For Heads-of · Practitioner
No documented AI policy
The organisation operates AI systems without a top-management-approved policy defining acceptable use, risk appetite, and escalation routes.
- high
- governance
- policy
- ai-management-system
How it happens
AI adoption happens organically across teams, procurement decisions, shadow IT, individual experimentation, with no single policy document that top management has actually approved and that says what's allowed, what isn't, and who to escalate to.
Why it matters
Every other governance control in this list assumes a policy exists to point back to; without one, 'is this allowed' has no answer until someone improvises one under pressure.
Mitigating controls
The controls that address this risk, ranked by effectiveness.
Framework and clause references
| Framework | Clause | Title |
|---|---|---|
| NIST AI Risk Management Framework (AI RMF 1.0) | Govern | Govern |
| ISO/IEC 42001:2023 | Annex A.2 | Policies related to AI |
| SS1/23: Model Risk Management Principles for Banks | Principle 2 | Model risk governance |
Related resources
The external sources behind this risk, from the Resources library.