views

Week 1: Foundation & Policy (Goal: Draft Policy Signed Off)
-
Day 1-2: Kickoff & Stakeholder Mapping. Assemble core team. Identify key stakeholders (Legal, Compliance, Security, Privacy, Risk, IT, key business units using AI). Map known AI projects (shadow AI hunt!).
-
Day 3-4: Gap Analysis & Principles Review. Audit existing relevant policies (IT, Security, Privacy, Ethics, Procurement). Review current AI principles. Identify immediate high-risk AI use cases.
-
Day 5-6: Draft Risk Classification Schema & Core Requirements. Define simple High/Medium/Low criteria. List 5-7 non-negotiable mandatory requirements based on principles and regulations.
-
Day 7: Develop Policy Draft. Consolidate schema and requirements into a concise Enterprise AI Policy & Standards draft document.
-
Deliverable: Draft AI Policy & Standards Document.
Week 2: Process Design & Pilot (Goal: Core Process Defined & Piloted)
-
Day 8-9: Design Intake & Triage Process. Create AI Project Intake Form. Define initial risk assessment steps.
-
Day 10-11: Develop Impact Assessment (AIA) Template. Focus on essential questions for risk identification and mitigation planning. Create a Model Card template skeleton.
-
Day 12: Map Stage-Gated Workflow. Define key review points (Concept, Pre-Dev, Pre-Deploy) and required artifacts for each. Outline incident response steps.
-
Day 13-14: Select & Pilot Process. Choose 1-2 active (preferably medium-risk) AI projects. Run them through the new intake, AIA, and documentation process. Gather feedback.
-
Deliverable: Defined Governance Workflow (Map), AIA Template, Model Card Template, Intake Form. Pilot feedback report.
Week 3: Tools & Roles Setup (Goal: Inventory Live, Tools Piloted, Roles Defined)
-
Day 15-16: Stand Up Inventory/Registry. Populate with known projects from Week 1 and pilot projects. Define mandatory fields (Owner, Risk Class, Status, Doc Links).
-
Day 17-18: Assess & Select Initial Tool. Evaluate immediate need (e.g., bias testing vs. drift monitoring). Choose one open-source or readily available tool. Integrate it into one pilot project pipeline.
-
Day 19: Define Core Roles & RACI. Draft clear responsibilities for Project Owner, Developer, Governance Lead, Review Board, Compliance, Security. Create a RACI matrix for key governance tasks.

Comments
0 comment