Knowing where to start an AI governance committee can be overwhelming. See how OneTrust set up our committee, and learn how you can get started in your organization
Adomas Siudika
OneTrust AI Governance Committee, Privacy Counsel, FIP
November 30, 2023
To effectively govern AI and mitigate the risks to different populations, organizations must establish diverse AI governance committees to establish policies, define risk levels and organizational risk posture, evaluate use cases, and ensure human involvement for high-risk processes.
Though most organizations can agree that having an AI governance committee is crucial to the use of responsible AI, it can be overwhelming to know where to start. To give an example, we’ll use this blog to outline how OneTrust established its AI governance committee, along with considerations for establishing a committee in your business.
We’re at this key point of AI evolution where the future of AI highly depends on whether the public will trust AI systems and companies that use them. OneTrust is fully committed to the adoption and responsible use of human-centric AI systems that adhere to our core company values, ethical principles, and put people first.
Gradual integration of AI systems throughout our business ecosystems and widespread adoption of AI systems will fundamentally change the way we operate as a business. OneTrust decided early on to establish a dedicated internal AI governance committee to oversee our efforts of building a robust AI governance program. The goal of this committee is to ensure our current and future use of AI systems conforms with OneTrust responsible AI principles, regulatory standards, and best industry practices.
The first step to forming your committee is determining who in your organization will be involved.
Here are key questions to consider for the involvement stage:
OneTrust’s AI governance committee includes representatives from the key functional areas of the organization, including Legal, Ethics & Compliance, Privacy, Information Security & Architecture, Research & Development, and Product Engineering & Management. Members of the committee have diverse skillsets, experiences, and backgrounds because we believe that cross-functional knowledge sharing is key to an effective AI governance program.
Tackling AI governance challenges requires engagement of individuals who come from a variety of specialized backgrounds. Responding to the new challenges posed by modern innovation often requires creative solutions that can be delivered when individuals representing different areas of expertise come together and bring their unique perspectives to the table.
Making sure you have a diverse committee will help you come up with the creative solutions and thoughtful response that an AI governance program requires.
Once your committee is formed, it’s time for it to govern your program. A lot falls into this category, but some key questions for the governance stage are:
Defining AI is an important building block of AI governance programs. We see the tech and business communities, academics, and legal scholars all coming up with different definitions for digital brains. Even AI may be utilized to define itself; when asked for the definition of AI, ChatGPT says: “AI is the simulation of human intelligence in machines that are programmed to perform tasks that typically require human intelligence, such as visual perception, speech recognition, decision making, and natural language processing.” It’s well articulated and highlights the essence of what AI stands for.
At OneTrust, we consulted existing AI regulatory frameworks and decided to use the definition of AI outlined in the EU AI Act. We consider new AI standards rolled out in the EU as the most advanced set of AI governance standards that shape the direction of AI policy globally.
The definition of AI systems in the EU AI Act refers to a software-based application that’s developed with one or more of the AI-embedded techniques or approaches like machine learning, statistical, logical, and/or knowledge-based approaches, and Bayesian estimation and search and optimization methods.
This definition also specifies that an AI system can generate outputs such as content, predictions, recommendations, or decisions influencing the environments that humans interact with.
In a similar vein, our internal AI governance program also adopted the AI risk classification system outlined in the EU AI Act. Following the guidelines set forth in the AI Act, we put AI systems into four risk categories:
OneTrust’s AI Use Policy (which will be rolled out shortly) doesn’t allow prohibited AI systems; that same policy sets the processes for assessing the use of all other risk categories. We leverage OneTrust Third-Party Risk Management (TPRM) tools and developed AI-risk extensions to our existing risk assessment templates. Using this process, we’re able to assess AI-linked risks, which in some instances are connected to other standards, like privacy, information security, and ethics risks domains.
While the TPRM process is highly automated, there’s always a human involved in reviewing assessments and following up in case there is an issue. We developed and are now testing internally modified versions of Privacy Impact Assessments (PIAs) that include questions about known AI-risks when assessing AI systems and our AI service providers.
These pre-built templates are an effective tool for identification of some of the new AI-linked compliance challenges, like the explainability of an AI system’s processing algorithm or adequacy in disclosures of personal information processed by AI systems.
