AI for IT Certification
Aware · M46 · lesson 46 of 120 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Cross Functional Ai Governance
📖
now learning

Cross Functional Ai Governance

15 min

Overview

Your organization is building an AI system for hiring. The project needs input from:

  • HR (this affects hiring process, employee relations)
  • IT (security, infrastructure, data)
  • Legal (compliance with employment law)
  • Compliance (anti-discrimination law)
  • Finance (budget, cost)
  • Business unit (defines requirements, owns outcomes)
  • Ethics (bias and fairness considerations)

Each department has legitimate concerns. But they don't all agree:

  • HR wants the AI to be used in hiring (sees efficiency gains)
  • Legal is nervous about discrimination liability
  • Compliance wants extensive governance
  • IT is focused on technical implementation
  • Business wants speed
  • Ethics wants thorough bias review

This is the challenge of cross-functional governance: many departments, different priorities, legitimate conflicts, need to reach decisions.

This lesson teaches you how to structure cross-functional governance, how to make decisions when different functions disagree, and how to ensure IT is at the table driving decisions, not just implementing them.

Purpose

The purpose of this lesson is to equip you with:

  • A cross-functional governance structure that includes all necessary stakeholders
    - A RACI framework for AI decisions so everyone knows who decides what
    - A decision-making process for resolving conflicts across functions
    - Escalation procedures for when functions can't agree
    - Integration with IT governance so AI governance isn't separate from IT governance

By the end of this lesson, you'll understand how to lead cross-functional AI governance.

Why This Matters

AI Decisions Are Not IT Decisions

This is the most important insight. Many organizations treat AI as an IT project. "IT builds the AI, then other departments use it."

This is wrong. AI decisions involve:

  • Business decisions: What problem are we solving? Is it valuable?
  • Legal decisions: Are we compliant? What's our liability?
  • HR decisions: Does this affect employees? How?
  • Compliance decisions: What regulations apply?
  • IT decisions: Can we build it securely? Can we maintain it?
  • Ethics decisions: Is it fair? Does it cause harm?

AI projects that succeed have multi-functional teams from the start, not IT leading with other departments adding input.

Why IT Leadership of AI Governance Matters

Even though AI decisions are multi-functional, IT's voice is essential:

IT understands systems thinking.

  • IT manages cross-functional infrastructure (networks, databases, security)
  • IT thinks about integration, dependencies, technical debt
  • IT can see how AI decisions affect the broader technology ecosystem

IT manages risk across the organization.

  • IT is responsible for security, compliance infrastructure, business continuity
  • IT is positioned to spot risks others miss
  • IT is accountable when things go wrong

IT is closest to data.

  • Data is IT's domain
  • Data quality, security, governance are IT responsibilities
  • AI depends entirely on data

IT has stakeholder relationships.

  • IT works with every department
  • IT understands their needs and constraints
  • IT is trusted neutral party

IT leadership of cross-functional governance doesn't mean IT controls all decisions. It means IT facilitates the process and ensures all voices are heard.

The Cost of Poor Cross-Functional Governance

Organizations with poor cross-functional governance experience:

  • Conflicting requirements (HR says one thing, Legal says another)
  • Delayed decisions (waiting for alignment that never comes)
  • Legal/compliance issues (built something that's not compliant)
  • Low adoption (departments didn't get what they needed)
  • Rework (built the wrong thing, had to rebuild)

Core Concepts

Key Insight 1: The Cross-Functional AI Governance Structure

A well-structured cross-functional governance has three levels:

Level 1: AI Strategy Committee (Executive Level)

Members: CEO or Chief Operating Officer, CIO, Chief Risk Officer, Chief Compliance Officer, CFO, plus heads of major business units

Purpose: Set AI strategy and direction

  • Allocate budget across AI initiatives
  • Set risk tolerance and governance standards
  • Approve major AI initiatives (> $5M, high-risk, strategic importance)
  • Remove obstacles to AI execution

Cadence: Quarterly

Authority: Strategic decisions only (not day-to-day)

Level 2: AI Governance Committee (Operational Level)

