 severity.

Section 11 - Reporting line. AIGC reports to the Board AI Subcommittee (or, absent one, the Board Risk Committee) quarterly via written report and at least one annual in-person briefing, with ad-hoc reporting on serious incidents, regulator engagement, and material risk-appetite breaches.

Section 12 - Ratification standard. What "ratified by the AIGC" means as an audit-visible standard: the matter appears on an agenda; minutes record the discussion; the decision log records the outcome with named voters and dissent; the action tracker captures follow-up; the relevant policy or artifact records the AIGC ratification reference. Three layers of evidence, agenda, minutes, decision log, must align for an external auditor to accept a decision as ratified.

Section 13 - Document retention. Agendas, minutes, decision logs, and action trackers retained for the longer of ten years from decision date, the retention period of the relevant AI system plus five years, or the period required by applicable regulation (including EU AI Act Article 18, technical documentation, ten years post-market, and GDPR). Records held in the AIGC document repository with access restricted to AIGC members, Internal Audit, the AI Office, and on legitimate business need.

Section 14 - Charter-review cadence. Reviewed annually at the AIGC offsite, ratified or amended by AIGC vote; material amendments endorsed by the Board AI Subcommittee. The 2026 expectation is at least one substantive amendment per annual cycle as the operating model matures.

Section 15 - Signatures. The CEO, the Chair (CRO or CAIO per industry context), and the Chair of the Board AI Subcommittee sign. Date of effect, version number, and previous-version reference are recorded. The signature page is the artifact an ISO 42001 auditor reads to confirm A.3 leadership commitment is real.

Membership Composition and the Decision-Rights Matrix

Membership composition is where charter-on-paper becomes operationally real or operationally toothless. The 2026 default is 8-12 voting members plus 2-3 observers, chosen by role rather than by individual so the committee survives personnel change without re-chartering.

Chair - CRO or CAIO. In regulated industries (banking, insurance, healthcare, critical infrastructure) the Chief Risk Officer typically chairs because regulatory accountability already routes to that role under SR 11-7, PRA SS1/23, Solvency II, and equivalents. In technology-native and non-regulated firms, a Chief AI Officer reporting to the CEO commonly chairs because AI is a strategic-portfolio function rather than risk-defence. The 2026 hybrid posture, CRO chair, CAIO vice-chair, balances supervisory accountability with strategic enablement and prevents AI governance from being read as pure risk-aversion.

Vice-Chair. Whichever of CRO or CAIO is not chair. Carries chair authority in emergency-incident sessions when the chair is conflicted or unavailable; acts as agenda partner and decision-quality challenger.

CIO / CTO. Represents technology-platform view: infrastructure, deployment architecture, enterprise-stack integration, IT Change Advisory Board relationship. Owns the production environment AI systems run in; AIGC cannot approve a tier-1 deployment without the CIO's read on production readiness.

CISO. Owns AI cybersecurity: adversarial robustness, prompt-injection defence, model-theft prevention, supply-chain integrity (ML-BoM), AI-specific incident response. NIS2 and DORA reinforce the seat. Dispositive on any tier-1 deployment with attack-surface implications.

CCO / DPO. Carries regulatory-compliance and data-protection seat. Under GDPR Article 37, organisations whose core activities involve large-scale personal-data processing must designate a DPO who must be involved in personal-data matters, which most AI systems implicate. DPO independence under GDPR Article 38 is preserved; the DPO is a voting member but DPO regulatory authority is not delegated to AIGC majority vote.

CLO / General Counsel. Owns legal-risk read on deployments, AI-vendor contracts, IP and copyright strategy for AI outputs (lesson 038), litigation-hold and discovery posture, regulator-engagement and disclosure strategy, legal-privilege envelope around incident response. Non-optional in 2026.

CDO. Owns data governance: training-data provenance, quality, classification, retention, lineage. Article 10 of the EU AI Act on data governance for high-risk systems routes here. For training-heavy AI strategies the CDO is dispositive; for foundation-model-deployment strategies the seat focuses on RAG corpora and fine-tune datasets.

