Enterprise AI governance
AI governance begins with deciding who is allowed to decide.
Governance is not a policy document sitting beside the technology. It is the operating system for accountability: who owns the AI use case, what the system may access, which actions it may take, where a person must intervene, and what evidence proves the boundary was respected.
TEMRIK's architecture direction is to translate approved governance rules into enforceable controls around data, models, agents, tools and consequential action.
accountability · policy · risk · authority · evidence · exceptions · incidents · evaluation
Governance execution path
Board / executive policy
Objectives · risk appetite · prohibited uses · accountability
AI governance rules
Risk class · data class · model conditions · decision rights
TEMRIK policy layer
Architecture direction: machine-enforceable operating boundary
Data / model / agent / tool / action
Every material capability is evaluated against policy
Allow / restrict / approve / escalate / deny
A visible control decision, not silent model discretion
Audit
Decision, approver, exception and outcome evidence
What governance is
Governance is the system that turns accountability into repeatable decisions.
Good AI governance connects strategy, risk, ownership, policy, technical controls, human authority, evidence and review. NIST treats governance as a cross-cutting function across the AI lifecycle; ISO/IEC 42001 frames it as a management system that is continually improved.
Policy on paper vs policy in execution
Policy on paper
“Do not send confidential data to unapproved AI.”
- Relies on memory and judgement.
- May be bypassed by an agent, integration or tool.
- Can be difficult to test or audit.
- Often says what people should do without defining what the system can do.
Policy in execution
The confidential-data rule becomes an operating boundary.
A policy the AI cannot be forced to follow is not yet an operating control.
Responsibility matrix
The model cannot own accountability.
Accountability stays with the organisation. The precise structure varies by size and jurisdiction, but every material AI system needs visible owners for purpose, risk, technical control and consequential decisions.
Board / governing body
Set risk appetite, oversight expectations and material accountability.
OversightExecutive owner
Own enterprise AI policy, resources, risk acceptance and escalation.
AccountableBusiness process owner
Define the purpose, operating rules, exceptions and acceptable outcomes.
ResponsibleRisk / legal / privacy / security
Map obligations, controls and assurance requirements.
ControlTechnical owner
Implement identity, data, model, agent, tool and observability controls.
ImplementationHuman approver
Retain decision rights for actions that remain outside delegated AI authority.
AuthorityInternal audit / assurance
Test whether declared controls are operating as intended.
AssuranceAI risk classes
Govern the use case, not just the model name.
The same model can support a low-consequence drafting task or a consequential workflow affecting money, customers, employees, rights, contracts or safety. Risk classification should follow the actual context, authority and impact.
Assistive
Drafting, summarising, retrieval and low-consequence support.
Operational
AI participates in bounded internal workflows with defined controls.
Consequential
AI can materially affect customers, money, rights, contracts, safety or regulated activity.
Restricted
Use case is prohibited, legally constrained, outside policy, or lacks sufficient control.
Governance domains
Every capability needs a defined boundary.
Model governance
Approved providers, use cases, data classes, retention conditions, evaluation criteria and change review.
Data governance
Purpose, classification, provenance, access, minimisation, retention and authorised retrieval.
Agent governance
Identity, owner, purpose, tools, delegation rights, action ceiling, expiry, stop conditions and revocation.
Tool governance
Allowed systems, operations, parameters, credentials, write permissions, rate limits and high-risk actions.
Action governance
Which outputs may remain advisory, which require approval and which actions may be pre-authorised.
Evidence governance
What must be recorded so material decisions, approvals, exceptions and incidents can be reconstructed.
The model may propose. The operating architecture decides whether the proposal may become an action.
TEMRIK policy layer
A governance rule should resolve to a control decision.
TEMRIK's policy-layer concept is designed to sit outside the model. The model should not be trusted to decide whether its own authority is valid.
Inside declared purpose, approved data class, approved tool and delegated authority.
Proceed only with narrowed data, tool scope, model, amount, recipient or action.
Pause for an authorised human before consequential release.
Route uncertainty, exception, conflict or material risk to a named owner.
Block activity outside policy, authority or legal / security boundary.
Human decision rights
Human oversight must be specific enough to operate.
“Human in the loop” is too vague unless the organisation defines who the human is, what they must review, which evidence is required, the authority they hold, how conflicts are handled and what happens when they decline or do not respond.
Recommend
AI can analyse and propose; a person decides.
Prepare
AI can assemble a draft action; a person authorises release.
Act within ceiling
Pre-authorised low-consequence action inside explicit limits.
Escalate
Exceptions, uncertainty and conflicts route to a named owner.
Revoke
Human authority can suspend the agent, tool, provider or workflow.
Evidence and audit
Governance that cannot be evidenced is difficult to assure.
