AI Governance Committee: Charter and Cadence
The question arrives at 11:04 on a Tuesday, in an email with nine people copied, and it is perfectly reasonable: the customer-operations team wants an AI assistant that drafts responses using three years of recorded support calls, and someone would like to know whether that is allowed. By 11:40 it has reached legal, who forward it to privacy, who ask whether it has been to the AI steering group, which meets in eleven days. On day twelve the group discusses it for six minutes and asks for a fuller paper. On day forty the paper arrives, two members are absent, the item is deferred. On day sixty-two the customer-operations director stops waiting and buys the tool through standard software procurement, where nobody asks about recorded calls at all. The governance body did not reject the request. It never got the chance. It simply moved slower than the organization it governed, and organizations route around slow things the way water routes around rocks.
Two Ways a Committee Dies
Almost every AI governance committee that fails does so in one of two directions, and they look like opposites until you notice they produce the same outcome.
The first is the bottleneck. A serious body, staffed by serious people, becomes the single place where AI questions go: every use case, tool, data question, vendor, and pilot extension, at the same monthly table. Because members are senior, the calendar is monthly at best. Because the agenda is long, each item gets minutes. Because items arrive underspecified, most are deferred once, and a deferral costs a full cycle. Six to ten weeks becomes the normal time to answer a question one competent person could have answered in an afternoon. Chapter 4.3 named this shape at request level: the tollbooth, where governance is a queue rather than a service and compliance is slower than circumvention. At committee level the tollbooth has better catering and identical physics. The business waits twice, then finds another path.
The second is theater. A well-attended body meets on schedule, receives a handsome deck, nods at a framework, notes a risk register, and approves what is put in front of it. Minutes are produced. And if you stopped a member in the corridor and asked "what did this body decide today, and what would have happened differently if it had decided the other way?", you would get a pause. A committee that reviews everything and decides nothing is not governance. It is a distribution list with a calendar invitation, and its existence lets everyone else stop worrying while nothing is controlled.
Both end the same way: the real decisions get made elsewhere, and the organization has a governance body without having governance, which is the most dangerous configuration available because it feels safe. The difference between a committee that works and one that does not is almost entirely charter precision about two things: what the committee decides, as distinct from what it merely reviews, and what it has delegated, as distinct from what it has retained. Get both right and the body is fast and consulted before decisions rather than after them. Wrong in one direction gives you a bottleneck; wrong in the other, theater.
A committee that decides everything decides slowly. A committee that decides nothing is a mailing list.
This lesson's artifact is one page long: the Governance Committee Charter, in five parts (purpose and boundary, membership with named authorities, a decision rights table, intake and cadence, the escalation path) written so a new member can read it in four minutes and know what the body is for.
First, what this body is not
By now you have stood up several other decision-making bodies, and if the new committee overlaps them you have built the bottleneck on purpose. Distinguish them in writing, on the charter itself.
Gate day (Chapter 4.2) is the monthly stage-gate forum deciding proceed, hold, or kill on portfolio items against pre-committed evidence. It runs the portfolio; the governance committee does not. The Governance Service Catalog (Chapter 4.3) is the published menu of standing rules, review lanes with service level agreements (SLAs, the maximum turnaround published per lane), and an exception route; it handles routine data-access and usage decisions, mostly by having pre-decided them. It answers requests; the committee does not. The C-suite quarterly (the previous lesson) presents value, risk, and portfolio health to executives who allocate. It informs; it does not adjudicate.
What is left is the committee's territory: the rules, the exceptions to them, the risk posture the organization will hold, and the few decisions that genuinely cross functions and have no other natural owner. An important job, and much smaller than the one most committees are handed.
The Charter's Five Parts
Part one: purpose and boundary (with the NOT list)
Three sentences of purpose, then a list of what this body does not do. The NOT list is not a footnote. It is the highest-leverage paragraph a readiness strategist writes in the whole setup, and writing it first is what makes the purpose statement honest.
