02 — Capability · BC-770.10
AI Strategy & Governance
Decide where AI should and should not be used, keep a portfolio of use cases with owners and measured value, and govern models and generated output so the enterprise can defend every decision they influence.
- Responsible AI
- AI Governance
- AI Portfolio
In scope
- AI use case intake and portfolio
- Responsible-use policy and ethical review
- Model and AI risk assessment
- AI literacy for the workforce
Out of scope
- Enterprise risk framework (see BC-130)
- Regulatory compliance for AI beyond internal controls (see BC-140)
Decomposes into · 4
- BC-770.10.10AI Use Case PortfolioCollect, qualify and prioritize candidate AI uses by value, feasibility and risk, and track each approved one to a measured outcome.
- BC-770.10.20Responsible AI PolicySet the rules for fairness, transparency, human oversight and acceptable use of AI, and the review that enforces them before deployment.
- BC-770.10.30AI Risk & Model ReviewAssess each model and AI application for bias, drift, misuse and failure impact, and record who accepted the residual risk.
- BC-770.10.40AI LiteracyGive employees a working understanding of what AI tools can and cannot do, so they use them well and question them when they should.