The Governance Framework
Policy, process, and a list of what’s safe to use. Customized to your business, your industry, and your insurance carrier.
What you get
The Governance Framework is a set of written artifacts plus the process of keeping them current. It’s the difference between “we have an AI policy” and “we can produce our AI policy in front of a regulator.” Included in every MIP tier, customized at depth in Operate and Strategic.
- AI Acceptable Use Policy. Written for your business, your industry, and the regulatory bodies you answer to. Names the tools that are approved, the data classes that are in-scope and out-of-scope, the consequences of violation, the escalation path. Plain English. Signed by employees as part of onboarding.
- Approved Tool Registry. The AI allowlist for your business. Microsoft Copilot — approved. ChatGPT Enterprise on the corporate SSO — approved. Personal ChatGPT — not approved. Vendor X’s new AI feature — approved with the following data restrictions. Updated when the AI landscape changes, which is constantly.
- Data Handling Guide for AI Tools. Which data classes can be processed with which tools. Two pages. Reads like a decision tree, not a policy. The thing an associate or estimator actually consults before pasting.
- Vendor Due Diligence Checklist. What we ask of every AI vendor before we add them to the registry. Data residency, training data policy, sub-processors, security certifications, exit terms. We run it; you get the file.
- Incident Response Playbook for AI events. Detected shadow AI use, hallucinated output that affected a client, suspected data leak through an AI tool, vendor data incident disclosure. Each scenario has steps. Each scenario has a named owner inside your business.
- Training materials for new hires. A 15-minute module added to your existing onboarding — the AUP, the decision tree, the help desk contact. We refresh it quarterly to match policy changes.
- Annual review cadence. Formal end-to-end review of the Framework every 12 months, with you and your insurance broker if appropriate. Quarterly drift reviews in between.
How it’s customized
The Framework is not a template with your logo dropped on top. The variables that change per client:
- Regulated data classes. A law firm’s privileged communications, an accounting firm’s client tax data, a manufacturer’s ITAR-controlled drawings, a healthcare client’s PHI. Each gets named, each gets handling rules.
- Vendor exclusions. Some clients can’t use certain LLM providers because of contract clauses or customer requirements. The Registry reflects those exclusions explicitly.
- Role-based permissions. What an associate can do, what a partner can do, what an admin can do. What an estimator can do, what a controller can do, what shop-floor staff can do.
- Jurisdiction-specific rules. State bar AI opinions where applicable. State data breach notification laws. Industry-specific (CMMC, HIPAA, FERPA, etc.) overlays.
Where it lives
The Framework is documented inside the systems you already use. By default, we store it in IT Glue or SharePoint, with version control and access permissions you control. Legal and HR can pull the current version on demand without a ticket. Employees can find the AUP and the decision tree from their normal company portal. It is not a PDF in a drawer.
For Strategic clients, we maintain a public-facing version for inclusion in RFP responses and client-facing AI disclosures. The internal version stays internal; the external version answers “what’s your AI policy” without disclosing operational specifics.
Updated when…
- Quarterly review baseline. Every quarter, we walk the Framework against the prior quarter’s activity. What got used. What got blocked. What needs an update. Small revisions land at this cadence.
- New vendor adopted. Any new AI tool added to the Registry triggers a vendor due diligence pass and an AUP delta.
- Regulatory change. New state bar opinion, new HIPAA guidance, new CMMC interpretation, new FTC AI rule — the Framework updates within 30 days of the change.
- Incident. Anything that fires the Incident Response Playbook produces a post-incident review and, usually, a Framework update.
- Leadership shift. New CEO, new managing partner, new plant manager — we walk the new leadership through the Framework as part of their onboarding, and they get to redline it.
Book an AI Readiness Assessment
Ready when you are.
Three weeks. Fixed fee. A real report and a 90-day roadmap. You keep it whether you hire us or not.