Learning Objectives
By the end of this lesson, the learner should be able to:
- Define AI governance and explain its importance in business analytics.
- Explain the relationship between AI governance, data governance and corporate governance.
- Identify major risks associated with artificial intelligence and analytical systems.
- Explain key privacy principles relevant to business analytics.
- Describe methods for identifying, assessing and mitigating analytical risks.
- Explain the importance of accountability, transparency and human oversight.
- Apply international AI and risk-management frameworks to business situations.
- Develop a basic AI and analytical risk-management approach.
1. Introduction to AI Governance
Artificial intelligence is increasingly being incorporated into business operations and decision-making. Organizations use AI and advanced analytics for forecasting, fraud detection, customer segmentation, credit assessment, recommendation systems, automation and strategic planning.
However, AI systems can create significant risks if they are poorly designed, incorrectly implemented or used outside their intended purpose.
AI governance refers to the policies, structures, processes, responsibilities and controls established to ensure that AI systems are developed, deployed, monitored and retired in a responsible and controlled manner.
AI governance seeks to balance:
Innovation + Business Value + Risk Management + Responsible Use
2. Importance of AI Governance
AI governance is important because analytical and AI systems can affect:
- Customers.
- Employees.
- Suppliers.
- Investors.
- Regulators.
- Communities.
- Organizational reputation.
Poor governance can result in:
- Privacy violations.
- Discriminatory outcomes.
- Incorrect decisions.
- Security breaches.
- Financial losses.
- Regulatory violations.
- Reputational damage.
- Loss of stakeholder trust.
The OECD AI Principles emphasize human-centred values, fairness, transparency, robustness, security, safety and accountability throughout the AI lifecycle.
3. AI Governance and Data Governance
AI governance and data governance are closely connected but are not identical.
Data Governance
Focuses on:
- Data ownership.
- Data quality.
- Data access.
- Data security.
- Data definitions.
- Data lifecycle management.
- Appropriate use of data.
AI Governance
Focuses on:
- AI use cases.
- AI system development.
- AI risk.
- Model validation.
- Human oversight.
- Transparency.
- AI accountability.
- Monitoring and continuous improvement.
Good AI governance therefore requires strong data governance.
4. AI Governance and Corporate Governance
AI governance should form part of the organization’s wider governance framework.
A simplified structure is:
Board and Executive Leadership
↓
Enterprise Governance
↓
AI and Data Governance
↓
Risk and Compliance
↓
Technology and Security
↓
Business Operations
This structure helps ensure that responsibility for AI does not remain exclusively within the IT or analytics department.
5. International AI Governance Frameworks
Important international frameworks include:
- NIST AI Risk Management Framework (AI RMF).
- ISO/IEC 42001:2023.
- OECD AI Principles.
- ISO/IEC 23894:2023.
The NIST AI RMF provides a voluntary framework for organizations designing, developing, deploying or using AI systems. Its four core functions are Govern, Map, Measure and Manage.
ISO/IEC 42001:2023 provides requirements for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System.
6. AI Risk
AI risk is the possibility that an AI system may produce harmful, incorrect, unfair, insecure or otherwise undesirable outcomes.
AI risks can arise from:
- Data.
- Models.
- Algorithms.
- People.
- Processes.
- Technology.
- Security.
- Business context.
- External changes.
Risk management should therefore cover the entire AI lifecycle.
7. Major Categories of Analytical Risk
7.1 Data Risk
Problems associated with:
- Poor-quality data.
- Missing data.
- Inaccurate data.
- Outdated data.
- Biased data.
- Incomplete datasets.
7.2 Model Risk
Problems caused by:
- Incorrect assumptions.
- Poor model selection.
- Overfitting.
- Poor validation.
- Inappropriate variables.
- Model deterioration.
7.3 Privacy Risk
Risks associated with:
- Unauthorized collection.
- Excessive collection.
- Improper sharing.
- Re-identification.
- Unauthorized access.
- Inappropriate retention.
7.4 Security Risk
Includes:
- Unauthorized access.
- Data theft.
- Model manipulation.
- Data poisoning.
- Adversarial attacks.