Members: CIO (chair), Chief Data Officer, Head of AI/Data organization, Head of IT Security, Head of Compliance, Legal representative, Chief Ethics Officer, Plus rotating business unit representatives

Purpose: Operational AI governance

  • Review and approve AI initiatives (details that strategy committee delegates)
  • Set governance standards and policies
  • Monitor AI performance and compliance
  • Escalate issues to strategy committee

Cadence: Bi-weekly

Authority: Approval/rejection of initiatives within policy; setting standards

Level 3: AI Implementation Teams (Execution Level)

Members: Business owner, AI team lead, IT architect, Data engineer, Security representative, Compliance representative, HR representative (if applicable), Ethics representative (if high-risk)

Purpose: Execute specific AI initiative

  • Define requirements
  • Design and build AI
  • Conduct testing and validation
  • Plan deployment
  • Manage post-deployment issues

Cadence: Weekly (or as needed)

Authority: Detailed execution decisions within approved initiative

This three-level structure ensures:

  • Strategic alignment at top
  • Operational governance at middle
  • Efficient execution at bottom

Key Insight 2: RACI for AI Decisions

RACI clarifies who is Responsible, Accountable, Consulted, and Informed for different types of AI decisions.

Example RACI for Hiring AI:

Decision
Responsible
Accountable
Consulted
Informed

Use case definition
HR + Business
VP of HR
IT, Legal
Employees

Compliance assessment
Legal
Chief Counsel
HR, Compliance
N/A

Data governance
IT
CIO
HR, Legal
N/A

Model development
AI team
AI Lead
IT, HR
N/A

Bias assessment
Ethics committee
Chief Ethics Officer
Legal, HR, AI team
N/A

Deployment approval
IT + HR + Legal
VP of HR + CIO
Finance, Business
Employees

Post-deployment monitoring
IT + HR
CIO
Legal, Compliance
N/A

RACI prevents:

  • Confusion ("who decides?")
  • Duplication ("three people doing the same work")
  • Missed input ("they should have been consulted")

Key principle for RACI:

  • Responsible: 1-2 people who do the work
  • Accountable: 1 person who owns the outcome (often responsible person or their manager)
  • Consulted: People whose input is needed before decision (usually 3-5 people)
  • Informed: People who need to know the decision but didn't need to be consulted (usually larger group)

Key Insight 3: Decision-Making Framework for Cross-Functional Conflicts

When different functions disagree, you need a clear process for decision-making.

Conflict Resolution Process:

Step 1: Surface the Disagreement (Clearly)

Describe what each function wants:

  • "HR wants to use this model in hiring. Legal is concerned about discrimination liability."
  • Not: "People have different opinions"
  • But: Specific disagreement with clear stakes

Step 2: Understand the Underlying Concern (Root Cause)

Why does Legal have concerns?

  • "If model discriminates and we're sued, we could lose $10M+"
  • Is it about the model quality? About legal liability? About process?
  • What would reduce the concern?

Why does HR want to proceed?

  • "This model increases hiring speed by 40%, helping us compete for talent"
  • Is it about efficiency? About competitive necessity? About culture?
  • What would help HR achieve the goal without the legal risk?

Step 3: Explore Trade-offs and Mitigations

Can we address both concerns?

  • Add human review (addresses legal concern without sacrificing efficiency)
  • Run extensive bias testing (reduces legal risk)
  • Implement transparency to candidates (addresses fairness concern)
  • Set audit and monitoring to catch unintended consequences

Step 4: Make a Decision

Three possible outcomes:

Option A: Both functions agree

"We'll deploy with human review. That addresses legal concerns and HR still gets efficiency gains."

→ Proceed

Option B: Functions propose different approaches

"HR proposes deploy with human review. Legal proposes more extensive bias testing first. Let's try the bias testing; it takes 2 weeks and gives us better legal position."

→ Agree on approach and proceed

Option C: Functions fundamentally disagree

"HR wants to deploy this model. Legal is saying we could face material legal risk."

→ Escalate to executive (VP HR and General Counsel, or CEO if needed)

→ Executive makes decision knowing the risks and benefits

→ Decision is documented: "We've decided to deploy with these mitigations. We understand and accept the remaining risks."