Purpose: This committee owns the organization's AI policy, its accepted risk posture, and its regulatory position. It decides exceptions to policy and the small set of AI decisions that cross functional boundaries and have no single owner. It sets the rules under which others decide everything else, and audits how those delegated decisions were made.
This committee does NOT:
- Run the AI portfolio or decide whether individual initiatives proceed, hold, or stop. That is gate day.
- Approve routine data access, tool usage, or standard use-case patterns. That is the Governance Service Catalog, and if the catalog cannot answer, the answer is a new standing rule, not a meeting.
- Manage delivery, timelines, budget, or vendor relationships day to day. Those have named owners.
- Serve as a design review, an architecture board, or a demo audience.
- Act as the place a decision goes when nobody wants to own it.
That last line earns the page. Committees accumulate work by drift, and the drift is well-intentioned: an item is ambiguous, someone says "let us take it to the AI committee," nobody objects, and the precedent is set. Six months later the agenda has nineteen items, four of which are decisions and fifteen of which are somebody's discomfort. A published NOT list gives the chair a response that is not a rebuff: not ours, here is where it goes. Every line names a destination, because a boundary without one is just a refusal.
Part two: membership sized for decisions
Most governance committees are staffed on a representation principle: every function deserves a voice, so every function gets a seat. It sounds fair, and it is the mechanism by which a decision body becomes a discussion body. Use a different rule. Every member is present because some decision in the decision rights table requires their authority. If you cannot point to the row that needs them, they are a consultee, not a member: invited to the item that concerns them, briefed, and thanked. That distinction lets the body meet monthly and finish in an hour. A working set for an organization of a few thousand people:
- The executive sponsor as chair, the person who can accept a risk on the organization's behalf and be held to it.
- The risk-holder: legal, compliance, or privacy, with authority to classify a use case and sign off on regulatory position. One seat, one named person, one deputy.
- The technology owner, accountable for the platforms, integrations, and security architecture any decision has to land on.
- Two business function heads on rotation, six or twelve months, drawn from functions with live AI work. Rotation keeps the body connected to operations and spreads governance literacy through the leadership bench without growing the table.
- The readiness strategist as secretary and evidence presenter, running intake, preparing the pack, keeping the log. Non-voting, deliberately.
That non-voting line is the measurement-independence principle again: the person who prepares the evidence should not be the person who benefits from how it lands. It costs you a vote and buys something worth more, because nobody can claim the numbers were arranged to produce a preferred decision. Independence is not an insult to your judgment; it is the reason your judgment gets believed.
The size threshold, stated honestly: past roughly eight people a body stops deciding and starts performing. Everyone present feels a need to contribute, contributions become positioning, and the chair manages airtime instead of resolving questions. When an important function feels excluded the instinct is to add a seat. Resist it: the fix runs the other way, a smaller core plus a published consultee list showing which decisions will pull each function in. A consultee called on the one item that matters to them is better served than a standing member sitting through eleven that do not.
Delegates must hold authority. One sentence in the charter: a member who must take every question back to their team is not a member. A deputy attends with the principal's authority, or the principal attends. Without this line the body develops a habit of provisional decisions, which are not decisions, and each costs a full cycle when it comes back.
Part three: the decision rights table (the charter's heart)
If you write only one part of the charter properly, write this one. It lists decision types and, against each, who decides, in what timeframe, with what reporting obligation. It is the difference between a body people bring things to and a body people wait for.