AI systems that use higher risk data, like HR systems that usually include more personal information, must be vetted through the assessment process. This ensures that we gain the right level of visibility into how these systems are operated, what data is used, and whether the system provider followed the regulatory requirements and industry best practices when developing the system.
Our general policy is to support the use of AI systems, including generative AI tools, as long as they’re thoroughly vetted, and reasonable guardrails are put in place to manage the known risks.
Using our third-party risk assessments process, we’re able to scan for any risks and approve the use of AI-tools that are aligned with our internal AI Use Policy, including our Responsible AI principles. Rather than banning the use of generative AI, we’ll implement the same vetting protocols as we do for any other category of AI applications.
Risk assessments for AI systems will cover the whole spectrum of associated risks, including privacy and information security architecture. Based on the results of these assessments, we can make the decision on whether or not to allow the use of that AI application.
We recognize that we might not be able to completely eliminate the identified AI risks in every case – instead, we’ll turn our attention to how we can mitigate known risk and share best practice approaches for users of those systems.
For example, in OneTrust’s forthcoming AI Use Policy, we warn the users to be aware that content produced by GenAI is not entirely reliable and may not be accurate and that general purpose AI systems may mistakenly produce outcomes that may be inappropriate. We further alert users they should use caution and discretion before sharing, publishing, or otherwise using outcomes produced by GenAI systems.
Finally, we advise users that data produced by AI systems under no circumstances shall be used as a substitute for legal, financial, or any other professional advice. We are looking into educating the users of AI systems through AI risk awareness training that is part of the overall AI risk mitigation controls we will roll out to our workforce by the end of this year.
The work of your AI governance committee will be ongoing, but it is helpful to have a set cadence for regular meetings. As you’re setting up your processes, consider these key questions:
Currently, OneTrust’s AI Governance Committee is set to meet once quarterly. This cadence may be adjusted if we decide that there is a business necessity for more frequent meetings. That said, a full committee meeting is not the only way the AI Governance committee conducts its business at OneTrust.
If the Committee must make a decision on some initiative or policy, such voting is facilitated by electronic means where each committee member can vote. At the current stage, most of the AI Governance work is conducted in the smaller groups, e.g., by Information Security, Compliance, or Privacy teams. Ad hoc meetings in smaller groups play an important role in making sure that we make progress in governing our AI program.
The Committee’s meetings are intended to focus on discussions and decision making around the key areas of responsibility, which include reviewing and approving AI-linked projects and initiatives, developing AI governance policies and procedures, and monitoring that the use of AI aligns with OneTrust Responsible AI principles and values.
Although standing up an AI governance program can seem overwhelming at the start, taking it one step at a time and making sure you have the right team in place goes a long way. To learn how OneTrust can support you in your AI governance journey, request a demo today.
Webinar
This webinar will explore the key privacy pitfalls organizations face when implementing GenAI, focusing on purpose limitation, data proportionality, and business continuity. Attendees will gain insights into how to navigate these challenges through strong data governance, version control, and detailed model documentation to ensure compliance and mitigate risks.
Webinar
This webinar will explore the how AI is affecting the data landscape, focusing on how data teams can extend common data practices to support AI’s unique use of data.
eBook
Download our guide to building an AI project intake workflow that balances risk and efficiency, complete with a checklist for thorough, informed assessments.
Webinar
This webinar will uncover the top 5 data sharing challenges organizations face and demonstrate how advanced data governance solutions can streamline processes, improve data quality, and enhance compliance, allowing organizations to discover the full potential of their data assets.
White Paper
Download this white paper to learn how to adapt your data governance program, by defining AI-specific policies, monitoring data usage, and centralizing enforcement.
Report
Getting Ready for the EU AI Act, Phase 1: Discover & Catalog, The Gartner® Report
Webinar
This webinar unpacks California’s approach to AI and emerging legislations, including legislation on defining AI, AI transparency disclosures, the use of deepfakes, generative AI, and AI models.
eBook
Download this coauthored eBook by OneTrust and Protiviti to learn how organizations are building scalable AI governance models and managing AI risks.
Report
Download this 2024 Forrester Consulting Total Economic Impact™ study to see how OneTrust has helped organizations navigate data management complexities, generate significant ROI, and enable the responsible use of data and AI.