What doesn't work:

  • Compromise that doesn't address core concerns ("we'll deploy, but Legal doesn't have to approve")
  • Delaying indefinitely to reach perfect consensus
  • One function overriding others without escalation

Key Insight 4: IT's Specific Role in Cross-Functional Governance

IT's role in cross-functional governance is different from other functions.

What IT Does:

  • Facilitate the process (not dominate it)
    - Call meetings, ensure all voices are heard
    - Help surface disagreements early
    -
    Structure decisions clearly

  • Provide technical perspective
  • Can we build this? How? By when? At what cost?
    - What are the technical risks and mitigation?
    -
    What are the implementation implications?

  • Ensure integration
  • How does this fit with other systems?
    - What dependencies exist?
    -
    What's the impact on infrastructure?

  • Manage risk
  • Security implications?
    - Data quality implications?
    - Compliance implications?
    -
    Sustainability implications?

  • Escalate when needed
  • If an initiative is technically infeasible, IT should escalate
    - If an initiative creates unacceptable risk, IT should escalate
    - If cross-functional alignment can't be reached, IT should escalate

What IT Doesn't Do:

  • Make business decisions (should HR use AI in hiring? That's HR's business decision, not IT's)
    - Decide policy (that's legal/compliance decision)
    - Determine ethics standards (that's ethics committee decision)

IT's role is facilitating and enabling cross-functional decision-making, not controlling it.

Key Insight 5: Escalation and Conflict Resolution Process

Not every disagreement needs escalation. But you need a clear process for conflicts that can't be resolved at the working level.

Escalation Criteria:

Escalate if:

  • Disagreement is about fundamental approach (not just details)
  • Disagreement affects multiple functions significantly
  • Disagreement involves compliance or legal risk
  • Working-level teams have spent significant time trying to resolve (and can't)
  • Business impact depends on resolution

Escalation Path:

Level 1: Working team tries to resolve

(1 week to attempt resolution)

Level 2: Governance committee discusses

(governance committee hears both perspectives, tries to find resolution)

Level 3: Escalate to executives

If governance committee can't resolve:

  • Identify the issue clearly
  • Present both positions
  • Executive makes decision
  • Document decision and reasoning

Level 4: CEO/Board involvement

Only for issues with material strategic or legal implications

Example Escalation:

Working team: "AI team and Legal can't agree on bias testing requirements. AI team says 4 weeks of testing is enough. Legal says we need 8 weeks."

Governance committee: "We discussed this. AI team is right that 4 weeks is sufficient for most AI, but hiring is high-risk. We recommend 6 weeks as compromise (thorough testing, reasonable timeline)."

If still disagreement: Escalate to CFO + General Counsel + VP HR. They decide: "We'll do 6-week testing. We'll allocate budget. We'll accept the remaining risk. Here's why: [decision reasoning]."

Practical Use Cases

Use Case 1: Supply Chain AI Governance

A manufacturing company built cross-functional governance for supply chain optimization AI.

Governance Structure:

Strategy Committee (Quarterly):

  • CEO, COO, Chief Procurement Officer, CIO, CFO, VP Operations
  • Strategic questions: How much AI should we use in supply chain? What's our risk tolerance?

Governance Committee (Bi-weekly):

  • CIO (chair), Chief Data Officer, Head of Supply Chain Operations, IT Security, Supply Chain IT Lead, Finance representative
  • Reviews supply chain AI proposals, approves budget, monitors performance

Execution Teams (Weekly):

  • Supply Chain leader, AI team, IT architect, Finance, Procurement

RACI for New Supply Chain AI Initiative:

Decision
Responsible
Accountable
Consulted
Informed

Supplier selection
Procurement
VP Procurement
Supply Chain Ops, Finance
N/A

Data requirements
IT + Supply Chain
IT Lead
AI team, Finance
N/A

Model development
AI team
AI Lead
IT Security, Supply Chain Ops
N/A

Risk assessment
IT + Compliance
IT Security
Procurement, Finance
N/A

Cost/benefit analysis
Finance
CFO
Procurement, IT
N/A

Deployment
IT + Supply Chain
IT Lead + Supply Chain Lead
All stakeholders
Executives

Conflict Resolved: Finance wanted to use lower-quality (cheaper) supplier data. IT Security raised concerns about data integrity. Resolution: Use better data, phased approach to manage cost, demonstrated ROI justifies investment.

