Part of the Operationalizing Responsible AI series — a three-part leadership reflection exploring how organizations can build on existing governance capabilities to operationalize Responsible AI.
The Foundations Are Already There
One of the questions asked when discussing Responsible AI is deceptively simple.
“With so many AI regulations, standards and frameworks emerging, where do we even start?”
That question came up recently during a discussion with the Vice President and Global Head of Model Risk Management at a Tier 1 financial institution.
We weren't debating whether AI would transform the business. That decision had already been made.
The conversation was about something far more practical. With regulations, standards and frameworks continuing to emerge around the world, where should an organisation begin?
As I listened, I realised I'd experienced this before.
Several years earlier, I was leading Canada's Analytics and Data Management practice, helping organisations prepare for the introduction of the General Data Protection Regulation (GDPR). There was the same sense of urgency. Organisations wanted to understand what GDPR meant, what needed to change and how quickly they needed to respond. Like many organisations approaching Responsible AI today, they assumed the biggest challenge would be interpreting the legislation.
What I learned was something quite different.
Rather than beginning with the regulation itself, we started with the data.
The first question seemed almost too simple.
Do you know what data you have? Do you maintain a data inventory or registry?
You can't govern what you don't know exists.
What often surprises leaders wasn't the question itself, but rather how quickly it unravelled into dozens of others.
Where was personal information stored?
Where did it come from? Who owns it? Who is using it?
How would you respond to a request for access to personal information?
How does it move through the organization?
Were the right controls already in place?
Could we demonstrate that through monitoring and audit?
Those discovery conversations revealed something I hadn't fully appreciated at the time.
Most organisations already possessed many of the capabilities they needed.
Privacy, Enterprise Risk, Information Security, Legal, Records Management and Data Governance were already established.
The supporting processes were there as well. Risk assessments, governance forums, policy management, audit activities and operational controls were already embedded in the way these organisations operated.
The challenge wasn't that governance was missing.
The challenge was that these capabilities and processes weren't connected around a common objective.
Start with the foundations.
That experience has shaped the way I think about major regulatory change.
When organisations ask me where they should begin with Responsible AI, my answer is remarkably similar to the one I discovered during GDPR.
Start with the foundations.
Most organisations already have governance capabilities.
They also have mature governance processes that support those capabilities.
Committees already make decisions.
Risk assessments already exist.
Policies are reviewed.
Controls are monitored.
Audit functions already provide independent assurance.
Responsible AI isn't about replacing those capabilities.
It isn't about creating a parallel governance structure.
It's about bringing existing capabilities and processes together through a common operating model.
One observation has become increasingly clear to me in the last few years.
AI isn't exposing weaknesses in governance.
It's exposing the distance between existing operating models.
Every function is doing important work.
The opportunity is to connect those functions so governance becomes coordinated rather than fragmented.
When organisations achieve that, Responsible AI becomes part of the way they operate instead of another programme running alongside everything else.
Responsible AI does introduce new considerations.
Explainability, human oversight, continuous monitoring and model behaviour all deserve careful attention.
The mistake is assuming those new obligations require an entirely new governance ecosystem.
Responsible AI isn't about replacing existing governance.
It presents an opportunity to connecting it.
In my experience, the stronger approach is to build on the governance capabilities and business processes the organisation has already spent years developing. Those foundations don't need to be replaced. They need to be connected.
Looking back, GDPR taught me a lesson that extends well beyond privacy.
The organisations that responded most successfully weren't necessarily the ones that created the most governance. They were the ones that recognised the strength of what they had already built and found a way to bring it together.
I believe Responsible AI is asking organisations to do exactly the same thing.
The technology will continue to evolve.
The regulations will continue to evolve.
The foundations are already there.
Responsible AI doesn't begin with new governance.
It begins by connecting what already exists.
Reflection Questions
- What assumptions are you making about Responsible AI that may not be true?
- Are you trying to solve a governance problem, or a coordination problem?
- What foundations already exist within your organisation that you could build upon?