P02 / AI governance / Independent work sample
AI governance.
AI use cases need accountable owners, review criteria and documented oversight.
The decision
behind the work.
Govern AI use cases from discovery and classification through evaluation, deployment authorization, monitoring, and retirement.
Methodology and scope are defined in the project manifest. Listed capabilities describe the module design; source files show the implemented subset.
Assessment approach
- AI inventory
- Use-case and impact classification
- Model and supplier provenance
- Human oversight records
- TEVV evidence
- MCP tool authorization
- Post-deployment monitoring
Evidence
to request.
Start with source records, owner confirmation, scope and observation dates. A completed template alone does not establish operating effectiveness.
Defined output contract
- ai-system-card.json
- risk-impact-assessment.json
- deployment-decision.json
- monitoring-plan.json
The manifest defines these expected artifacts; confirm their existence and completion in source before relying on an output.
Read the full manifest ↗Review & decision boundaries
- AI may assist drafting but cannot approve its own deployment
- Legal classification remains reviewable
- Material model changes require reassessment
Remediation sequence
Record each finding with its evidence reference, risk rationale, accountable owner, target date and closure test. Escalate missing evidence rather than treating it as a pass.
Present management with the supported conclusion, remaining uncertainty and a specific decision request.