Use Case 2: Marketing AI Governance (Customer Personalization)

A retail company built cross-functional governance for customer personalization AI.

Governance Structure:

Strategy Committee (Quarterly):

Defines customer personalization strategy and risk tolerance

Governance Committee (Bi-weekly):

Reviews customer-facing AI proposals

Execution Teams (Weekly):

  • Marketing, Data Science, IT, Privacy, Legal (as needed)

Key Stakeholders:

  • Marketing (wants to personalize customer experience)
  • Privacy Officer (concerned about customer data usage)
  • Legal (concerned about data protection law compliance)
  • IT (manages data infrastructure)
  • Finance (watches ROI)
  • Compliance (monitors regulatory requirements)

Major Cross-Functional Conflict:

Marketing wanted to:

  • Use all customer data (purchase history, browse history, location, inferred interests, etc.)
  • Track customer behavior to improve personalization
  • Build sophisticated predictive models

Privacy Officer said:

  • "We don't have explicit consent for all this data use"
  • "We're collecting too much data"
  • "We're creating privacy risk"

Resolution:

  • Conducted customer survey: "What data are you comfortable with us collecting?"
  • Found: Customers are OK with purchase history and browsing history, not location
  • Redesigned AI to use only consented data
  • Added transparency: "Here's the data we're using, you can opt-out"
  • Reduced risk and improved customer trust
  • AI still works well with narrower data

Use Case 3: HR AI Governance (Retention Prediction)

A technology company built cross-functional governance for employee retention prediction.

Key Stakeholders:

  • HR (wants to retain good employees)
  • Employees (concerned about monitoring/privacy)
  • Legal (concerned about employment law)
  • IT (concerned about data security)
  • Ethics (concerned about fairness)
  • Finance (wants to measure ROI)

Cross-Functional Conflicts:

Conflict 1: Privacy vs. Prediction Accuracy

  • HR wanted: Build models using all employee data (performance ratings, salary, benefits choices, etc.)
  • Employees concerned: "You're monitoring us; what if data is wrong?"
  • Resolution: Use only essential data (performance, tenure, compensation tier); communicate what data is used; allow opt-out

Conflict 2: Predictive Accuracy vs. Fairness

  • AI team wanted: Use historical data to train model
  • Ethics committee found: Model perpetuated historical biases (underrepresented groups at higher risk of predicted churn)
  • Resolution: Retrain model with fairness constraints; bias test showed no disparate impact

Conflict 3: Intervention vs. Autonomy

  • HR wanted: "If we identify people at risk of leaving, we want to intervene (offer promotion, more compensation, etc.)"
  • Employees concerned: "That feels manipulative"
  • Resolution: Make intervention transparent ("We notice you might be considering leaving; here are opportunities we think fit your growth"). Employees can opt-out.

Overall Decision:

  • Model is used to identify retention risks
  • Managers are alerted to have conversations (not automated decisions)
  • Model transparency is provided to employees
  • Employees can opt-out
  • Model is monitored for fairness

Use Case 4: Finance AI Governance (Fraud Detection)

A bank built cross-functional governance for fraud detection AI.

Governance Structure:

  • Strategy: CEO, CRO (Chief Risk Officer), CIO, CFO
  • Operational: CIO, Chief Compliance Officer, Chief Fraud Officer, IT Security, Finance
  • Execution: Fraud team, IT, Analytics, Legal

Cross-Functional Dynamics:

What Different Functions Want:

Risk Management:

  • "We need to detect 99%+ of fraud"
  • "We need to limit false positives (legitimate transactions blocked) to < 0.1%"

Compliance:

  • "Fraud decisions must be explicable (can we explain to regulators why we blocked this transaction?)"
  • "We need audit trails for all decisions"

Customer Experience (Operations):

  • "We're blocking too many legitimate transactions; customers are frustrated"
  • "We need faster approval (can't take 24 hours to resolve)"

IT:

  • "We can build 99%+ detection but it requires real-time processing"
  • "Cost is high; need budget"

Resolution:

  • Set fraud detection target: 98% detection (aggressive but achievable)
  • Set false positive target: 0.5% (acceptable level)
  • Build explanation capability: Every blocked transaction has explanation to customer
  • Implement fast escalation: If customer disputes block, resolved in 2 hours
  • Invest in infrastructure: Budget increased to support real-time processing
  • All stakeholders agree: Trade-off acceptable

Examples

Example 1: Cross-Functional Steering Committee Charter

AI Governance Committee Charter

Mission:

To enable responsible, strategically aligned AI across [Organization] through multi-functional oversight and decision-making.