| Decision type | Who decides | Timeframe | Reporting |
|---|---|---|---|
| Change to AI policy or a standing rule | Committee | Monthly meeting | Published to all staff within 5 days |
| Exception to policy (time-bound) | Chair plus risk-holder | 5 business days | Logged, reported at next meeting |
| New AI vendor entering the portfolio | Committee | Monthly meeting | Decision and conditions in log |
| Risk acceptance above the stated threshold | Committee | Monthly meeting | Named accepting executive, expiry date |
| Risk acceptance below the threshold | Strategist plus risk-holder | 3 business days | Logged, sampled quarterly by committee |
| Regulatory classification of a new use case | Risk-holder with counsel | 10 business days | Classification and rationale in register |
| Routine data access within published rules | Service catalog lanes | Per published SLA | Volumes reported quarterly |
| Incident escalation at severity 1 or 2 | Chair, immediately | Same day | Full review at next meeting |
Notice what most of the table does: of eight decision types, five are decided below the committee. That is not giving away power. That is the committee doing its actual job, which is setting the rules under which other people decide, then auditing the log. A body that retains everything has confused authority with activity.
Say the arithmetic out loud to any executive who hears delegation as weakening. Every row pushed below the committee, with a logged trail and a sampling obligation, converts a wait of up to a month into a wait of days: if forty of sixty governed decisions a year move from a monthly cycle (average wait fifteen working days) to a five-day path, you buy back roughly four hundred working days of program latency without loosening a control. The control never lived in the waiting. It lived in the rule, the named decider, and the log.
Three drafting notes keep it honest. State thresholds numerically, in your own units: an exposure figure, a count of affected people, any processing of personally identifiable information (PII) in a new category, anything touching an employment or credit decision. Give every delegated row a sampling rate, so delegation is supervised, not abandoned. And make the log entry mandatory before the decision takes effect, because an unlogged delegated decision is indistinguishable from an unauthorized one.
Part four: intake and preparation
Most committee dysfunction is not a meeting problem but an intake problem that only becomes visible in the meeting: items arrive as questions, questions require exploration, exploration takes the hour, and the body defers. So publish one intake path, one form, one address, with a fixed submission format of five fields:
- The question, stated as a decision in one sentence, answerable yes or no or by choosing an option.
- The options, at least two, each with its consequence.
- The recommendation, with the submitter's name against it.
- The evidence, attached, no longer than two pages.
- The deadline, and what happens if it passes.
Field three transforms the body, and it is the cheapest change in this lesson. Requiring a recommendation from the submitter, not just a question, converts a committee from a debating society into a decision engine. A meaningful share of items then never arrive, because writing a recommendation sends the submitter to the existing policy, which often answers it. The items that do arrive land in a shape the committee can act on: the debate becomes whether to accept a specific recommendation, a four-minute conversation, rather than what the question even is, a forty-minute one. And accountability attaches early, because someone's name sits on the proposed answer before the meeting.
Two supporting rules finish the job. The pack circulates 72 hours ahead, and an item without a pack does not get a slot, exactly as gate day treats a missing evidence pack. Updates are read, not presented. The standing agenda puts decisions first and reserves most of the hour for them; status and information items sit at the back as pre-read, and the chair asks only "questions on the read items?" Presented updates are the largest consumer of governance time in most organizations, and they spend it delivering what the document already said. Reading recovers roughly half the room's time, permanently, for free.
Part five: cadence and the fast path
Three paths, published together, before anyone needs any of them.
The standing monthly meeting handles retained decisions: policy, vendors entering the portfolio, risk acceptances above threshold, the sampled audit of delegated decisions, the regulatory horizon. Fixed date, sixty to ninety minutes, agenda a week ahead, pack 72 hours ahead.
The 5-day fast path handles time-critical exceptions: chair plus risk-holder, decided within five business days, logged with reasons, reviewed at the next full meeting. It is not a lower standard, just the same standard with a smaller quorum and a written trail. The evidence requirement does not shrink; only the calendar does.
The emergency path handles incidents: the chair decides immediately at defined severity levels, committee reviews after. Name the severities and the chair's deputy, and rehearse once so the first use is not the first attempt.
