Module 07 Synthesis — Governing AI at Scale
Many organizations that take AI seriously now have the parts of governance: principles, a policy, owners, a committee, an inventory, gates and audits. At scale, governance rarely fails inside a part. It fails at the seams, where one part hands work to the next, and those seams are what an executive should test.
After this chapter you can
- Summarize Module 07 as one system of connected parts rather than a set of documents.
- Identify the six seams where AI governance most often breaks as AI use grows.
- Explain why closing seams takes design work, not more reviewers.
- Apply six seam questions to your own organization and judge the answers by their evidence.
Suppose, in an illustrative scenario, that you sit on the board of an online specialty retailer. It is eleven at night. An AI system that sets prices for several thousand products, approved last spring after a careful review, starts cutting prices in half. Nobody changed the model. A supplier changed the units in its data feed that afternoon, and the system did exactly what it was built to do with the numbers it was given.
Three questions decide how much this costs the company.
Now notice what this retailer already has. It has principles and a policy. It has a committee and a small governance office. The pricing system sits in the inventory with a risk rating, and it passed an approval gate. Every part that Module 07 described exists. Whether the three questions get quick answers depends on something none of those documents shows: whether the parts are connected. Is the supplier feed covered by the system’s change triggers? Does the monitoring alert reach the person who owns the system, or a shared mailbox? Has anyone outside the pricing team ever tested whether the alert fires?
The core idea
Governance at scale is not a collection of good parts. It is the connections between them. In organizations that have done the basic work, the parts usually exist, and failures happen at the seams: the points where one part hands work to the next, or where one team’s version of a rule meets another’s.
This matters more as AI spreads. Each new system, business unit, supplier and model update adds handoffs. A governance team can strengthen a part by adding reviewers, but it cannot hire its way to sound seams. Seams are closed by shared definitions, shared records, triggers that fire on their own, and checks made by people who do not run the work. The executive’s job is therefore not to admire the parts. It is to test the joins. Module 09 Synthesis — From Strategy to Execution turns the same lens on delivery, the handoffs from strategy to pilots to operations; the seams here are the ones inside governance itself.
Module 07 in one pass
The module built the parts one chapter at a time, and they fall into three groups. The first five chapters set intent and authority: who may make which AI decisions, why informed trust matters, which principles apply, how a policy becomes practice and who owns each system. The next three design the structures that carry decisions: the operating model, the committee and office, and the inventory with its risk tiers. The last three keep those decisions true over time: lifecycle governance, evaluation and approval gates, and standards, monitoring and audit.
None of the questions can be answered well in isolation, because each answer is an input to the next.
Six seams where governance breaks
Where, specifically, do the parts fail to connect? Six seams recur once AI use grows beyond a handful of systems.
Scope to inventory. A policy applies to “AI”, but someone has to decide what that word covers in practice. If the definition is too narrow, risky systems never enter the register; if it is too broad, teams stop believing in it. AI Inventory and Risk Classification covers how to build the register; the seam is the agreed boundary that feeds it.
Unit to unit. Two business units can follow the same policy and still rate the same kind of system differently, because they understand “risk” differently. The AI Governance Operating Model described fragmentation as one of the two ways an operating model fails; at the seam, the test is simply whether a system would get the same rating in any unit.
Build to buy. Governance built around in-house projects can quietly exempt AI that arrives inside purchased software or through a partner. If the rules bind only what you build, the riskiest work tends to move to whatever you buy.
Approval to operation. An approval describes the system as it was on the day it was reviewed. AI Lifecycle Governance and AI Evaluation and Approval Gates set out the triggers that should reopen it. The seam fails when a new model, a new data feed or new permissions arrive and nothing connects that change to a review.
Signal to authority. Monitoring that produces an alert nobody with authority reads is a log, not a control. The seam holds when the alert reaches the named owner, or a deputy, who can pause the system. AI Roles, Ownership and Accountability defined that owner.
Management to assurance. Monitoring is management’s own view. The Institute of Internal Auditors’ Three Lines Model separates the roles that own and manage risk from internal audit, which gives the governing body independent and objective assurance on whether that view can be trusted1. AI Policies, Standards, Monitoring and Audit covered how audit works; the seam fails when audit has never looked at AI at all.
Why scale opens the seams
When AI use is small, a few people carry the seams in their heads. The head of data science knows which models run where, and the risk lead hears about changes over coffee. That works until the numbers move. Every new system adds records to keep current, every new unit adds a version of the rules, every supplier adds a contract that may or may not carry them, and every model update adds a change that may or may not trigger review.
The natural response is to strengthen the parts: more reviewers, a longer checklist, a second committee. The AI Governance Operating Model asked whether doubling AI use would force the governance team to double, and showed why a yes means the model is a queue. The seam view explains why: extra reviewers strengthen a part, but they do nothing for the joins between parts.
Most seam fixes are design work rather than headcount. A shared list of examples that shows what is in and out of scope. One rating method that every unit uses, with local judgment added on top. Change triggers built into the release process, so that a new model version cannot ship without a fresh review. Alerts that route to a named owner, with a deputy for nights and holidays. Each of these is cheaper than a reviewer, and each keeps working as AI use grows.