Composition:

  • Chair: CIO
  • Members: Chief Data Officer, Chief Compliance Officer, IT Security Director, AI/Data Head, Legal representative, Ethics representative, Rotating business unit representative (quarterly)

Authority:

  • Approve all AI initiatives $1M+ or high-risk
  • Set AI governance standards
  • Monitor AI performance and compliance
  • Escalate issues to AI Strategy Committee
  • Resolve cross-functional conflicts on AI decisions

Responsibilities:

  • Review AI initiatives against governance standards
  • Identify cross-functional requirements and concerns
  • Resolve conflicts between functions
  • Recommend conditions for approval
  • Monitor post-deployment performance
  • Identify policy or process improvements

Meeting Cadence:

  • Bi-weekly (standing)
  • Plus ad-hoc meetings for urgent decisions

Decision Making:

  • Consensus preferred; majority vote if consensus not reached
  • Escalate fundamental disagreements to AI Strategy Committee

Reporting:

  • Report monthly to AI Strategy Committee on approved initiatives, conflicts, and issues
  • Quarterly report to board on AI governance status

Example 2: Cross-Functional AI Initiative RACI Template

RACI for [AI Initiative Name]

Decision/Activity
Responsible
Accountable
Consulted
Informed

Define Business Requirements
Business Owner
Business Owner
IT, Compliance
N/A

Compliance Assessment
Legal
General Counsel
Compliance, Risk
N/A

Data Governance
IT + Data Owner
CIO
Privacy Officer
N/A

Security Assessment
IT Security
Chief Security Officer
IT, Risk
N/A

Privacy Impact
Privacy Officer
Chief Privacy Officer
Legal, Compliance
N/A

Ethics Assessment
Ethics Committee
Chief Ethics Officer
AI team, Business
N/A

Architecture Design
IT Architecture
CIO
AI team, Security
N/A

Development
AI/Data Team
AI Lead
IT, Business
N/A

Testing & Validation
AI team + IT QA
AI Lead
Compliance, Ethics
N/A

Deployment Planning
IT Operations
IT Lead
All
N/A

Go/No-Go Decision
Governance Committee
CIO + Business Lead
All
Executives

Deployment
IT Operations
IT Lead
Business
Users

Post-Deployment Monitoring
IT + Business
Business Lead
All
N/A

Color coding:

  • 🔴 High involvement (Responsible/Accountable)
  • 🟡 Medium involvement (Consulted)
  • 🟢 Low involvement (Informed)

Example 3: Escalation Decision Framework

When cross-functional teams can't agree:

Question 1: Does this require strategic decision?

  • Is this a question of overall AI strategy or policy?
  • If yes → Escalate to AI Strategy Committee

Question 2: Does this require legal/regulatory decision?

  • Are there legal, compliance, or regulatory implications?
  • If yes and unresolved → Escalate to Chief Counsel + Compliance Officer

Question 3: Does this require executive trade-off decision?

  • Is this a trade-off between competing legitimate concerns?
  • Does it require executive judgment?
  • If yes → Escalate to relevant VPs + CIO

Question 4: Can we compromise or phase?

  • Can we do Phase 1 (limited scope) to prove concept, then Phase 2?
  • Can we add conditions that address both concerns?
  • If yes → Try compromise before escalating

Question 5: What's the business impact of delay?

  • If we wait for consensus, what's the cost?
  • Escalate faster if delay is costly

Anti-Patterns

Anti-Pattern 1: IT Controls All AI Decisions

You see this when IT is the single decision-maker on AI initiatives.

