Governance and Policy
Chapter Overview
Governance is how an organization decides, enforces, and evolves the rules by which AI is allowed to operate. Policy is the written artifact of those decisions. For managers at Level 5, this chapter closes the gap that sinks most AI programs: executives issue a one-page AI principles memo, and six months later nobody knows whether the customer-service team can paste transcripts into ChatGPT, who signs off on a new vendor, or which risks trigger escalation. The four lessons in this chapter give you the scaffolding to build a governance stack that is specific, enforceable, and auditable, without turning your team into a compliance desk.
Lesson 2.1 (AI Governance Frameworks) grounds you in the external landscape. You will work with three reference frameworks: the NIST AI Risk Management Framework (Govern, Map, Measure, Manage), ISO/IEC 42001 (AI management system certification), and the EU AI Act tiering model (prohibited, high-risk, limited-risk, minimal-risk). You learn where each applies, how they overlap, and why choosing a primary framework matters: the framework sets the vocabulary everyone in your organization uses. You also learn the manager's specific role within these frameworks: you are not drafting the constitution, you are operationalizing it inside a team of 8-80 people.
Lesson 2.2 (Developing Team and Department Policies) is the workhorse. You translate high-level principles into operational policy covering six areas: acceptable use (approved tools, approved data classes), data handling (what PII, IP, or client data can enter which tool), disclosure (when to tell clients and colleagues that AI was used), human-in-the-loop requirements (which decisions require a named reviewer), model and vendor changes (how you re-approve when a vendor pushes a new model), and incident reporting (what to do when the tool goes wrong). You leave with a reusable one-page policy template and a RACI matrix.
Lesson 2.3 (Risk Management and Escalation) teaches you to build and maintain an AI risk register: a living inventory of identified risks, each scored on likelihood and impact, each with an owner, mitigation, and trigger for escalation. You learn the difference between inherent risk (what the tool can do wrong) and residual risk (what is left after controls), and how to calibrate escalation so the CISO hears about the cases that actually matter and not about every minor prompt failure.
Lesson 2.4 (Ethical Leadership in AI Adoption) addresses the human side. Policy without ethical leadership produces compliant cynicism. You learn to set tone by modeling the policy yourself, to address workforce anxiety about displacement with specific commitments rather than reassurances, to treat fairness as a measurable property of outputs rather than an abstract value, and to handle the moments where the policy is silent and judgment is all you have.
How the four lessons connect. Think of governance as a pipeline: a framework (2.1) sets vocabulary and scope; a policy (2.2) converts scope into daily rules; a risk register (2.3) tracks what the rules are protecting against and when they fail; ethical leadership (2.4) is what keeps the whole apparatus credible. Managers who implement only the first two build paperwork. Managers who implement all four build trust.
Estimated time: approximately 70 minutes across the four lessons. Difficulty: Strategic (Level 5).
Prerequisites and Context
This chapter assumes you have completed Levels 1-4 of the AI for Managers certification, or the equivalent. Specifically, you should be comfortable with: the basics of how generative AI models work and where they fail (Level 1), selecting and evaluating AI tools for a specific workflow (Level 2), designing your own AI-augmented workflows and coaching your team through them (Level 3), and measuring AI impact with leading and lagging indicators (Level 4).
If your organization already has a Chief AI Officer, a formal AI Governance Committee, or a dedicated Trust and Safety function, this chapter teaches you how to interface with them as a line manager. If your organization has none of those, this chapter teaches you how to build the manager-level equivalent: because in most mid-sized organizations, the first real governance work happens at your level, not at the C-suite, and waiting for top-down guidance is how shadow AI use metastasizes.
Lessons in This Chapter
2.1 AI Governance Frameworks. External frameworks (NIST AI RMF, ISO/IEC 42001, EU AI Act) and the manager's role within them. Deliverable: a one-page mapping of which framework applies to your team and why.
2.2 Developing Team and Department Policies. Writing enforceable policy on acceptable use, data handling, disclosure, human-in-the-loop, vendor change management, and incident response. Deliverable: a policy draft and a RACI matrix showing who approves what.
2.3 Risk Management and Escalation. Building an AI risk register; distinguishing inherent vs residual risk; setting escalation thresholds. Deliverable: a populated risk register with at least eight entries specific to your team's AI use.
2.4 Ethical Leadership in AI Adoption. Setting tone, addressing displacement anxiety, auditing for fairness, and exercising judgment where policy is silent. Deliverable: a personal leadership stance you can articulate in a 3-minute team conversation.
What You Will Be Able to Do
By the end of this chapter you will be able to: (1) name the framework your organization operates under and articulate its four or five top-level controls without looking them up; (2) produce a team-level AI acceptable use policy that a new hire could read in ten minutes and apply that day; (3) maintain a risk register that your manager and your security counterpart would both recognize as usable; (4) run an escalation process that distinguishes between a minor quality issue and a governance incident; and (5) lead a team conversation about AI ethics that goes beyond platitudes and produces concrete commitments.
Tradeoffs to Understand
Every governance decision is a tradeoff, and managers who do not name the tradeoff explicitly end up relitigating it every month.
Speed vs control. Tighter policy slows adoption. Looser policy produces preventable incidents. The right setting depends on your blast radius (how bad is the worst plausible mistake?) and your recovery time (how fast can you catch and correct?). For a marketing team drafting internal memos, lean toward speed. For a finance team drafting earnings commentary, lean toward control.
Centralized vs federated. A single corporate AI policy is consistent but cannot capture domain-specific risk. Per-team policies are specific but create gaps and contradictions. Most mature organizations settle on a federated model: a corporate floor (things no team may do) with team-specific ceilings (additional rules that apply only to your context).
Rule-based vs principle-based. Rules are easier to enforce but cannot anticipate every situation. Principles are flexible but require judgment. Strong policies combine both: bright-line rules for the highest-risk behaviors, principles plus examples for the gray zones.
Transparency vs confidentiality. Disclosing AI use to clients builds trust but may reveal competitive detail or create contractual liabilities. You need a disclosure standard that differentiates by stakeholder and by stakes.
Skill.re