FDE ACADEMY · MODULE 04 · LESSON 05
Governance: oversight, transparency, and the policy nobody wrote
Who checks the output, who is told the system exists, what people may type into it, and the register that lets an organisation answer “what AI are we running?” in one page.
- Effort
- About three hours to draft, and one meeting to get it owned.
- Skills
- compliance-governance · change-management
Free and self-paced. No certification is offered.
Before you startYou have worked lessons 01 to 04 and have an issue list for your deployment.
01Oversight is a design decision
“A human reviews the output” is only true if a specific person, with the time and the authority to disagree, sees the output before it has an effect. Build the review into the flow so it cannot be skipped under pressure, and log it, because an oversight step nobody can evidence is an oversight step that will be disbelieved.
Distinguish suggestion from decision. A drafted reply a person edits is one thing; a classification that routes a case without anyone reading it is another, and the second attracts a different set of questions in most jurisdictions covered here.
02Transparency, in two directions
Inwards: staff should know the system exists, what it does with what they type, and what is logged. Outwards: where the system affects other people — clients, candidates, patients, customers — the organisation may owe them information about it, and that obligation is jurisdiction-specific. Read the page rather than assuming.
The cheapest version of this is a short notice next to the tool, written in the organisation’s own words, saying what it can see, what it keeps and who to ask. It prevents more incidents than any technical control.
03The policy and the register
Two documents cover most of the ground. An acceptable-use policy: which tools are permitted, by whom, on which devices, and what may not be entered into a prompt — the regulator guidance summarised on the jurisdiction pages is explicit about this kind of internal policy. And a register of deployments: what is running, who owns it, what data it touches, when it was last reviewed.
Write both, and make sure the register has a review date on every row. This site marks its own claims stale past a review window because guidance and documentation age; a governance record without a date does the same thing silently.
- Permitted tools, permitted users, permitted devices, prohibited inputs.
- A named owner per deployment, not a team name.
- The data types it touches, and the jurisdiction it operates in.
- A last-reviewed date and a next-review date, on every row.
04Do this
PRACTICAL TASK
Write the use policy and register one deployment
Draft a one-page acceptable-use policy grounded in the guidance on the relevant jurisdiction page, and create a deployment register with your deployment as its first row.
What you need
- Your deployment and its issue list from lesson 01
- The person who will own the policy — usually not you
Steps
- 01
Read the regulations and guidance section for your jurisdiction and note every instrument that speaks to internal policy, oversight or transparency.
- 02
Draft the policy in one page: permitted tools, permitted users, permitted devices, prohibited inputs, and who to ask. Plain sentences, no defined terms.
- 03
Read the human-oversight and transparency compliance notes on a higher-sensitivity recipe and check your oversight step against them.
- 04
Create the register with columns for owner, data types, jurisdiction, oversight step, last reviewed and next review. Fill in your deployment.
- 05
Get a named person to accept ownership of both documents, in writing. An unowned policy is a draft.
You are done when
- A one-page policy naming permitted tools, users, devices and prohibited inputs, in the organisation’s own words.
- A register with at least one complete row, including a next-review date.
- Both documents have a named owner who has agreed to own them.
05Where these facts live
This lesson does not restate anything that is already recorded with its evidence elsewhere on the site. These are the pages it leans on.
- Hong Kong
Regulator guidance on internal policies for generative AI use, with the primary sources it was read from.
- Contract review pipeline
A recipe whose first step is defining the clause set with a lawyer, and whose oversight step is visible in the flow.
- AI-assisted candidate workflow
Oversight written into a design rather than into a policy: the system summarises, and never ranks or rejects.
Ticks are stored in your browser only. They are not sent anywhere, they are not attached to an account, and clearing your browser data removes them.