HR Director. Covers workforce-impacting AI: hiring tools (NYC LL-144, Annex III §4), performance management AI, employee monitoring, workforce-displacement strategy, AI literacy program ownership (Article 4), workplace-AI ethics policy. As AI moves into HR processes the seat becomes dispositive rather than courtesy.

Business-unit head representing the largest AI footprint. The business owner whose use cases are most material: Head of Retail Banking for consumer-credit AI, Chief Medical Officer for clinical-decision-support, Chief Underwriting Officer for an insurer. Brings the business-value perspective and prevents AIGC from being read as purely a control function.

ML / Engineering technical lead. The senior technical voice, model architect, ML platform lead, or AI Office head of engineering, translates between governance language and engineering reality. Without this seat the committee approves deployments it cannot rigorously interrogate.

Internal Audit, observer. Attends every standing meeting and the annual offsite as a non-voting observer. Observer status preserves third-line independence; Internal Audit cannot vote on a matter it may later assure. Observer presence ensures audit visibility and prevents surprise findings.

Optional seats. An external Ethics Advisor (academic or named external) brings outside-view challenge and signals public-trust posture in healthcare, public-sector, and consumer-facing AI. External Counsel attends sessions on regulator engagement and litigation-adjacent matters. Typically non-voting; attendance documented.

Decision-rights matrix. The matrix below is the dispute-resolution device that should have been in place at Acme Inc before Maya's first meeting. The 2026 default mapping:

AIGC owns. (1) Ratification of the enterprise AI risk appetite statement; (2) approval of tier-1 deployments and tier-1 substantial modifications per Article 43(4); (3) ratification of the AI policy stack (Acceptable Use, Vendor Risk, Incident Response, GenAI Use, AI Literacy); (4) acceptance of IMV, red-team, and incident root-cause findings at tier-1 severity; (5) regulator-engagement strategy for AI matters; (6) ratification of the AIGC charter itself.

IT Change Advisory Board (IT CAB) owns. Operational technical-deployment approval for AI systems already ratified at the policy level: change-window scheduling, technical readiness, rollback, integration testing, production cutover. Routine version updates within previously-approved envelopes. IT-platform-level security baseline. The IT CAB does not approve the AI deployment as a governance matter; it approves the production-environment change as a technical matter, after AIGC has issued policy-level approval.

Board AI Subcommittee owns. Strategic AI mandate and capital allocation; enterprise risk-appetite ratification at board level (AIGC ratifies operationally, board ratifies strategically); AIGC charter approval; tier-0 strategic decisions (enterprise AI strategy, major AI acquisitions, board-statement commitments); quarterly oversight of AIGC performance through the AIGC quarterly report; annual ratification of AIGC chair and vice-chair appointments.

Business-unit head owns. Tier-2 and tier-3 deployment approvals within the unit per the AI policy stack with notification to AIGC; local risk-acceptance within enterprise appetite; business-process accountability for AI outputs in operation; escalation to AIGC when matters exceed unit authority.

Model owner owns. Day-to-day operation, monitoring, and routine remediation; documentation maintenance (model card, system card, FRIA); incident detection and first-line response; escalation to second line (MRM / AI Office) and AIGC where matters exceed first-line authority. The model owner is the named accountable individual; the AIGC approves the policy-level disposition.

The matrix prevents the Acme 90-minute debate by making explicit who decides what. The single most common 2026 governance failure is overlap: two bodies believing they own a decision, or worse, both believing the other owns it.

Cadence, Standing Agenda, and the Metrics Dashboard

Cadence and agenda are where the AIGC moves from charter-on-paper to operating reality. The 2026 standard pattern combines monthly business-as-usual, quarterly extended, ad-hoc trigger-based, and emergency-incident sessions, anchored to a fixed eight-item standing agenda and a metrics dashboard that becomes the artifact the chair takes to the board.

Monthly BAU sessions. 90 minutes, fixed second Tuesday, in-person or hybrid. Default forum for routine governance work (agenda items 1-8 below) without metrics deep-dive. Most months surface one or two tier-1 approval requests, two to three substantial-modification reviews, several FRIA-pipeline updates, ongoing incident-remediation oversight. Skipped months require chair documentation.