What the frameworks ask for is a system that runs
The main frameworks reach the same conclusion from different directions. None of them describes governance as a project with an end date.
ISO/IEC 42001 sets requirements for establishing, implementing, maintaining and continually improving an AI management system, which is a standing system rather than a one-time exercise2. The NIST AI Risk Management Framework organizes the work into four functions, and treats Govern as cross-cutting: it is meant to inform the other three, not to sit beside them3. The Three Lines Model keeps independent assurance separate from the management it examines1.
Law adds a floor for the highest-risk uses. The EU AI Act puts continuing duties on organizations that deploy high-risk systems, not only on those that build them4.
Six questions for the board
The seams turn into a short set of questions that any executive can ask of their own organization. What makes them useful is the kind of answer they demand. A weak answer points to a document. A strong answer points to evidence that someone could check.
The questions return to the eleven o’clock scenario. “Who finds out tonight?” and “who can switch it off?” are the signal-to-authority seam. “Did the supplier feed count as a change?” is approval to operation. “Who tells the board independently?” is management to assurance. An organization that can answer all six with evidence has governance that will hold as AI use grows. One that answers with the names of documents has parts.
Story: a decentralized company tests its own seams
AstraZeneca offers a detailed public account of a large company putting AI governance into practice across independent business areas. Two researchers from the University of Oxford observed the company for 12 months as it prepared for and went through an AI audit, and published what they saw6.
In November 2020, AstraZeneca’s board published five Principles for Ethical Data and AI: private and secure; explainable and transparent; fair; accountable; and human-centric and socially beneficial. The next problem was structural. The company’s business areas operate independently, with different levels of digital maturity and different kinds of AI, from in-house drug-discovery models in research to analytics tools used by sales teams.
The dilemma. Put yourself in the leadership’s position. You could mandate one governance structure for every business area, from the top. That would make standards consistent but would cut against the way the whole company is run. Or you could let each area build its own structure within the principles, which would fit local reality but risk a different version of governance in every area. Which would you choose, and how would you find out whether it was working?
What the company did. AstraZeneca let each business area design its own AI governance, as long as it aligned with the principles, and added four enterprise-wide supports to hold the pieces together.
The audit, coordinated by the internal audit function and conducted by an outside professional-services firm, reviewed governance structures and selected projects in depth. It did not test individual systems technically.
The reveal. The audit found that the hard problems were not inside any single part. They were at the seams.
On scope, the company did not try to write a perfect definition of AI. Its playbook listed the capabilities that brought a system into scope, with examples: a statistical test run during data analysis was out, while automated statistical tests that put patients into different arms of a clinical trial were in. On consistency, the researchers suggested harmonizing the checks against law and policy across business areas while letting each area adapt its open-ended risk questions to its own work. On procurement, they recommended making alignment with internal governance a condition of future contracts, so that vendor and in-house systems would be treated equally. They also noted that the company found it hard to measure whether governance was changing outcomes, one of the classic governance challenges the authors expect any large multinational to face.
This is not a story of failure. AstraZeneca chose to test its seams early and in the open, before a regulator or an incident did it for them. The lesson for executives is in the order of events: principles first, structure second, and then an independent test aimed precisely at the places where the parts meet.
What this means for leaders
Module 07 gave you the parts of AI governance. Holding them together at scale comes down to a few habits. Ask about joins, not parts: when someone reports that a policy, a committee or an inventory exists, ask what connects it to the next step. Spend on design before headcount, because shared definitions, automatic triggers and routed alerts keep working as AI use grows, while reviewers only add capacity to one part. And commission an independent look at the seams early, while fixing them is still cheap.
Check yourself
- Once an organization has a policy, a committee and an inventory, its AI governance can scale.
- Doubling the number of reviewers is the most direct way to keep governance working when AI use doubles.
- AI that arrives inside purchased software should sit in the same register and follow the same rules as AI built in-house.
- ISO/IEC 42001 describes AI governance as a project that ends at certification.
- In the AstraZeneca audit, the hardest problems lay inside individual AI models.
- A strong answer to a board question about AI governance points to evidence someone could check, not to a document.
Reflection: trace one handoff
What comes next
Governance answers whether an organization may use AI, and how safely. It does not answer whether the use pays off, and every control described in this module, from human review to independent audit, has a cost of its own. Module 08 turns to that question. Its first chapter, The Economics of AI, explains why AI behaves like a metered service and how leaders judge what each unit of value really costs.
Laws referenced
Not legal advice. Laws change; verify before relying on this, and consult counsel for decisions.
