โ†
AI for Manufacturing
Strategic ยท M19 ยท lesson 19 of 21 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
Standing Up a Plant AI Governance Forum
๐Ÿ“–
now learning

Standing Up a Plant AI Governance Forum

15 min

The customer's quality auditor stood on the floor of a tier-one automotive supplier and pointed at the green light on the vision camera. "That system dispositions parts. Who owns it?" The quality manager said the camera was the vision vendor's system. The auditor asked who decided the reject threshold. The quality manager said the controls engineer set it during install. The auditor asked who checks that the threshold still works now that the plant runs a darker resin on second shift. Silence. The auditor asked who would shut the line down if the model started passing bad parts, and whether anyone had logged the model's last drift check. More silence, then four people pointing at each other: quality said maintenance owned the camera hardware, maintenance said the controls engineer owned the software, the controls engineer said quality owned the spec, and nobody owned the decision. The plant did not fail the audit that day, but it came within one finding of a customer containment, and the reason was not the model. The model worked fine. The reason was that an AI system that touches quality, sits on the OT network, and could in theory hurt someone if it drove the wrong action had been deployed with no forum where quality, maintenance, OT, and EHS sat at one table and agreed who is accountable. A plant AI governance forum is that table. It exists so that the next time an auditor asks "who owns it," there is one answer, and it is a person, not a vendor.

Why a Forum and Not a Policy

The instinct when a plant first gets serious about AI on the floor is to write a policy: a document that says AI must be verified, models must be monitored, humans stay accountable. The policy is necessary and it is not enough, for the same reason a quality manual on a shelf does not prevent an escape. AI on the floor cuts across functions that do not naturally talk to each other, and the gaps between those functions are exactly where an AI failure hides. A policy describes the rules. A forum is the standing body of humans from each function who meet, decide, and own the rules in practice. The audit story above is what a policy without a forum looks like: every rule was probably written down somewhere, and still no one owned the decision when it mattered.

Consider why AI is uniquely a cross-functional problem on the floor, more than almost any other technology a plant deploys. A vision-QA system is simultaneously a quality decision (it dispositions parts the customer audits), a maintenance asset (the camera, lighting, and compute have to be kept in calibration), an OT object (it sits on the operational-technology network, the side of the plant that runs the machines, as opposed to the IT network that runs the office), and a safety concern the moment its output could trigger an action that moves a robot or diverts a part. A predictive-maintenance model is a maintenance tool, an OT data consumer pulling from the historian (the time-series database logging every sensor tag), and a safety matter if a missed prediction lets a guard or a brake fail. No single function can govern these alone, because each function only sees its own slice. The quality engineer does not watch the OT firewall. The OT engineer does not read the customer's quality standard. EHS (environment, health, and safety, the function accountable for keeping the floor from hurting anyone) does not tune the model. Put them in separate rooms and the AI system falls through the cracks between them, which is precisely where the auditor was pointing.

An AI system that no single function fully owns is governed by no one. The forum exists so accountability has a chair, not a gap.

The forum also solves the accountability problem that defines AI on the floor: the customer audits you, not the vendor. When an AI-touched part ships and turns out defective, the customer's containment lands on the plant, the corrective-action request is addressed to the plant, and the human who signed the quality record is the one who answers. "The model flagged it" is never a sufficient answer to an auditor. A forum is how a plant makes that accountability real before the audit instead of discovering during the audit that it was never assigned. It is the difference between a plant that can say "this AI decision is owned by this named person under this charter, logged here, reviewed on this cadence" and a plant that points four ways and hopes.

Who Sits at the Table

A governance forum that is too small misses a function and recreates the gap it was meant to close. A forum that is too large becomes a meeting nobody can decide anything in. The right size for a single plant is usually five to seven core members, each owning a clear slice of accountability, plus the ability to pull in others for a specific decision. Get the membership wrong and the best charter in the world cannot save it, so this is worth doing deliberately.