- Credential compromise.
7.5 Ethical Risk
Includes:
- Discrimination.
- Unfair treatment.
- Lack of transparency.
- Excessive automation.
- Harm to affected individuals.
7.6 Regulatory Risk
Organizations may face consequences when analytical systems fail to comply with applicable laws and regulatory requirements.
7.7 Reputational Risk
Poor analytical decisions can reduce stakeholder confidence in an organization.
8. Privacy in Business Analytics
Business analytics often involves personal, financial, behavioural or commercially sensitive information.
Privacy governance should consider:
- Why the data is collected.
- Whether collection is appropriate.
- How the data will be used.
- Who can access it.
- How long it will be retained.
- Whether it can be shared.
- How it will be protected.
The OECD principles specifically recognize privacy and data protection as part of human-centred and trustworthy AI.
9. Data Minimization
Data minimization means collecting and processing only information that is reasonably necessary for the intended purpose.
For example, an organization developing a customer-service analytics dashboard should not automatically collect unrelated personal information simply because its systems can technically capture it.
Data minimization can reduce:
- Privacy exposure.
- Security exposure.
- Storage requirements.
- Governance complexity.
10. Purpose Limitation
Data should generally be used consistently with its legitimate and defined purpose, subject to applicable law and organizational requirements.
For example:
Data collected to process a customer transaction should not automatically be assumed to be appropriate for unrelated analytical purposes.
Business analysts should therefore understand the intended purpose of data before using it.
11. Privacy by Design
Privacy should be incorporated into analytical systems from the beginning.
Possible controls include:
- Access restrictions.
- Data minimization.
- Encryption.
- Pseudonymization.
- Retention controls.
- Audit trails.
- Appropriate authentication.
Privacy should not be treated solely as a problem to solve after deployment.
12. Human Oversight
Human oversight is particularly important where analytical systems can significantly affect individuals or organizations.
Human oversight may involve:
- Reviewing high-risk decisions.
- Investigating unusual outputs.
- Approving important actions.
- Overriding inappropriate recommendations.
- Monitoring system performance.
The OECD principles specifically emphasize human agency and oversight where appropriate.
13. Transparency and Explainability
Stakeholders may need meaningful information about:
- What an AI system does.
- What data it uses.
- Its capabilities.
- Its limitations.
- How outputs are generated.
- How decisions can be challenged.
Transparency is particularly important where AI outputs have significant consequences.
14. Model Validation
Before an important analytical model is deployed, it should be appropriately tested and validated.
Validation may examine:
- Accuracy.
- Robustness.
- Generalization.
- Bias.
- Stability.
- Security.
- Suitability for the intended business purpose.
A model should not be judged solely by its technical accuracy.
15. Model Drift
Model performance can deteriorate when the environment changes.
Examples include:
- Changes in customer behaviour.
- Changes in economic conditions.
- Changes in fraud patterns.
- Changes in market conditions.
- Changes in data distributions.
Organizations should therefore monitor important models after deployment.
16. Generative AI Risk
Generative AI introduces additional analytical risks, including:
- Hallucinations.
- Inaccurate information.
- Confidential-data leakage.
- Bias.
- Intellectual-property concerns.
- Prompt injection.
- Misuse of generated content.
NIST’s Generative AI Profile provides additional guidance for identifying and managing risks associated with generative AI.
17. AI Risk Assessment
A business analyst can structure an AI risk assessment around the following questions:
- What is the purpose of the system?
- Who will be affected?
- What data will be used?
- What could go wrong?
- How likely is each risk?
- What could be the impact?
- What controls already exist?
- What additional controls are required?
- Who is responsible?
- How will performance and risk be monitored?
18. Risk Matrix
Organizations may classify risks using likelihood and impact.
|
Likelihood |
Impact |
General Risk |
|
Low |
Low |
Low |
|
Low |
High |
Medium |
|
High |
Low |
Medium |
|
High |
High |
High |
Organizations may use more sophisticated risk scales depending on their needs.
19. Risk Mitigation
Common approaches include:
Avoid
Do not implement the proposed use case where risk is unacceptable.
