Governance and risk in the enterprise: a practical guide
Enterprise AI governance ensures the category manager and shift supervisor access relevant data, while enforcing permissions and auditability, to maintain trust and compliance, by controlling access to sensitive information and tracking system usage, which is critical for large organisations using AsscherAi to query their data.
This week, the category manager at a large retail organisation needs to decide which supplier to use for a new product line, and currently bases this decision on a combination of historical sales data, supplier performance metrics, and intuition, but is looking for a more systematic approach to evaluating suppliers, which is where enterprise AI governance comes into play, particularly in controlling access to sensitive data and ensuring that the right people see the right information, as the category manager will be using AsscherAi to query the organisation's data in natural language and get answers in real time.
Enforcing permission at retrieval
The traditional approach to controlling access to data is to instruct the model on what data it can and cannot access, but this approach can be problematic, as it relies on the model being correctly configured and updated, and can lead to errors and inconsistencies, particularly when the system is used by people who did not build it, such as the shift supervisor who needs to check the maintenance log, but may not have the necessary permissions to access the underlying data, which is why enforcing permission at retrieval, rather than by instructing the model, is a more effective approach, as it ensures that the right people see the right information, regardless of how they query the data.
This approach requires a deep understanding of the organisation's data and the different roles and responsibilities within the organisation, as well as the ability to configure the system to enforce permissions at the point of retrieval, which can be a complex task, but is essential for ensuring that sensitive data is only accessed by authorised personnel, and that the organisation's data governance policies are enforced, which is critical for maintaining trust and confidence in the system, and for ensuring that the organisation is compliant with relevant regulations and laws.
Auditability
Auditability is a critical component of enterprise AI governance, as it provides a clear record of what was asked, what was returned, and on what data, which is essential for tracking and monitoring system usage, and for identifying and addressing any potential issues or errors, such as the category manager comparing two suppliers and noticing that the results are inconsistent, or the shift supervisor checking the maintenance log and finding that the data is outdated, which can help to build trust and confidence in the system, and ensure that the organisation's data governance policies are being enforced.
This requires the ability to log and track all system activity, including queries, results, and data access, as well as the ability to analyse and interpret this data, which can be a complex task, but is essential for ensuring that the system is being used correctly and that any potential issues are identified and addressed, and for providing a clear audit trail, which is critical for maintaining transparency and accountability, and for demonstrating compliance with relevant regulations and laws, and for this reason, it is recommended to contact us to discuss how AsscherAi can help with auditability.
Categories that should route to a human
There are certain categories of queries that should always route to a human, rather than being answered by the system, such as queries that require complex decision-making or judgment, or queries that involve sensitive or confidential information, such as employee personal data or financial information, which is why it is essential to identify these categories and configure the system to route them to a human, rather than attempting to answer them automatically, which can help to ensure that the system is being used correctly and that any potential issues are identified and addressed.
This requires a deep understanding of the organisation's data and the different types of queries that are likely to be made, as well as the ability to configure the system to route certain categories of queries to a human, which can be a complex task, but is essential for ensuring that the system is being used correctly and that any potential issues are identified and addressed, and for providing a clear and transparent process for handling sensitive or confidential information, and for this reason, it is recommended to work closely with the organisation's data governance team to identify these categories and configure the system accordingly.
Model and prompt change control
Model and prompt change control is a critical component of enterprise AI governance, as it ensures that any changes to the system are carefully managed and controlled, which is essential for maintaining the integrity and accuracy of the system, and for ensuring that any changes are properly tested and validated, which can help to prevent errors and inconsistencies, and ensure that the system continues to provide accurate and reliable results, such as when the category manager updates the supplier performance metrics, and the system needs to be updated to reflect these changes.
This requires the ability to track and manage all changes to the system, including updates to the model or prompts, as well as the ability to test and validate these changes, which can be a complex task, but is essential for ensuring that the system continues to provide accurate and reliable results, and for maintaining trust and confidence in the system, and for this reason, it is recommended to have a clear and transparent process for managing changes to the system, and to work closely with the organisation's data governance team to ensure that any changes are properly managed and controlled, and to contact us to discuss how AsscherAi can help with model and prompt change control.
What this does not do
While enterprise AI governance is a critical component of any organisation's data strategy, it is not a replacement for other governance and risk management processes, such as data quality management or compliance monitoring, which are essential for ensuring that the organisation's data is accurate, complete, and compliant with relevant regulations and laws, and for maintaining trust and confidence in the system, and for this reason, it is recommended to have a comprehensive governance and risk management strategy that includes multiple components, including enterprise AI governance, data quality management, and compliance monitoring.
This requires a deep understanding of the organisation's data and the different governance and risk management processes that are in place, as well as the ability to configure and manage these processes, which can be a complex task, but is essential for ensuring that the organisation's data is accurate, complete, and compliant with relevant regulations and laws, and for maintaining trust and confidence in the system, and for this reason, it is recommended to work closely with the organisation's data governance team to develop a comprehensive governance and risk management strategy.
Frequently asked questions
What is the role of permission enforcement in enterprise AI governance?
Permission enforcement ensures the right people access the right information, preventing errors and inconsistencies, and maintaining trust in the system.
How does auditability contribute to enterprise AI governance?
Auditability provides a clear record of system usage, enabling tracking and monitoring, and helping to identify and address potential issues, ensuring compliance and transparency.
What types of queries should be routed to a human instead of the AI system?
Queries requiring complex decision-making, judgment, or involving sensitive information, such as employee personal data, should be routed to a human to ensure correct handling and maintain confidentiality.
Why is model and prompt change control essential in enterprise AI governance?
Model and prompt change control ensures that changes to the system are carefully managed, tested, and validated, preventing errors and inconsistencies, and maintaining the integrity and accuracy of the system.