What it looks like: "IT approved this AI" (no business input, legal input, ethics input).

Why it fails: Other functions have legitimate authority and perspective. IT-only decisions miss important considerations.

How to avoid it: Structure governance to be multi-functional; IT facilitates, not controls.

Anti-Pattern 2: No Clear Decision Authority

You see this when it's unclear who actually decides.

What it looks like: "We discussed this in the committee. We all agreed. But then...actually nobody approved it."

Why it fails: Decisions don't get made. Initiatives stall.

How to avoid it: Use RACI to clarify authority. Make clear who the decision-maker is.

Anti-Pattern 3: Governance Without Clear Process

You see this when there are governance committees but no clear process for how they work.

What it looks like: "Let's discuss this. What do people think?" (90 minutes later: no decision).

Why it fails: Without structure, meetings are inefficient. Nothing gets decided.

How to avoid it: Define clear process (how are decisions made? what information is needed? who decides?)

Anti-Pattern 4: No Escalation Process

You see this when conflicts between functions have no clear path to resolution.

What it looks like: "HR and Legal don't agree on this AI. We'll table it and revisit next month."

Why it fails: Unresolved conflicts block progress indefinitely.

How to avoid it: Define escalation path (governance committee tries to resolve; if not possible, executive decides).

Anti-Pattern 5: Functions Not Actually Represented

You see this when cross-functional governance invites representatives but they're not empowered to speak for their function.

What it looks like: "We had Legal in the governance meeting. They didn't say anything." Later: "We can't do this; it violates compliance law."

Why it fails: If representatives can't speak for their function, having them in the meeting doesn't help.

How to avoid it: Choose representatives with authority and make sure they're empowered to voice their function's concerns.

Human Judgment Checkpoints

Before you establish cross-functional AI governance, use these checkpoints:

Checkpoint 1: Do All Functions Support the Governance Structure?

Does IT, Legal, Compliance, HR, Finance, Ethics all agree this structure is appropriate? If not, you need to get alignment first.

Checkpoint 2: Are Key Stakeholders Represented?

Who are the essential voices? Have you included them? Typical: IT, Business, Legal, Compliance, Ethics, Data. May also need: HR, Finance, Operations, Privacy, Security.

Checkpoint 3: Do Representatives Have Authority?

Are the people in governance meetings empowered to speak for their function and make decisions? If not, replace them.

Checkpoint 4: Have You Defined Decision Authority Clearly?

For each type of decision, is it clear who decides? Use RACI.

Checkpoint 5: Do You Have an Escalation Process?

When functions disagree, how do you resolve? Don't leave this vague.

Executive Summary

>
For the C-Suite: AI decisions require multiple voices (business, IT, legal, compliance, ethics), not IT alone. Use a three-level governance structure (strategy committee, operational committee, implementation teams) with clear RACI (who is Responsible, Accountable, Consulted, Informed) for each decision. Cross-functional governance is harder than IT-led governance but produces better decisions because all legitimate concerns are addressed. IT's role is facilitating and enabling, not controlling.

Key Takeaways

  • Recognize that AI decisions are multi-functional, not IT decisions; IT's role is facilitating and enabling, not controlling
    - Build three-level governance structure: strategy committee (executives), governance committee (operational), implementation teams (execution)
    - Use RACI to clarify decision authority: who is Responsible, Accountable, Consulted, Informed for each decision
    - Structure decision-making process: surface disagreements → understand concerns → explore mitigations → make decision with clear accountability
    - Escalate conflicts that working teams can't resolve: governance committee tries to resolve; if not possible, executive decides
    - Include all necessary functions: IT, Business, Legal, Compliance, Ethics, Data, Privacy, Security (as applicable)
    - Give IT's specific roles: facilitate process, provide technical perspective, ensure integration, manage risk, escalate when needed
    - Avoid pure IT control or pure business control; cross-functional decision-making produces better outcomes
    - Document decisions including reasoning and trade-offs accepted; this helps future decisions
    - Review governance effectiveness regularly: is it enabling or blocking? Adjust as needed

Cross-functional governance is harder than IT-led governance, but it's more effective. It ensures all legitimate concerns are heard and addressed.