Control Objectives
Governance Body Effectiveness
Establish effective governance bodies (councils, boards, committees) that make timely decisions and enforce policies.
Governance decisions not made or enforced
Decision cycle time
Role and Accountability Clarity
Ensure every agent has a named accountable owner with clear responsibilities.
Gaps or overlaps in responsibility
% agents with named accountable owner
RACI Completeness
Define RACI matrices for all governance activities to clarify who decides, acts, and informs.
Confusion over who decides, acts, or informs
% governance activities with RACI defined
Executive Training Coverage
Ensure executives understand AI governance to make informed strategic decisions.
Leadership decisions without understanding
% executives completing training
Developer Training Coverage
Train developers on secure, compliant agent development practices.
Insecure or non-compliant development
% developers certified
Business User Training Coverage
Train business users on proper agent usage to prevent misuse and maximize value.
Misuse or underutilization of agents
% business users completing training
Governance Liaison Effectiveness
Maintain effective liaisons between governance and business units to ensure alignment.
Business units disconnected from governance
Business unit satisfaction score
Change Management Execution
Execute effective change management to overcome resistance and drive governance adoption.
Resistance and adoption failure
Governance adoption rate
Communication Effectiveness
Communicate governance requirements effectively to ensure stakeholder awareness.
Stakeholders unaware of governance requirements
Awareness survey score
Feedback Mechanism Utilization
Capture and act on feedback to continuously improve governance practices.
Governance not improving from input
Feedback volume and action rate
Quick Reference
| ID | Objective | Primary Risk Addressed | Key Metric |
|---|---|---|---|
| ORG-01 | Governance Body Effectiveness | Governance decisions not made or enforced | Decision cycle time |
| ORG-02 | Role and Accountability Clarity | Gaps or overlaps in responsibility | % agents with named accountable owner |
| ORG-03 | RACI Completeness | Confusion over who decides, acts, or informs | % governance activities with RACI defined |
| ORG-04 | Executive Training Coverage | Leadership decisions without understanding | % executives completing training |
| ORG-05 | Developer Training Coverage | Insecure or non-compliant development | % developers certified |
| ORG-06 | Business User Training Coverage | Misuse or underutilization of agents | % business users completing training |
| ORG-07 | Governance Liaison Effectiveness | Business units disconnected from governance | Business unit satisfaction score |
| ORG-08 | Change Management Execution | Resistance and adoption failure | Governance adoption rate |
| ORG-09 | Communication Effectiveness | Stakeholders unaware of governance requirements | Awareness survey score |
| ORG-10 | Feedback Mechanism Utilization | Governance not improving from input | Feedback volume and action rate |