Publish the fast path before it is needed, because a body without one gets bypassed the first time speed genuinely matters, and the first bypass is the expensive event. Not because that decision went badly (it usually does not) but because the organization learns something it cannot unlearn: the committee is optional under pressure. After one successful bypass its authority is permanently conditional. A fast path is not a concession to the business. It is what keeps that authority unconditional, by ensuring there is never a case where going around the committee is the only way to move.
The regulatory calendar earns a standing agenda slot for the same reason. EU AI Act obligations for general-purpose AI (GPAI, foundation models supplied for many downstream uses) have applied since August 2, 2025; AI-content transparency arrives December 2, 2026; high-risk Annex III on December 2, 2027; embedded high-risk Annex I on August 2, 2028. Those are dates, not vibes, and a body that cannot say which use cases are affected and who is preparing them is not holding the regulatory posture its charter claims.
The Operating Disciplines
Decisions logged with reasons
Every decision, retained or delegated, goes into one log with six fields: date, decision, decider, reasoning, conditions attached, expiry or review date. The reasoning field is the one people skip and the one carrying the value, because a decision without its reasoning cannot be reused: six months later somebody faces a similar case and either re-litigates it or guesses at what the committee would have wanted.
Chapter 4.3 gave you the precedent ratchet at request level, where every review outcome becomes a candidate standing rule by default. Run the same ratchet here: the last question of every decision is "does this generalize?", and if it does, the decision becomes a published rule and the question never reaches an agenda again. That is the compounding mechanism of the design. A committee that ratchets sees its agenda shrink quarter over quarter while coverage grows, because policy is just the sediment of decisions that turned out to be reusable. One that does not ratchet answers the same question four times a year forever and calls it governance.
Measuring the committee itself
An uncomfortable fact about governance bodies: nobody in the room experiences the waiting. Members are never blocked. The cost of slowness is paid outside the meeting, by people with no channel to report it, which is why governance drifts toward slowness by default and almost no committee notices its decline. The fix is instrumentation, in the quarterly pack beside the program's value metrics.
- Median decision latency by type, measured from intake timestamp to decision communicated, not meeting to meeting, with the 90th percentile beside it, because the tail is where bypass pressure lives.
- Agenda composition: share of meeting time on decisions versus updates. Below half, the body is drifting toward theater and the agenda needs surgery.
- Bypass incidence: AI tools, vendors, or use cases found in operation that never came through any governance path. Treat each as a design defect in intake, not a discipline failure by the business.
- Delegation ratio: the share of logged decisions made below the committee under published rules. A rising ratio with flat bypass incidence is governance getting both faster and tighter.
Bypass incidence connects to a foundational finding. MIT's 2025 study of enterprise generative AI documented a shadow economy: employees using personal AI tools productively for real work while official deployments stalled. That is what accumulates when the governed path is slower than the ungoverned one. S&P Global found 42 percent of companies scrapped most of their AI initiatives in 2025, up from 17 percent the year before, and Gartner expects over 40 percent of agentic AI projects to be cancelled by end 2027, citing escalating costs, unclear business value, and inadequate risk controls. Note that last cause: inadequate controls kill projects, and so do controls that arrive too late to be used.
The committee and the board
Three lines settle the upward relationship. What escalates: risk acceptances above a named board threshold, regulatory classifications that change the organization's obligations, severity 1 incidents. What is reported: a quarterly decision summary, the committee's latency and bypass metrics, the open exception register with expiry dates. What is reviewed annually: the charter itself, because one written for four AI use cases will be wrong for forty. Level 5 takes this into enterprise governance properly; for now, put the annual review in the calendar the day you publish version one, because charters that are never revisited become fiction quietly.
Norvik Group's First Quarter: A Worked Example
Norvik Group, the 2,400-person business-to-business services and distribution company this level has followed, stood up its AI governance committee in January. Every number below is illustrative, showing the shape of the thing rather than promising yours.