The objective is not to expose private model reasoning. It is to retain operational evidence showing the declared purpose, applicable boundary, material inputs, approvals, exceptions and released actions.
Exceptions, incidents and change
Governance is tested when the normal path breaks.
Exceptions
Record the request, business reason, risk owner, compensating controls, expiry and approval. Exceptions should not silently become permanent policy.
Incidents
Define reporting, containment, evidence preservation, affected-system review, notification duties, corrective action and reactivation criteria.
Change
Reassess when the provider, model, data source, tool, permissions, use case, regulation or consequence profile materially changes.
Evaluation
Policy needs tests, not only statements.
Evaluation should test whether the system performs its intended work and whether it respects the governance boundary under normal, edge, malicious and failure conditions.
Regulatory mapping
Build one control architecture. Map it to the obligations that actually apply.
NIST, ISO, OECD, the EU AI Act, UK management guidance and Australian guidance are not interchangeable legal instruments. They do, however, converge on recurring governance themes: accountability, risk management, documentation, oversight, transparency, security, evaluation and lifecycle review.
NIST AI RMF
Voluntary risk-management framework; GOVERN spans the lifecycle.
ISO/IEC 42001
Certifiable management-system standard. TEMRIK does not claim certification.
OECD AI Principles
International principles supporting human-centric, trustworthy AI and accountability.
EU AI Act
Binding EU regulation with obligations that vary by role and AI-system category.
UK AIME
Practical organisational management guidance and self-assessment.
Australia
Current government guidance emphasises accountability, risk management and human oversight; existing law continues to apply.
Governance maturity
Mature governance moves from advice to operating evidence.
Ad hoc
Teams use AI with local judgement and limited visibility.
Documented
Policies, approved tools, registers and named owners exist.
Controlled
Policy is translated into identity, access, tool, model and approval controls.
Measured
Evaluations, incidents, exceptions and operating evidence are routinely reviewed.
Adaptive
Controls change with risk, regulation, provider capability and operating evidence.
TEMRIK governance architecture
The policy should sit above the model, the agent and the tool.
Explore the TEMRIK AI control plane: an architecture for keeping company data, operating rules, agent permissions, human authority and evidence independent of whichever model is selected for the work.
Product reality matters. Some controls are live today; others are configurable, provider-dependent or architecture direction. TEMRIK does not claim ISO/IEC 42001 certification, regulatory approval or universal enforcement across every third-party system.
Policy
Purpose · risk · data · model · agent · tool · action
Control
Allow · restrict · approve · escalate · deny
Authority
Named human decision rights and revocation
Evidence
Audit trail, exceptions, incidents and evaluation
Research basis
Current primary sources, linked directly.
Governance requirements depend on jurisdiction, sector, role and use case. These references inform the architecture and should be rechecked when designing a specific customer deployment.
NIST
AI Risk Management Framework 1.0
GOVERN is a cross-cutting lifecycle function spanning policy, accountability, documentation and organisational risk management.
Primary sourceISO
ISO/IEC 42001:2023
Requirements for establishing, implementing, maintaining and continually improving an AI management system.
Primary sourceOECD
OECD AI Principles
Human agency, transparency, robustness, traceability, accountability and systematic lifecycle risk management.
Primary sourceEuropean Union
EU AI Act — Regulation (EU) 2024/1689
Risk management, documentation, human oversight and other obligations for regulated AI use cases, including high-risk systems.
Primary sourceUK DSIT
AI Management Essentials
Practical organisational controls covering AI system records, policy, impact assessment, risk, data and issue reporting.
Primary sourceAustralian Government
Guidance for AI Adoption
Current Australian guidance emphasises named accountability, governance, risk management and meaningful human oversight.
Primary sourceSecure AI Framework controls
Governance and assurance controls plus agent permissions, user control, incident response and security testing.
Primary sourceMicrosoft
Responsible AI
Principles and governance practices covering accountability, transparency, privacy, security, reliability and safety.
Primary sourceRelated TEMRIK architecture
Human Control
How consequential actions remain behind visible authority.
AI Security
How data, identity, providers and tools fit inside the security boundary.
Agentic AI
How agents use tools, memory, delegation and multi-step orchestration.
How it works
How TEMRIK separates interpretation, recommendation and authorisation.
Free field guide
27 Rules of Peace
Governance gets easier when the rules of the work are explicit.
TEMRIK's free field guide explores evidence, decision rights, escalation and practical playbooks for keeping human authority visible when AI enters operational workflows.
Governance boundary
Map your AI governance boundary.
Start with one real workflow. Define the owner, risk class, data boundary, models, agents, tools, human decision rights, evidence and escalation path before authority expands.
AI can become more capable.The organisation should remain accountable for what it is allowed to do.