Reduce
Introduce controls that lower likelihood or impact.
Transfer
Use appropriate contractual or other risk-sharing arrangements.
Accept
Accept the risk when it falls within approved organizational risk tolerance.
20. AI Risk Register
An AI risk register may contain:
|
Risk |
Likelihood |
Impact |
Owner |
Control |
|
Biased data |
Medium |
High |
Data Team |
Bias assessment |
|
Privacy breach |
Low |
High |
Security Team |
Access controls |
|
Model drift |
Medium |
Medium |
Analytics Team |
Performance monitoring |
|
Incorrect output |
Medium |
High |
Business Owner |
Human review |
21. AI Governance Roles
Responsibilities may be distributed among:
Board / Executive Management
Provides strategic oversight.
AI Governance Committee
Coordinates AI policies and risk management.
Data Governance Team
Oversees data quality, access and appropriate use.
Analytics Team
Develops, validates and monitors analytical systems.
IT and Security
Protect infrastructure and information.
Legal and Compliance
Provides regulatory and legal guidance.
Business Owner
Remains accountable for the business purpose and outcomes.
22. Third-Party AI
Organizations increasingly obtain AI capabilities from external providers.
Before adopting such systems, organizations should consider:
- Vendor security.
- Data processing.
- Privacy.
- Contractual obligations.
- Performance.
- Reliability.
- Transparency.
- Regulatory requirements.
- Exit arrangements.
Using a third-party system does not automatically eliminate organizational responsibility.
23. AI Procurement
Before acquiring an AI solution, decision-makers should ask:
- What problem does it solve?
- What data does it require?
- Where is data processed?
- How is information protected?
- What evidence supports its performance?
- What are its limitations?
- How are updates managed?
- How can the system be audited?
- What happens if the provider becomes unavailable?
24. Continuous Monitoring
AI governance must continue after deployment.
Organizations should monitor:
- Model performance.
- Data quality.
- Bias.
- Security.
- Privacy incidents.
- User feedback.
- Unexpected outcomes.
- Changes in the operating environment.
NIST describes AI risk management as a continuing activity across the AI lifecycle rather than a one-time exercise.
25. AI Governance Lifecycle
A practical lifecycle is:
Identify Use Case
↓
Assess Risk
↓
Assess Data and Privacy
↓
Develop or Procure
↓
Test and Validate
↓
Approve
↓
Deploy
↓
Monitor
↓
Review
↓
Improve or Retire
26. Case Study: Credit Risk Analytics
A financial institution wants to use machine learning to assess credit risk.
Potential benefits include:
- Faster decisions.
- Consistent analysis.
- Better risk identification.
- Reduced processing costs.
Potential risks include:
- Historical bias.
- Privacy concerns.
- Incorrect predictions.
- Lack of transparency.
- Model drift.
Appropriate controls could include:
- Data-quality testing.
- Bias testing.
- Model validation.
- Human oversight.
- Documentation.
- Continuous monitoring.
27. Role of the Business Analyst
The business analyst can support AI governance by:
- Defining the business purpose.
- Identifying stakeholders.
- Documenting requirements.
- Identifying risks.
- Assessing data requirements.
- Supporting validation.
- Communicating limitations.
- Monitoring business outcomes.
Lesson Summary
AI governance provides the structures necessary for responsible use of AI and advanced analytics.
The major principles include:
- Accountability.
- Transparency.
- Privacy.
- Security.
- Human oversight.
- Risk management.
- Model validation.
- Continuous monitoring.
- Proportionality.
- Responsible innovation.
The central principle is:
AI should be governed throughout its lifecycle so that organizations can obtain its benefits while managing risks to individuals, organizations and society.
References
- NIST — Artificial Intelligence Risk Management Framework (AI RMF 1.0) NIST AI RMF 1.0
- NIST — AI Risk Management Framework NIST AI Risk Management Framework
- NIST — AI RMF Resources NIST AI RMF Resources
- ISO/IEC 42001:2023 — AI Management System ISO/IEC 42001:2023
- OECD — AI Principles OECD AI Principles
- OECD — What are the OECD Principles on AI? OECD AI Principles Publication