The strategist wrote the NOT list first: five lines, each naming a destination. Portfolio decisions to gate day. Routine data access to the Governance Service Catalog. Delivery and vendor management to named owners. Design review to the technology function. And the fifth, which took two conversations to agree: this committee is not where a decision goes because nobody wants to own it. Only then was the purpose statement written, and it took three sentences because the boundary had done the work.
Membership: seven. The chief operating officer as chair and sponsor, the general counsel as risk-holder, the chief information officer as technology owner, two function heads on six-month rotation (customer operations and finance shared services, both with live AI work), the strategist as non-voting secretary, and internal audit as a non-voting observer. Nine functions asked for seats; seven of those requests became named consultee entries with a published note on which decision types would pull them in, and two were called in the first quarter.
The decision rights table: eight rows, five delegated. The retained-risk threshold was set numerically in a forty-minute argument the chair called the most useful forty minutes of the setup: any decision touching employment, credit, or health data; any exposure above an agreed figure; any processing of PII in a category not covered by a standing rule. Everything below went to the strategist plus the general counsel on a three-day clock, logged, five sampled each quarter.
Intake did something nobody expected. The first draft agenda had eleven items. The strategist sent each submitter the required format and asked for a recommendation with their name against it. Four came back withdrawn: writing the recommendation had sent each submitter to the existing policy, which already answered the question. One more was routed to the service catalog as routine access. The first real meeting had six items and finished in fifty-five minutes, four of them in under five minutes each because the recommendation was sound and the evidence attached.
First-quarter results. Median decision latency across all types: nine days, against a pre-committee baseline nobody had measured but which the strategist reconstructed from email threads at five to nine weeks. Fast-path median: three days across four exceptions, all logged and reviewed at the following meeting, no reversals. Agenda composition: 70 percent of meeting time on decisions, achieved almost entirely by moving updates to pre-read. Bypass incidence: zero discovered instances, though the strategist noted that one quarter is not evidence of a pattern, only the absence of a bad one. Delegation ratio: rising, because the decision log produced three generalizable outcomes that became standing rules, each retiring a recurring question.
One hard case, narrated. The C-suite quarterly surfaced a vendor concentration finding: four of Norvik's seven AI-touching capabilities ran on one platform provider, renewal fourteen months out. By the charter's own test this was genuinely a committee decision: cross-functional, above the exposure threshold, not answerable by any existing rule. It arrived through intake with three options and a recommendation, and was decided in one meeting: accept the concentration for now, with three dated conditions. An exit-readiness assessment for the two highest-value workflows by a named date, a data-portability clause in the renewal, and a mandatory refresh of the acceptance at the next renewal rather than an open-ended one. Named accepting executive: the chair. Expiry: fourteen months. The item took nineteen minutes, and it could only take nineteen minutes because everything around it was designed so the committee's scarce hour went to exactly this question.
The Representative Committee: A Failure Story
Now the counter-example, and its discomfort is the point, because nothing went wrong that anyone could name at the time.
A health-services organization of about 6,000 staff formed an AI governance council in the spring. The intent was excellent, the executive backing real, and the founding principle the one that sounds unimpeachable in every kickoff ever held: every function needs a voice. Nineteen members were named, covering clinical, pharmacy, information technology, security, legal, privacy, human resources, finance, procurement, quality, patient experience, research, and three operating regions. It would meet quarterly, because aligning nineteen senior calendars more often was not realistic. A terms-of-reference document described the remit as oversight and guidance on responsible AI adoption.
The April meeting ran two hours. Introductions took twenty-five minutes; a consultant presented a responsible-AI framework with seven principles; the discussion was rich. Nothing was decided, because nothing had been brought as a decision, because there was no intake path, because nobody builds one for a body whose remit is oversight and guidance.
The second meeting slipped to September on summer calendars and a quorum problem. It reviewed a draft AI policy. Nineteen thoughtful people with different professional obligations produced forty comments, several in genuine conflict, and it closed with an action to reconcile the feedback next session. No decision rights table said who resolved a conflict between the clinical view and the procurement view, so the reconciliation had no owner with authority to close it.