Quarterly extended sessions. Half-day, co-located with board AI subcommittee preparation week. The metrics dashboard is reviewed in depth; AI inventory growth is interrogated; risk-appetite tolerance bands are reviewed against actuals; the three-month forward pipeline is walked. Standard checkpoint for AI literacy metrics, vendor-DDQ throughput, and red-team / IMV programme effectiveness.

Ad-hoc tier-1 approval sessions. Trigger-based on a 5-business-day window from receipt of the complete approval package (FRIA, model/system card, validation report, residual-risk statement, business case). Charter-defined to prevent business-unit pressure for same-week sign-off, the operational discipline whose absence allowed Acme's Innovation Subcommittee to announce a go-live before the AIGC had even seen the FRIA.

Emergency-incident sessions. Within 48 hours of notification of an Article 73 serious incident, regulator inquiry, tier-1 vendor breach affecting an AI system, or board-escalated AI matter. Quorum can be reduced per charter; the decision log records reduced quorum and rationale. Most emergency sessions produce interim actions pending next BAU session.

Annual offsite. Full day, scheduled Q4 to inform next-year board planning. Three fixed items: risk appetite refresh, charter review and ratification, three-year horizon scan. Optional fourth: deep-dive on one priority topic (agentic governance, multimodal risk). Produces the AIGC's strategic posture for the year ahead.

Standing agenda, eight items, fixed order.

  1. Prior-meeting actions and decisions log review. Walk every open action with owner and target date; close completed; re-baseline slipped with rationale. First 15 minutes non-negotiable, an AIGC without action discipline has no operational traction.
  2. AI inventory tier-1 movements. New tier-1 systems in onboarding; tier reclassifications; substantial modifications under review; decommissionings. The inventory is read here, not built here.
  3. FRIA / Article 27 pipeline. Active FRIAs by stage (draft, stakeholder review, AIGC review, ratified); backlog; quality findings; Annex III §-specific patterns; DPIA cross-walk.
  4. Red-team and IMV findings. Open by severity; new; closed with verification; material findings exceeding policy thresholds requiring AIGC decision.
  5. Incident review (Article 73 + equivalents). Open incidents by severity; new; closed with lessons captured; Article 73 notifications made or pending; NIS2 / DORA cross-walk where in scope.
  6. Regulator interactions. Active inquiries, examinations, supervisory letters; submissions made and due; engagement-strategy adjustments. Often part-privileged; minutes record fact-of-discussion and action, not substance.
  7. Policy and standard updates. Policy-stack changes proposed, in consultation, ratified, in implementation; standard updates (NIST RMF, ISO 42001, OWASP, MITRE ATLAS) and the posture-adjustment plan.
  8. Emerging-issue scan. 10-minute round-table: new regulator guidance, new attack patterns, new technology classes (agentic, multimodal, on-device), competitor governance moves, public discourse. Feeds the quarterly extended session and annual offsite.

Metrics dashboard. A standing dashboard, refreshed monthly by the AI Office, presented in full at the quarterly extended session. The 2026 default metrics:

  • AI inventory growth: total in-scope systems by tier, MoM delta, annualised rate; shadow-AI detection rate (lesson 021).
  • FRIA / Article 27 backlog, active FRIAs by stage and age; average cycle time; quality findings rate.
  • IMV findings, open by severity; mean-time-to-close; recurrence rate.
  • Red-team findings: open by severity; mean-time-to-close; coverage map against OWASP LLM Top 10, OWASP Agentic Top 10, MITRE ATLAS.
  • AI literacy training compliance, Article 4 rate by role-band; assessment pass rates; audit-evidence completeness (lesson 034).
  • Vendor DDQ throughput: in progress, completed this quarter, average cycle time, findings rate (lesson 070).
  • Time-to-incident-report, mean time from detection to Article 73 notification (15/10/2-day windows by severity); compliance against the regulatory window.
  • Tier-1 approval throughput: deployments approved this quarter, mean cycle time, rejection/deferral rate.
  • Charter health: quorum-met rate, meetings held vs scheduled, action-closure rate, charter-review currency.