Quality. The quality manager or a senior quality engineer owns the question the customer auditor will ask: is every AI-touched quality decision specific, accurate, traceable, and signed by a human. Quality is usually the right chair or co-chair of the forum, because quality already lives in the audit world the forum has to satisfy and already owns the corrective-action process when something escapes.

Maintenance and reliability. The maintenance superintendent or reliability lead owns the predictive-maintenance models, the physical upkeep of any AI hardware (the camera, the sensors, the edge compute), and the work-order workflow that turns a prediction into a prevented breakdown. Maintenance is also the function most likely to be running the highest-volume AI on the floor, since predictive maintenance scales across many assets, so its voice carries real operational weight.

OT and controls. The controls engineer or OT lead owns the boundary between AI and the machines. This person answers whether a model is advisory or in control, whether it can reach a PLC (programmable logic controller, the rugged computer that actually drives the machine), and how it sits on a network where 78 percent of plants cannot even monitor centrally. The OT seat is the one most often left off the forum and the one whose absence is most dangerous, because the OT boundary is where an advisory AI quietly becomes a control AI and nobody notices until it moves something it should not have.

EHS. The safety lead owns the line that AI must never cross: anything that can hurt someone stays under human accountability, and a safety-critical control loop is not where AI goes first or, in most plants, at all. EHS is on the forum so that the safety question is asked before deployment, in the room, rather than after an incident, in the investigation.

Operations. A line lead or operations supervisor represents the people who actually live with the AI: the operators who will trust or disable the green light, the crew who will act on or ignore the alert. An operator who was once burned by a false alarm will quietly turn the system off, and no charter survives that. The operations seat keeps the forum honest about whether the floor actually trusts what the plant deployed.

Two more roles round it out without necessarily being standing members. IT or data joins for integration and data-governance decisions, because the historian, MES (manufacturing execution system, the software tracking what is built on each line), and CMMS (computerized maintenance management system, where work orders live) all have to feed and be fed by these models cleanly. And a plant leadership sponsor, usually the plant manager, charters the forum and gives its decisions teeth, even if they do not attend every meeting. Without a sponsor the forum has no authority to stop a deployment, and a governance body that cannot say no is decoration.

The rule that prevents the empty chair

Name every seat to a person and a named alternate, never to a function in the abstract. "Maintenance is represented" is how a forum ends up with the empty chair that recreates the gap. "Maria is the maintenance seat, Devin is her alternate" is how the forum actually meets quorum and decides. The same discipline that makes a CMMS work, a real owner on every record, makes a forum work, a real person in every seat.

The Charter That Gives the Forum Teeth

A forum without a charter is a recurring meeting that drifts into a status update and then off the calendar. The charter is the short, signed document that says what the forum decides, what it cannot decide, how it decides, and what authority backs its decisions. Keep it to a few pages a busy plant manager will actually read, and make it concrete enough that an auditor reading it understands exactly how AI is governed here. A strong charter covers five things.

Scope: what the forum governs. Name it precisely. The forum governs every AI system that touches a quality decision, a maintenance action, the OT network, or anything safety-relevant. State explicitly that no AI system in those categories deploys to production, and no existing one materially changes (a new reject threshold, a retrained model, a wider rollout), without forum review. The scope statement is what turns the forum from advisory to load-bearing, because it makes forum review a gate, not a courtesy.

Decision authority: the gates. Define the specific decisions only the forum can make. The clearest structure is a small set of gates: a go or no-go to deploy any new floor AI, an approval of the verification and human-sign-off plan for each system, a periodic re-authorization of each deployed system, and the authority to suspend or shut down a system that is failing. The shutdown authority is the most important and the most often missing. In the opening story, the auditor's sharpest question was who would stop the line if the model started passing bad parts, and the answer has to be the forum, with a named person empowered to pull it without waiting for a meeting.

