Quaintitative

MindForge Toolkit

Governance documents

Governance documents are the policies, procedures and standards that set out how a firm manages AI risk - starting with what it even counts as AI. It is one of the seventeen areas in the MindForge AI Risk Management Toolkit: MindForge is the practices, the AIRG is the expectations and standards. This guide sets out the practice, the AIRG expectation it meets, and the evidence it produces. I wrote the AIRG.

What the AIRG expects

The AIRG expects a firm to have the governance documents that define its AI approach: a consistent, enterprise-wide way to identify AI, clear ownership, and the policies that carry the oversight and lifecycle controls. Identification across all business and functional areas is a critical prerequisite, because a control only reaches the AI the firm has defined and found. See the AIRG explained and the AIRG in practice.

What MindForge says to do

The Toolkit builds the conceptual foundation first, then institutionalises it.

Principles, definition, identification

  • AI principles - an overall direction against which each use case is judged, commonly starting from the FEAT principles (fairness, ethics, accountability, transparency), kept open-ended so they last.
  • An AI definition - clear, enterprise-wide, and useful to both technical and non-technical staff, aligned with regulators, and able to catch emerging patterns such as embedded AI. A vague definition produces false positives (non-AI dragged into governance) and false negatives (shadow AI nobody governs).
  • An identification framework - the controls that apply the definition consistently: identification steps built into the software lifecycle and existing risk reviews, third-party onboarding checks, a final authority to adjudicate borderline cases, and documentation of the decisions.

Institutionalise and review

The principles, definition, roles, rules and controls are then written into the firm's governance documents - a dedicated AI policy, or AI content folded into existing documents such as the model-risk policy. Because the technology moves, the documents and the definition are reviewed periodically and revised, consulting the functions, users, providers and regulators affected.

In practice

What good looks like. A short set of AI principles, one clear enterprise-wide AI definition with worked examples of what is and is not AI, an identification framework wired into the lifecycle with a named final authority for borderline cases, and all of it institutionalised in policy and reviewed on a schedule. Documents that drive decisions, not documents that sit on a shelf.

Evidence to hold:

  • The AI policy (or the updated existing policies), the AI principles, and the enterprise AI definition with examples.
  • The identification controls in the lifecycle and risk reviews, and borderline-case decisions with their rationale.
  • The review schedule and the record of the last revision to the definition and documents.

How banks do it

The MindForge Implementation Examples show the pattern at Income Insurance: it folded its fairness, ethics, accountability and transparency assessments into enterprise model risk management, set an enterprise AI definition that risk uses to identify use cases, updated that definition as generative AI arrived, and made AI governance training and an attestation mandatory for model owners.

My take

Principles tell you to be fair, accountable, transparent. Lovely, and useless on their own. The real job is in the details.

A policy that stops at principles governs nothing. What makes governance documents real is the definition that catches shadow AI and the identification controls that apply it consistently. (From my book, AI Risk Management for Directors.)

Work with me

I train and advise financial institutions on the AIRG and on writing governance documents that actually manage AI risk. See the courses and workshops, read more on AI risk management, or get in touch.