Quaintitative

The AIRG in Practice

The AIRG in practice: inventory, materiality, controls

The AIRG asks financial institutions to identify their AI, assess how material each use is, and apply controls in proportion to that risk. This page is the practical core: the inventory, the materiality assessment, and the lifecycle controls, and how they work as one system rather than a checklist. I wrote the AIRG, and this is how I would put it into practice.

Start by identifying your AI

It sounds trivial until you sit down to do it. When is a thing even AI: the vendor "smart feature", the old regression model, the autocomplete everyone uses? And when does an AI thing become a different thing: a retrain, a swapped step, a new set of customers? Miss one and there is no next step for it. It just runs, ungoverned, because as far as your governance is concerned it does not exist.

The inventory is the command centre

When firms ask me what separates good AI governance from bad, I go straight to the inventory. A real inventory is not a list for the auditor. It is the one place where everything about an AI system meets. With a live one, "what does this change touch, and what has to be re-checked?" is answered in an afternoon; without one, every change starts with an archaeological dig. It is also where reuse happens, because most AI in a firm only looks novel until someone notices the team next door already built the same thing.

Materiality is a throttle, not a label

Not every AI use warrants the same controls. Materiality is assessed on impact, complexity and reliance, and the depth of the controls follows that rating. One practical warning: the cheapest way to make a lot of risk disappear is to rate it low. When I inspected firms, I went to the systems rated low risk, not high, because the low rating is the one field that quietly tells every other control to try less. Materiality is a throttle on how hard everything downstream works, and it cannot be set once: a system can change materiality without a single line of code changing.

Before a system goes live

Before launch, three controls are supposed to clear a model: is it performing, is it fair, can you explain it. They are not three things. They are one instrument pointed in three directions, and the instrument is good evaluation and testing, built against the task. Explainability is that same test aimed at understanding; an explanation you never tested is theatre. Fairness is that same test with the right features in the frame, and it does not apply everywhere: forcing a fairness test on a meeting-notes summariser is the checklist reflex, not governance. Skip the evaluation and you have not done a lighter version of the work. You have done none of it.

After it goes live

After launch, four controls decide whether a live system can hurt you before you catch it, and they are one loop: watch, judge, stop, record. Monitoring is the launch evaluation never switched off. Human oversight is not a person near a button; an override rate near zero is automation bias wearing a job title. Change management is about the quiet changes: a retrain, a tweaked prompt, a vendor update nobody announced. And underneath sits the log, or the trace for agents, because you cannot watch, judge or stop what you never recorded.

It is a system, not a checklist

No control governs anything on its own. Explainability leans on selection and evaluation; human oversight leans on the monitoring that informs the overseer; fairness depends on the features in your data. Pull any control out and the ones that leaned on it should visibly fail. If you can quietly remove a control and nothing anywhere notices, what you had was never a system. For how the parts interlock, see Governing AI at Scale.

Related

This is the practical layer of the AIRG and of AI risk management in general. For agents specifically, see governing agentic AI.

Work with me

I train and advise financial institutions on turning the AIRG into a working AI risk management system, starting with the inventory and materiality. See the courses and workshops, or get in touch.