Standing decisions: the non-negotiables. Some rules should not be re-litigated every meeting. Bake them into the charter as standing decisions every system must meet: AI stays advisory and out of direct control of anything that moves unless a specifically governed exception is approved; every AI-touched quality or maintenance record is verified and signed by a named human; every such decision is logged in an audit-ready form; and no AI touches a safety-critical control loop. These are the program's spine, and writing them into the charter means a new pilot inherits them automatically instead of arguing them again.

Cadence and quorum. State how often the forum meets (monthly is typical for an active plant, with the ability to call an emergency session for an incident), what counts as a quorum (usually the quality, OT, and safety seats present at minimum, because those three cover the decisions that cannot wait), and how decisions are recorded. A decision the forum makes but does not record cannot be shown to an auditor, so the charter should require that every go, no-go, and suspension is minuted with the rationale and the responsible owner.

Accountability mapping. The charter's most audit-relevant section names, for each deployed AI system, the single accountable human, the verification step, the logging location, and the review cadence. This is the document the quality manager hands the auditor in answer to "who owns it." Worked through for the vision camera in the opening story, it reads: the second-shift quality engineer is the accountable human, every disposition the camera flags is reviewed and signed in the MES, drift is checked weekly against a labeled holdout set and logged, and the forum re-authorizes the system quarterly. Had that one paragraph existed, the audit would have been four sentences instead of four people pointing.

What the Forum Actually Does Each Meeting

A charter describes authority; the meeting is where governance actually happens, and a forum that meets without a real agenda decays into a status update fast. The work of each meeting falls into four recurring jobs, and running them on a standing agenda is what keeps the forum from drifting.

Review the new and the changed. Any AI system proposed for deployment, and any material change to one already running, comes to the forum for a go or no-go. The standard is the charter's non-negotiables: is it advisory, is the human sign-off defined, is the audit log in place, does it stay clear of safety-critical control. A predictive-maintenance model expanding from ten assets to forty is a change that comes to the forum, because the wider rollout changes the alert volume and the risk of alert fatigue, and a model the crew has learned to ignore is worse than no model at all. The forum's job here is to be the gate the orphan pilot never passed through.

Watch the health of what is deployed. Each standing AI system reports a small set of real numbers every cycle: for vision, the false-reject rate and the drift-check result against a holdout set; for predictive maintenance, the alert volume, the saves logged, and the false-alarm rate. These are not vanity metrics like "models deployed." They are the numbers that tell the forum whether a system is still earning its place or quietly costing more than it saves. A vision system whose false-reject rate has crept up because second shift runs a darker material is exactly the kind of slow failure the opening auditor caught and the forum should have caught first. Reviewing these numbers on a cadence is how the forum catches drift before the customer does.

Run the incident loop. When an AI-related quality or maintenance event happens, a passed bad part, a missed prediction that became a breakdown, a false-reject spike that scrapped good product, the forum owns the review: what happened, was the AI a cause, what changes, and does the system stay running, get suspended, or get shut down. This is the forum exercising its sharpest authority, and doing it on a known runbook rather than improvising in a crisis is what separates a governed plant from a lucky one. The incident loop is the natural bridge to a full incident-response process, which a maturing program builds out next.

Re-authorize on schedule. Every deployed system gets re-authorized on a set cadence, typically quarterly. Re-authorization is not a rubber stamp; it asks whether the system is still worth running given its current numbers, whether the accountable human is still in the seat, whether the audit log is still being kept, and whether anything in the process or material has drifted enough to require revalidation. A system that cannot pass re-authorization is suspended until it can, which means governance is continuous rather than a one-time approval that ages into a liability.

Keeping the meeting from becoming theater

The fastest way a forum dies is by becoming a meeting where reports are read and nothing is decided. Three habits prevent it. Every agenda item ends in a recorded decision, not a discussion. Every deployed system has an owner present to answer for its numbers, so there is no abstract reporting. And the plant-leadership sponsor visibly backs at least one hard call, an actual no-go or suspension, early in the forum's life, because a forum that has never said no is not yet believed to be able to, and the first time it holds the line is when the floor learns it is real.