Webinar
Join us for a webinar on the latest updates and emerging trends in global privacy regulations.
eBook
Download this eBook to explore strategies for trustworthy AI procurement and learn how to evaluate vendors, manage risks, and ensure transparency in AI adoption.
eBook
Learn why discovering, classifying, and using data responsibly is the only way to ensure your AI is governed properly.
Webinar
Join our webinar to gain practical, real-world guidance from industry experts on implementing effective AI governance.
Webinar
Join our webinar and learn about the EU AI Act's enforcement requirements and practical strategies for achieving compliance and operational readiness.
Video
Learn how OneTrust AI Governance acts as a unified program center for AI initiatives so you can build and scale your AI governance program
Webinar
Whether your AI is sourced from vendors and third parties or developed in-house, AI Governance supports informed decision-making and helps build trust in the responsible use of AI. Join the live demo webinar to watch OneTrust AI Governance in action.
Webinar
Discover the EU AI Act's impact on your business with our video series on its scope, roles, and assessments for responsible AI governance and innovation.
Webinar
As innovation teams race to integrate AI into their products and services, new challenges arise for development teams leveraging third-party models. Join the webinar to gain insights on how to navigate AI vendors while mitigating third-party risks.
Resource Kit
Download this resource kit to help you understand, navigate, and ensure compliance with the EU AI Act.
Webinar
In this webinar, we'll navigate the intricate landscape of AI Governance, offering guidance for organizations whether they're developing proprietary AI systems or procuring third-party solutions.
eBook
Discover the ISO 42001 framework for ethical AI use, risk management, transparency, and continuous improvement. Download our guide for practical implementation steps.
Webinar
Join OneTrust experts to learn about how to enforce responsible use policies and practice “shift-left” AI governance to reduce time-to-market.
Webinar
Join out webinar to hear about the challenges and solutions in AI governance as discussed at the IAPP conference, featuring insights and learnings from our industry thought leadership panel.
Webinar
Colorado has passed landmark legislation regulating the use of Artificial Intelligence (AI) Systems. In this webinar, our panel of experts will review best practices and practical recommendations for compliance with the new law.
Webinar
In this webinar, we’ll break down the AI development lifecycle and the key considerations for teams innovating with AI and ML technologies.
Report
Download the full OCEG research report for a snapshot of what organizations are doing to govern their AI efforts, assess and manage risks, and ensure compliance with external and internal requirements.
Report
In this 5-part regulatory article series, OneTrust sponsored the IAPP to uncover the legal frameworks, policies, and historical context pertinent to AI governance across five jurisdictions: Singapore, Canada, the U.K., the U.S., and the EU.
Webinar
In this webinar, we’ll look at the AI development lifecycle and key considerations for governing each phase.
Webinar
This webinar will provide insights for navigating the pivotal intersection of the newly announced OMB Policy and the broader regulatory landscape shaping AI governance in the United States. Join us as we unpack the implications of this landmark policy on federal agencies and its ripple effects across the AI ecosystem.
Webinar
In this webinar, we’ll discuss the evolution of privacy and data protection for AI technologies.
Resource Kit
What actually goes into setting up an AI governance program? Download this resource kit to learn how OneTrust is approaching our own AI governance, and our experience may help shape yours.
Interactive Tool
This self-assessment will help you to gauge the maturity of your privacy program and understand the areas the areas of improvement that can further mature your privacy operations.
Webinar
Learn the challenges AI technology poses for the (re)insurance industry and gain insights on balancing regulatory compliance with innovation.
Webinar
Watch this session for insights and strategies on buiding a strong data protection program that empowers innovation and strengthens consumer trust.
Webinar
Get the latest insights from global leaders in cybersecurity managment in this webinar from our Data Protection in Financial Services Week 2024 series.
Webinar
Join the first session for our Data Protection in Financial Services Week 2024 series where we discuss the current state of AI regulations in the EU.
White Paper
Download this white paper to explore key drivers of AI and the challenges organizations face in navigating them, ultimately providing practical steps and strategies for setting up your AI governance program.
Webinar
Join OneTrust and PA Consulting as they discuss key global trends and their impact on the UK, reflecting on the topics from IAPP DPI London.
Webinar
In this webinar, we’ll discuss key updates and drivers for AI policy in the US; examining actions being taken by the White House, FTC, NIST, and the individual states.
In-Person Event
Learn how privacy, GRC, and data professionals can assess AI risk, ensure transparency, and enhance explainability in the deployment of AI and ML technologies.