EU AI Act · EU
Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744
Risk-based rules. Prohibited practices include social scoring, untargeted scraping of facial images, and emotion recognition in workplaces and schools (with narrow exceptions). High-risk systems (Annex III: biometrics, safety components of critical infrastructure such as energy, water and traffic, employment and worker management, credit, education, essential services, law enforcement, migration, justice) need risk management, data governance, documentation, logging, human oversight, human oversight that keeps people able to understand the system, notice automation bias (over-reliance on its output), override it or stop it (Art. 14(4)), appropriate accuracy, robustness and cybersecurity (Art. 15), automatic logging of events (Art. 12), a provider quality-management system (Art. 17) and conformity assessment. An Annex III system is not high-risk if it poses no significant risk of harm, for example a narrow procedural or preparatory task that does not replace human assessment; systems that profile people are always high-risk, and a provider relying on this exception must document it and register (Art. 6(3)). Deployers of high-risk AI must use it as instructed, assign competent human oversight, monitor its operation, keep logs for at least six months and report serious incidents (Art. 26); employers must inform workers' representatives (Art. 26(7)). Public bodies, private providers of public services, and deployers of credit-scoring or life and health insurance pricing systems must carry out a fundamental-rights impact assessment before first use (Art. 27). Providers must run post-market monitoring (Art. 72). A deployer that puts its name on a high-risk system, substantially modifies it, or changes its purpose so that it becomes high-risk takes on the provider's obligations (Art. 25(1)). A substantial modification (Art. 3(23)) of a high-risk system needs a new conformity assessment, unless the change was pre-determined and documented at the first assessment, as with planned continuous learning (Art. 43(4)). Providers of general-purpose AI models (from 2 Aug 2025) must keep technical documentation, have a policy to comply with EU copyright law including text-and-data-mining opt-outs, and publish a sufficiently detailed summary of training content (Art. 53). Research, testing and development before a system is placed on the market or put into service is outside the Act, except testing in real-world conditions (Art. 2(8)). Since the 2026 Omnibus, the Art. 4 AI-literacy duty is an obligation of effort (take measures to support literacy), not of result. Fines reach EUR 35 million or 7% of global turnover for prohibited practices.
- 2024-08-01 — Entered into force
- 2025-02-02 — Prohibited practices (Art. 5) and the AI-literacy duty (Art. 4) apply
- 2026-07-27 — Omnibus softens Art. 4: providers and deployers must take measures to support AI literacy; no specific level must be guaranteed
- 2025-08-02 — General-purpose AI model obligations apply; governance and penalties regime in place
- 2026-08-02 — Transparency duties (Art. 50) apply: disclose AI interaction, label synthetic and deepfake content (marking for generative systems already on the market: 2 Dec 2026)
- 2027-12-02 — High-risk obligations for Annex III systems (e.g. hiring, credit, education, essential services) - moved from 2 Aug 2026 by the 2026 Omnibus
- 2028-08-02 — High-risk obligations for AI in products regulated under Annex I
Last verified 2026-10-06 · official text
EU Digital Omnibus on AI · EU
Regulation (EU) 2026/1744
First amendment to the AI Act. Defers high-risk obligations (Annex III to 2 Dec 2027, Annex I to 2 Aug 2028), adds two prohibited categories, softens the Art. 4 AI-literacy duty to "take measures to support", and simplifies some compliance duties. Art. 50 transparency duties still apply from 2 Aug 2026, with one transition (new Art. 111(4)): providers of generative AI systems placed on the market before 2 Aug 2026 must meet the Art. 50(2) marking duty by 2 Dec 2026.
- 2026-07-24 — Published in the Official Journal
- 2026-07-27 — Entered into force
- 2026-12-02 — Grace period ends for safeguards against two new prohibited uses (non-consensual intimate imagery, child sexual abuse material)
- 2026-12-02 — Art. 50(2) marking duty applies to generative AI systems placed on the market before 2 Aug 2026 (Art. 111(4))
Last verified 2026-10-10 · official text
References
- The Institute of Internal Auditors. The IIA's Three Lines Model: An update of the Three Lines of Defense. The IIA. 2020.
- ISO/IEC. ISO/IEC 42001:2023 Information technology - Artificial intelligence - Management system. International Organization for Standardization. 2023.
- National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. NIST. 2023.
- European Parliament and Council of the European Union. Regulation (EU) 2024/1689 (Artificial Intelligence Act), Article 26: Obligations of deployers of high-risk AI systems. Official Journal of the European Union. 2024.
- European Union. Regulation (EU) 2026/1744 (Digital Omnibus on AI) amending Regulation (EU) 2024/1689. Official Journal of the European Union. 2026.
- Jakob Mökander and Luciano Floridi. Operationalising AI governance through ethics-based auditing: an industry case study. AI and Ethics 3(2), 451-468 (online 31 May 2022). 2023.
Further reading
- Jakob Mökander and Luciano Floridi. Operationalising AI governance through ethics-based auditing: an industry case study. AI and Ethics 3(2), 451-468 (online 31 May 2022). 2023.
- ISO/IEC. ISO/IEC 42001:2023 Information technology - Artificial intelligence - Management system. International Organization for Standardization. 2023.
- The Institute of Internal Auditors. The IIA's Three Lines Model: An update of the Three Lines of Defense. The IIA. 2020.
Sources last verified 2026-10-08.