The AI Governance Committee Has Met Six Times and Shipped Nothing
Attendance is good and the minutes are thorough. Read six months of them in one sitting and the same items appear in every set, sliding down the page as new business lands above them. The committee is doing what its charter asked for, and its charter asked for advice.
The items that keep coming back
The meeting runs and it runs well. People attend, minutes circulate within a day, and the agenda gets through most of what was on it. The problem shows up when six sets of minutes are read together.
Item four appears in all six. Item nine arrived in February with an owner and a target date and has since lost both. The July minutes hold more text than the February ones and fewer things anybody downstream could act on.
An item leaves the room undecided in a small number of ways, and reading the six sets together will sort yours into them.
- The person who could settle it was absent, everyone present defers to them, and it returns when their diary allows
- The question turned out to be legal, employment or commercial, and the room was right to decline it
- It waits on an inventory of AI systems nobody has assembled and nobody in the room owns
- Everyone agreed, and nothing downstream moved, because agreement was never the output the work needed
The charter asked for advice
Read the charter and the verbs give it away: oversight, guidance, recommendations. They describe a group that produces opinions. An opinion has to be accepted by somebody with authority before an engineer changes anything, and where that person sits outside the room, the acceptance carries no date.
A second reason separates this body from every other review forum. A change advisory board knows who signs off a firewall rule. A vendor onboarding forum knows who accepts a third party. Both inherited that jurisdiction from years of precedent. An AI governance committee has none, because the question is new to everyone in the room and to everyone above them.
So each item carries two questions. The substantive one it was raised to answer, and a quieter one about who is entitled to answer it.
The jurisdiction question takes a handful of recognizable forms.
- Whether a business unit can accept residual risk on a system it owns, or whether that sits with the executive carrying the regulatory exposure
- Whether a model feature switched on inside an application the company already runs is a new system or a change to an approved one
- Whether something built internally faces the review a purchased system faces, and who rules on that
- Whether the committee can require a team to turn a running system off, and what follows if they decline
The substantive question gets answered in the room. The question about who was entitled to answer it gets reopened at the next meeting, from the beginning.
Two numbers about the body itself
Attendance and minutes describe whether the meeting happened. Two other numbers describe whether it produced anything, and both can be reconstructed from records the secretary already keeps.
The first is decisions per meeting: how many items left the room with a disposition somebody downstream could act on. Count dispositions only. An item everyone agreed to keep discussing sits exactly where it sat before.
The second is item age. Number every item the first time it appears, record that date, then measure the days from it to a disposition. Report the age of the oldest open item. An average flatters a register carrying three items from the first meeting.
Both numbers read badly in the first quarter, which is what makes them worth taking. A committee that settled two things in six meetings while carrying an item since February is describing a problem in its own charter, and the numbers give whoever wrote it something to answer.
A register row holds what the two numbers need.
- The item number and the date it first appeared, both fixed for the life of the item
- The decision being requested, written as a question with the options on the table
- The named owner who raised it and who implements whatever is decided
- The disposition: decided, delegated, escalated, declined as outside the committee's authority, or deferred
- For a deferral, the person or artifact it waits on and the date it returns
Publish the age of the oldest open item beside the count, and let the two numbers argue with each other in public.
The rights a committee needs delegated
Throughput follows from authority. A body that can only recommend produces recommendations at the rate it meets, and those recommendations queue somewhere with less visibility than the committee has.
Delegation has to be written, and it has to come from whoever holds the accountability. The GOVERN function of the NIST AI Risk Management Framework is where delegated decision rights belong, and CWS builds AI governance programs against it. It stops short of naming which executive in your organization holds them, so that page is yours to draft, and drafting it takes one conversation with one person.
Naming what the committee may not decide does as much work as naming what it may. Legal determinations, employment consequences and spending above a threshold belong elsewhere, and writing that down keeps the jurisdiction question off the agenda.
The set below is what CWS argues for. Someone reasonable could draw the thresholds differently.
- Approve or refuse a named system for a named use, with the data it may reach stated inside the approval
- Set conditions on an approval, covering logging, human review of output and limits on what the system reaches
- Accept residual risk up to a written threshold, with the route above that threshold named in the same document
- Grant an exception that carries an approver and an expiry date
- Require a running system to be suspended or withdrawn
- Rule an item outside its own authority and send it, by name, to the person who holds it
The right to require a running system to stop is the easiest one to leave out of a charter, and it is what makes the rest of the list credible.
How an item has to arrive
With rights delegated, what remains is the shape of the agenda. The frameworks stop at accountability and leave the agenda alone. What follows is a CWS working recommendation, argued from what an agenda has to carry for a decision to be recorded.
An item arrives with a recommendation from its owner, the options that were rejected, and why. An item that arrives as a topic produces a conversation, and a conversation has nothing to record. Expect the rule to be unpopular while it is new, and expect the agenda to get shorter once owners are drafting recommendations before the meeting.
Quorum is stated per decision type. If approving a system that reaches customer records requires the data owner, and the data owner has attended none of the six meetings, the committee has never been quorate for that class of decision. Saying so in the first month turns an attendance problem into a delegation request. Discovering it in the sixth turns it into six months of deferred items.
A deferral is available once, against a named blocker and a return date. When the item comes back, the committee settles it on what it has or escalates it with the question written out. Items waiting on an inventory nobody owns are the clearest case: fund the inventory with a date, or decide without it and record what was unknown.
Four rules, and they fit on the front of the agenda.
- Every item carries a recommendation, a named owner, and the options that were rejected
- Quorum is stated per decision type, and an item that cannot be settled quorate is escalated the same day
- A deferral names its blocker and its return date, and is available once
- A decision and its reasoning are written once, and the next item of the same shape is registered against it
Before the seventh meeting
Very little of this needs a new body. The people attending are the right people, and six sets of minutes show an organization that keeps turning up for the question.
What is missing is one page: what the committee may decide, up to what threshold, and where each thing it may not decide goes. That page is signed by whoever carries the accountability. Until it exists, the committee will keep producing careful advice, and the queue it lands in will stay unmeasured.
The two numbers then say whether it worked. Decisions per meeting should move inside a quarter, and the oldest open item should start getting younger. The work that gets you there is mostly clerical.
- Rebuild the register from the six sets of minutes, numbering items by the date they first appeared
- Put both numbers at the top of the next agenda
- Take the decision rights page to the executive who carries the accountability and ask for it in writing
- Name an owner and a date for the inventory the deferred items are waiting on
- Send every legal, employment or commercial item to its owner by name and off the agenda