The dashboard is the artifact the chair takes to the Board AI Subcommittee quarterly. Boards read dashboards, not minutes. An AIGC chair who cannot put a one-page dashboard in front of the board has not built the right metrics.

Worked Example - Acme Inc 2026 AIGC Charter and Three-Month Decision Log

Concrete application removes ambiguity. Acme Inc is a 14,000-employee European-headquartered diversified financial services group with a U.S. retail banking subsidiary and a UK branch network: in scope for EU AI Act provider and deployer obligations, ECB and PRA supervision, U.S. Fed and OCC supervision, GDPR, DORA, and NIS2.

Charter signed. Acme's AIGC charter v1.0 was ratified by the Board AI Subcommittee on 17 February 2026, signed by the CEO (Mariam de Vries), the AIGC Chair (Maya Okafor, CRO), and the Board AI Subcommittee Chair (Aleks Petrov, board director, former regulator). Charter v1.0 supersedes the one-page predecessor document and addresses every gap revealed by Maya's first session.

Membership, 11 voting + 2 observers. Chair: Maya Okafor, CRO. Vice-Chair: Dr Sven Lindqvist, CAIO (2025 hire reporting to CEO). Henrik Bauer, CIO. Priya Raman, CISO. Léa Moreau, CCO (the DPO reports to Léa and attends on data-protection matters). Catalina Reyes, CLO. Joon-ho Park, CDO. Fatima al-Sayed, Group HR Director. Tomás Silva, Head of European Retail Banking (rotating business-unit seat). Dr Anna Kovac, Head of AI Engineering (technical lead reporting to CAIO). Niraj Iyer, Head of Model Risk Management (the AIGC-MRM seam). Observers: Frederik Holm, Chief Audit Executive; Dr Elena Petrescu, External Ethics Advisor (two-year term). Secretary: Sara Ahmed, Head of the AI Office, non-voting.

Cadence ratified. Monthly second Tuesday, 14:00-15:30 CET. Quarterly extended session 09:00-13:00 the second Tuesday of March, June, September, December. Ad-hoc tier-1 approval sessions on 5-business-day windows. Emergency sessions within 48 hours of trigger. Annual offsite, third week of November.

Decision log: March, April, May 2026 (sample).

March 10 (monthly + quarterly extended). M03-01: Ratify Enterprise AI Risk Appetite Statement v1.0 (the document Acme had been operating without). Vote 11-0. Action: cascade within 30 days; embed in next AI policy refresh. M03-02: Approve tier-1 fraud-decisioning agent deployment (Maya's January item, now properly packaged). Vote 10-1 (CISO dissent: additional adversarial robustness testing required; deployment conditional on PyRIT + Garak completion). M03-03: Accept Q1 metrics dashboard. Three findings: FRIA backlog at 14 (target ≤8); time-to-incident-report 11-day mean (target ≤8); vendor DDQ cycle 6.5 weeks (target ≤4). AI Office to bring remediation plan in April.

April 14. M04-01: Ratify AI Vendor Risk Policy v2.0 (incorporating lesson 024 + 070 + 071 DDQ and SOC 2 + AI review requirements). Vote 11-0. M04-02: Reject tier-1 HR resume-screening AI procurement from Vendor X. Vote 9-2 (HR Director and CDO dissented). Rationale: NYC LL-144 + Annex III §4 exposure with insufficient bias-audit evidence from vendor; FRIA incomplete; vendor substantial-modification cadence unclear. Action: HR to evaluate alternatives; gating re-review July. M04-03: Substantial-modification review for production GPT-based customer-service assistant, vendor upgraded the underlying foundation model. Vote 11-0 to authorise IMV re-validation; deployment continues with elevated monitoring during the validation window.

May 12 (lesson 072 publication date). M05-01: Accept Q1-Q2 red-team programme report. Two tier-1 findings on the fraud-decisioning agent post-deployment; both remediated. Vote 11-0. M05-02: Charter amendment v1.1, explicit DORA Article 28 ICT third-party concentration risk language added; NIS2 incident-reporting cross-reference added. Vote 11-0; Board AI Subcommittee endorsement requested in June. M05-03: Accept Fed and PRA supervisory-letter responses on Acme's generative AI MRM adaptation. Vote 11-0. M05-04: Emerging-issue scan flagged the EU Commission's late-April Article 50(2) synthetic-content marking guidance for agentic systems; AI Office to draft policy refresh for June.