Connecting the Forum to the Rest of the Program

The governance forum is not a standalone artifact; it is the connective tissue that holds the rest of the plant's AI program together, and it works best when it is wired into the program's other parts deliberately. Three connections matter most.

It is the home of the roadmap's governance thread. A well-built plant AI roadmap runs a governance and audit thread through every horizon, naming who signs the AI-touched record at each step. The forum is where that thread lives once AI grows from a single pilot to a plant-wide practice. As each roadmap horizon ships, the new system enters the forum's standing review and its accountability mapping, so the program never reaches a point where it has to halt and retrofit governance onto systems already in production. The roadmap proposes; the forum authorizes and watches.

It owns the metrics that matter and refuses the ones that do not. The forum is the natural enforcer against vanity metrics. Because every deployed system reports real numbers, false-reject rate, logged saves, drift results, FPY (first-pass yield, the fraction of parts that pass without rework on the first try) deltas, the forum keeps leadership's attention on results that connect to the loss chart and off counts like "number of models deployed" that prove nothing. When the plant reports AI ROI upward, the forum is the body that can vouch that the numbers are real and logged, which is exactly the credibility a finance committee and a board require.

It is the seed of multi-line and multi-site standardization. A single-plant forum that works becomes the template for the next line and the next plant. The charter, the gates, the non-negotiables, and the accountability mapping that govern one vision system are the same structures that govern ten, and a company scaling AI across sites can lift this forum's charter as the starting standard rather than reinventing governance plant by plant. Governance that was built once, deliberately, and proven in a customer audit is far more valuable as a reusable asset than as a one-off fix.

Stand the forum up early, while AI on the floor is still one or two pilots, and it grows naturally with the program. Stand it up late, after an auditor has already pointed at the green light and asked who owns it, and you are building governance in the middle of a finding, which is the most expensive and least credible time to do it. The plant that put quality, maintenance, OT, EHS, and operations at one table before the audit is the plant that answers the auditor's question with a name and a logged record, and that calm, specific answer is what governance is for.

Key Takeaways

  • A policy describes the rules; a forum is the standing body of humans who own them in practice. AI on the floor falls through the gaps between quality, maintenance, OT, and EHS, and the forum exists to close those gaps before an auditor finds them.
  • Because the customer audits you and not the vendor, accountability for every AI-touched quality or maintenance decision stays with the plant and a named human. "The model flagged it" is never a sufficient answer, and the forum is how the plant makes accountability real before the audit instead of during it.
  • Staff five to seven core seats, each named to a person and an alternate: quality (often the chair), maintenance and reliability, OT and controls, EHS, and operations, with IT or data and a plant-leadership sponsor pulled in as needed. The OT seat is the most often omitted and the most dangerous to omit.
  • The charter gives the forum teeth: scope (every AI touching quality, maintenance, the OT network, or safety), decision gates (go or no-go, verification approval, re-authorization, and the authority to shut a system down), the non-negotiables (advisory only, human sign-off, audit logging, no safety-critical control), cadence and quorum, and the accountability mapping.
  • The accountability mapping is the document the quality manager hands the auditor: for each system, the single accountable human, the verification step, the logging location, and the review cadence. One such paragraph would have turned the opening audit from four people pointing into four sentences.
  • Each meeting runs four recurring jobs on a standing agenda: review the new and the changed, watch the health of what is deployed using real numbers (false-reject rate, drift, logged saves), run the incident loop, and re-authorize systems on schedule. Every item ends in a recorded decision.
  • Keep the forum from becoming theater: every item ends in a decision, every system has an owner present to answer for its numbers, and the leadership sponsor backs an early hard call so the floor learns the forum can actually say no.
  • Wire the forum into the rest of the program: it is the home of the roadmap's governance thread, the enforcer against vanity metrics, and the seed of multi-line and multi-site standardization. Stand it up early, while AI is still a pilot, not late, in the middle of an audit finding.