# AI Governance Operating-Model Worksheet

Complete this worksheet for each AI workflow, agent or material scope change.

## Decision record

| Field | Decision |
|---|---|
| Workflow / use case |  |
| Business sponsor |  |
| Product owner |  |
| Engineering owner |  |
| Data owner |  |
| Security / privacy owner |  |
| Operations / FinOps owner |  |
| Intended business outcome |  |
| Non-AI alternative considered |  |

## Lifecycle gates

| Stage | Required evidence | Approver | Date / outcome |
|---|---|---|---|
| Idea | Purpose, users, data class, expected outcome |  |  |
| Design | Data flow, model/tool choices, action classes, control map |  |  |
| Build | Evaluation plan, security tests, logs and enforcement design |  |  |
| Release | Acceptance results, rollback plan, support owner |  |  |
| Operate | Quality, incidents, spend and review record |  |  |
| Change | New model, tool, data, permission or action class |  |  |

## Action policy

| Action | Autonomous / approval-gated / prohibited | Evidence before action | Enforcement point | Owner |
|---|---|---|---|---|
|  |  |  |  |  |

## Exception record

| Exception | Residual risk accepted by | Compensating control | Expiry date | Review date |
|---|---|---|---|---|
|  |  |  |  |  |

Source: [AI Governance Operating Models: Who Decides, Who Enforces, Who Gets Paged](/writing/ai-governance-operating-model/)