Operating reality at three months. AIGC has ratified a risk appetite, approved two tier-1 deployments (one conditionally), rejected one tier-1 procurement, run two substantial-modification reviews, amended its own charter once, and produced a board-facing dashboard for the June Board AI Subcommittee. Action-closure rate 78% (target ≥85% by month six). Quorum met every session. The committee has moved from the 90-minute January debate to operating rhythm in May. The transformation is not glamour. It is discipline.

Cross-Walk to Standards and 2026 Regulator Expectations

The AIGC is the central node in the regulatory cross-walk. The 2026 audit and examination reality is that one well-run AIGC, with its charter, minutes, decision log, action tracker, and dashboard, satisfies the leadership-and-governance evidence requirement across every major standard simultaneously.

EU AI Act cross-walk. Article 17 (QMS, top-management responsibility), AIGC is the operating embodiment of the QMS management-responsibility element. Article 26 (deployer obligations), AIGC ratifies the deployer framework and approves tier-1 deployer use cases. Article 27 (FRIA), AIGC signs off completed FRIAs at tier-1 risk classification. Article 43(4) (substantial modification), AIGC classifies whether a modification is substantial and authorises re-assessment. Article 50 (transparency): AIGC ratifies the transparency policy for chatbots, synthetic content, emotion-recognition, biometric categorisation. Article 71 (EU database), AIGC oversees registration completeness. Article 73 (serious-incident reporting), AIGC is the named forum; the 48-hour emergency session is the operational backbone. Article 99(3) €15M / 3% of worldwide annual turnover for Articles 17, 26, 27 failures, AIGC discipline reduces this exposure directly.

NIST AI RMF cross-walk. Govern 1.1 (legal/regulatory understanding), agenda item 7. Govern 1.5 (ongoing monitoring), monthly cadence + quarterly dashboard. Govern 2.1 (roles, responsibilities, communication), charter + RACI + decision-rights matrix. Govern 3.1 (workforce diversity, equity, inclusion), composition discipline. Govern 4.1 (critical-thinking culture), dissent-recording discipline. Govern 5.1 (stakeholder engagement), external advisor seat + regulator strategy.

ISO 42001 cross-walk. A.3 (leadership), chair + signatures + minutes. A.4 (organisational structure and roles), charter Sections 4 + 5. A.5 (policy), AI policy stack ratification. A.6 (lifecycle including risk treatment), tier-1 risk-treatment ratification. Auditor expectation: read the charter and at least 12 months of minutes; the signature page, the most recent offsite output, and three sample decision-log entries are the standard evidence ask.

SR 11-7 + PRA SS1/23 + OCC 2011-12. SR 11-7 Pillar 3 governance, AIGC chairs the forum where second-line model-risk findings are heard. SS1/23 Principle 2 governance, AIGC carries management responsibility under the five-principle structure. OCC 2011-12, same posture. Bank examiners ask in 2026: "Show me the governance forum where this tier-1 model was approved, who was in the room, what dissent was recorded, what the dashboard showed." AIGC discipline is the answer.

DORA + NIS2 nexus. DORA Article 5 (ICT risk framework, board accountability), AIGC must coordinate with the ICT risk body or absorb it for AI-system ICT risk. DORA Article 28 (concentration risk on critical third-party providers), AIGC tracks foundation-model and AI-vendor concentration. NIS2 Article 21 (cybersecurity risk-management including supply chain), AIGC covers AI-specific supply chain via ML-BoM oversight (lesson 029).

Board AI Subcommittee, the layer above. Increasingly common in 2026, particularly post-SOX in U.S. listed entities and post-DORA in EU financial entities. Meets quarterly, receives the AIGC report, owns strategic AI mandate and capital allocation, and ratifies the AIGC charter. Board AI literacy preparation (lesson 035) is owned by the Board AI Subcommittee with delivery support from the AIGC. The AIGC is the operational layer; the Board AI Subcommittee is the strategic layer.