Meanwhile, in the eight months between formation and the third meeting, three business units deployed AI tools. Not secretly and not in defiance: through normal software procurement, with purchase orders, security questionnaires, and signatures, because that path existed and had a timeline they could plan around. The ungoverned path was not chosen over the governed one. It was the only one that could be used.
The December meeting was spent being briefed on those deployments. One tool was summarizing patient-contact notes with no documented human verification step and no record of where its outputs went downstream. Remediation took four months and a regulator conversation nobody had planned for.
Look at what this body had: legitimacy from the chief executive, expertise (genuinely the right nineteen people), backing, budget, a terms-of-reference document. What it never had was a decision rights table, an intake path, and a fast path. Those three absences were enough. Governance that cannot move at the speed of the thing it governs does not slow that thing down. It only loses sight of it.
And notice the final cruelty: the council existed precisely because the organization took AI risk seriously. That seriousness went into membership breadth and framework quality, which do not produce control, instead of decision rights and cadence, which do. Gartner's warning that inadequate risk controls will help cancel over 40 percent of agentic AI projects by end 2027 describes organizations exactly like this one, not careless ones.
What to Do Monday Morning
Standing a committee up or repairing one that drifted, the sequence is the same.
- Write the NOT list before the purpose statement. Five lines, each naming where that work goes instead. If you already have a stage-gate forum and a service catalog, the list writes itself and shows how small the committee's real job is.
- Build the decision rights table and push every row you can below the committee. Four columns: decision type, decider, timeframe, reporting. For each row ask "what rule would let someone else decide this safely?", and if you can write it, delegate the row with a log and a sampling rate. Retain fewer than half.
- Set the retained-risk threshold in numbers, not adjectives. Forty minutes with the chair and the risk-holder, leaving with a written line: which data categories, which decisions about people, which exposure figure. Everything below is delegated with a clock.
- Require a recommendation in the intake format. One form, five fields, the submitter's name on the proposed answer. Then watch the first agenda shrink as submitters discover the existing policy already answers them.
- Publish the 5-day fast path before anyone needs it, naming the chair, the risk-holder, each deputy, and the logging requirement. Publishing in calm conditions stops the first urgent case becoming the first bypass.
- Start measuring your median decision latency this week, from intake timestamp to decision communicated, by type, with the 90th percentile beside it, reported in the quarterly pack. A body that reports its own speed stays fast, because nobody in the room feels the waiting unless someone counts it.
Key Takeaways
- Recognize the two failure modes: the bottleneck that routes every question to a monthly table and gets bypassed, and the theater that approves everything and holds authority nobody can name.
- Write the NOT list before the purpose statement, giving each line a destination: portfolio decisions to gate day, routine access to the Governance Service Catalog, reporting to the C-suite quarterly, delivery to named owners.
- Staff for decisions, not representation: every member holds an authority some row of the table requires, eight people maximum, with rotating function heads and named consultees instead of extra seats.
- Build the decision rights table as the charter's heart (decision type, decider, timeframe, reporting) and delegate every row you can safely write a rule for, because delegation with a logged trail buys back weeks of latency without loosening a control.
- Require a recommendation, not just a question, in intake: it retires items existing policy already answers and turns the rest into four-minute decisions.
- Publish the 5-day fast path and the incident path before anyone needs them, because a body without one gets bypassed the first time speed matters, and its authority is then permanently conditional.
- Run the precedent ratchet at committee level: log every decision with its reasoning and ask whether it generalizes, so reusable decisions become standing rules and agendas shrink while coverage grows.
- Measure the committee itself on decision latency, agenda composition, bypass incidence, and delegation ratio, because nobody in the room experiences the waiting and governance drifts toward slowness by default.
Skill.re