AI Governance
See the latest OneTrust platform features that improve on customers' ability to build trust, ensure compliance, and manage risk.
Webinar
In this webinar, OneTrust DataGuidance and experts will examine global developments related to AI, highlighting key regulatory trends and themes that can be expected in 2024.
eBook
Data privacy is a journey that has evolved from a regulatory compliance initiative to a customer trust imperative. This eBook provides an in-depth look at the Data Privacy Maturity Model and how the business value of a data privacy program can realised as it matures.
Webinar
In this webinar, we’ll break down the four levels of AI risk under the AI Act, discuss legal requirements for deployers and providers of AI systems, and so much more.
Webinar
Join Sidley and OneTrust DataGuidance for a reactionary webinar to unpack the recently published, near-final text of the EU AI Act.
Data Sheet
Data privacy is evolving from a regulatory compliance initiative to a customer trust imperative. This data sheet outlines the four stages of the Data Privacy Maturity Model to help you navigate this shift.
Checklist
Managing third-party risk is a critical part of AI governance, but you don’t have to start from scratch. Use these questions to adapt your existing vendor assessments to be used for AI.
Webinar
In this webinar we’ll look at the AI Governance landscape, key trends and challenges, and preview topics we’ll dive into throughout this masterclass.
Webinar
OneTrust sponsored the first annual Generative AI survey, published by ISMG, and this webinar breaks down the key findings of the survey’s results.
Report
OneTrust sponsored the first annual ISMG generative AI survey: Business rewards vs. security risks.
Webinar
In this webinar, we’ll talk about setting up an AI registry, assessing AI systems and their components for risk, and unpack strategies to avoid the pitfalls of repurposing records of processing to manage AI systems and address their unique risks.
Webinar
Join Sidley and OneTrust DataGuidance for a reactionary webinar on the EU AI Act.
Webinar
Join this on-demand session to learn how you can leverage first-party data strategies to achieve both privacy and personalization in your marketing efforts.
Webinar
Join OneTrust and KPMG webinar to learn more about the top trends from this year’s IAPP Europe DPC.
eBook
Conformity Assessments are a key and overarching accountability tool introduced by the EU AI Act. Download the guide to learn more about the Act, Conformity Assessments, and how to perform one.
eBook
With the use of AI proliferating at an exponential rate, the EU rolled out a comprehensive, industry-agnostic regulation that looks to minimize AI’s risk while maximizing its potential.
Webinar
Join this webinar demonstrating how OneTrust AI Governance can equip your organization to manage AI systems and mitigate risk to demonstrate trust.
White Paper
What are your obligations as a business when it comes to AI? Are you using it responsibly? Learn more about how to go about establishing an AI governance team.
Infographic
AI Governance is a huge initiative to get started with for your organization. From data mapping your AI inventory to revising assessments of AI systems, put your team in a position to ensure responsible AI use across all departments.
White Paper
Download this white paper to learn how your organization can develop an AI governance team to carry out responsible AI use in all use cases.
eBook
We answer your questions about AI and chatbot privacy concerns and how it is changing the global regulatory landscape.
Webinar
Prepare your business for EU AI Act and its impact on the UK with this expert webinar. We explore the Act's key points and requirements, building an AI compliance program, and staying ahead of the rapidly changing AI regulatory landscape.
Webinar
Prepare for AI data privacy and security risks with our expert webinar. We will delve into the evolving technology and how to ensure ethical use and regulatory compliance.
Webinar
Join Sidley and OneTrust DataGuidence as we discuss the proposed EU AI Act, the systems and organizations that it covers, and how to stay ahead of upcoming AI regulations.
White Paper
With AI systems impacting our lives more than ever before, it's crucial that businesses understand their legal obligations and responsible AI practices.
Webinar
Join OneTrust and their panel of experts as they explore Artificial Intelligence regulation within the UK, sharing invaluable insights into where we are and what’s to come.
Regulation Book
Download this reference book and have foundational AI governance documents at your fingertips as you position your organization to meet emerging AI regulations and guidelines.
Webinar
Navigate global AI regulations and identify strategic steps to operationalize compliance with the AI governance masterclass series.
Webinar
OneTrust DataGuidance and Sidley are joined by industry experts for the annual Data Protection in Financial Services Week.