Three Lines of Defense applied. AIGC sits as the second-line governance forum. First-line model owners bring requests (tier-1 approvals, substantial modifications, incident reports). Second-line functions populate the committee and bring independent challenge. Third-line internal audit attends as observer to preserve independence and produces annual assurance over AIGC operation. Lesson 073 is the dedicated leadership-tier treatment of 3LoD for AI, building on lesson 067's practitioner coverage.

2026 emerging. Board AI literacy preparation under Article 4 is a 2026 priority, AIGC typically delivers board-AI-literacy briefings with external counsel and academic advisor support. AI-specific cyber-resilience under NIS2 and DORA is becoming a standing-agenda concern. Post-Omnibus VII dual-timeline obligation tracking (lessons 005, 006) requires AIGC oversight of which entities are on which compliance clock. Best practice in 2026 operates with named owners for each cross-walk and treats cross-walk maintenance itself as standing operational discipline.

Key Takeaways

  • The AI Governance Committee (AIGC) is a regulator expectation in 2026, not optional infrastructure. ISO 42001 A.3 leadership accountability, EU AI Act Article 17 top-management responsibility, NIST AI RMF Govern 1.1/1.5/2.1/3.1/4.1/5.1, SR 11-7 + PRA SS1/23 + OCC 2011-12 governance pillars all expect a named cross-functional forum. The absence of one is a first-order audit-visible and examiner-visible defect.
  • The L4 pivot from practitioner artifact-building (model cards, FRIAs, DDQs, ML-BoMs) to operating-model design begins here. The AIGC is the body that decides which artifacts get built, by whom, on what cadence, with what authority, against what risk appetite. Drafting its charter, setting its membership, and defining its decision rights is the leadership-tier skill.
  • The 15-section charter is the foundational artifact: purpose, scope, authority, membership, role-specific responsibilities, decision rights matrix, cadence, quorum, agenda, escalation triggers, reporting line, ratification standard, document retention, charter-review cadence, signatures. Abbreviated charters covering only purpose and membership are a known failure mode.
  • Membership composition is 8-12 voting members plus 2-3 observers, selected by role not individual. Chair = CRO (regulated industry) or CAIO; Vice-Chair = the other. CIO/CTO, CISO, CCO/DPO, CLO, CDO, HR Director, business-unit head (largest AI footprint), ML/engineering technical lead, MRM head. Internal Audit as observer to preserve third-line independence. Optional: external ethics advisor, external counsel.
  • The decision-rights matrix separates AIGC authority from IT Change Advisory Board authority and Board AI Subcommittee authority. AIGC owns risk-appetite ratification, tier-1 deployment approval, AI policy stack ratification, IMV and red-team findings acceptance at tier-1, incident root-cause acceptance, regulator-engagement strategy. IT CAB owns operational technical-deployment approval. Board AI Subcommittee owns strategic AI mandate, capital allocation, and AIGC charter ratification. The matrix prevents the Acme 90-minute debate.
  • Cadence: monthly BAU, quarterly extended with metrics dashboard, ad-hoc tier-1 approval on 5-business-day window, emergency incident within 48 hours, annual offsite. Standing agenda: 8 items in fixed order (prior actions; tier-1 inventory movements; FRIA pipeline; red-team/IMV findings; Article 73 incidents; regulator interactions; policy updates; emerging-issue scan).
  • The metrics dashboard is the artifact the chair takes to the board. AI inventory growth, FRIA backlog, IMV findings, red-team findings, AI literacy training compliance, vendor DDQ throughput, time-to-incident-report, tier-1 approval throughput, charter health. Boards read dashboards; boards do not read minutes.
  • One well-run AIGC satisfies the leadership-and-governance evidence requirement across EU AI Act Articles 17, 26, 27, 43(4), 50, 71, 73 + NIST RMF Govern + ISO 42001 A.3/A.4/A.5/A.6 + SR 11-7/SS1/23/OCC 2011-12 + DORA/NIS2 simultaneously. Article 99(3) penalty exposure of €15M / 3% of worldwide annual turnover for Article 17, 26, 27 failures is the direct economic argument for AIGC discipline.