MindForge Toolkit
The AI governance operating model
The AI governance operating model is how a firm assigns responsibility for AI across the board, senior management, and the functions that do the work. It is one of the seventeen areas in the MindForge AI Risk Management Toolkit: MindForge is the practices, the AIRG is the expectations and standards. This guide sets out the practice, the AIRG expectation it meets, and the evidence it produces. I wrote the AIRG, and the operating model is where firms most often overbuild.
What the AIRG expects
The AIRG expects oversight to be clear and effective: the board is accountable for the AI governance approach, senior management runs it and resources it, and where overall AI risk is material a cross-functional committee gives it dedicated attention. It does not mandate a shape - a central AI function or AI risk embedded in existing functions are both allowed. What it requires is consistency and real accountability. See the AIRG explained and the AIRG in practice.
What MindForge says to do
The Toolkit's first move is to leverage what already exists rather than build a parallel structure. The board and senior management already own risk under the Singapore Corporate Governance Code; the practice is to extend those roles explicitly to AI, not to invent a new persona for it.
Build on the three lines and existing committees
Firms run AI governance through the structures they already have: the three lines of defence, and committees such as Risk and Compliance, Enterprise Architecture, and Data Governance, with mandates revised to cover AI and the right people added. A senior role with overall responsibility for AI can coordinate across them, so each committee's work is mutually supporting rather than fragmented. Whether to create a new body (a "Line 1.5") depends on context and the sufficiency of existing forums.
Update the plumbing, and measure the model
Managing AI across the lifecycle is not fundamentally different from existing software, model-risk, and operations practice, so the Toolkit adds AI steps to existing workflows, AI-specific questions to templates, and AI items to the agendas of existing forums. It then expects operating-effectiveness measures - complaint trends, user feedback, documented governance gaps - plus horizon scanning, so the operating model is reviewed and improved as the technology moves.
In practice
What good looks like. AI responsibilities written into existing board and senior-management roles, the three lines and existing committees extended to AI with revised mandates, a senior owner coordinating across them, and a way to measure whether the model is actually working. One consistent approach, whatever the shape - not a separate AI governance tower.
Evidence to hold:
- Updated board and committee terms of reference that name AI responsibilities, and the named senior owner for AI.
- The three-lines mapping for AI, and the forums where AI governance effectiveness is reviewed.
- Operating-effectiveness measures and a horizon-scanning record feeding periodic improvements to the model.
How banks do it
The MindForge Implementation Examples show firms extending the structures they already had - risk, architecture, and data-governance committees - with AI mandates and people, and appointing a senior figure to coordinate across them, rather than standing up a separate AI governance hierarchy.
My take
Most of it is old risk in a new coat. Your existing risk management mostly applies. Do not build AI a shrine.
The firms that struggle here are the ones that treat AI governance as a greenfield build. The AIRG and MindForge both point the other way: extend the oversight you already run. (From my book, AI Risk Management for Directors.)
Work with me
I train and advise financial institutions on the AIRG and on building an operating model that works. See the courses and workshops, read more on AI risk management, or get in touch.
A guide in The MindForge AI Risk Management Toolkit, area by area. See also the AIRG, MindForge and CRI mapping.