# Governance Charter **Purpose.** A short, board-approved mandate that establishes the governance programme: why it exists, what authority it has, what it covers, and how success is measured. It is what you point to when someone asks "who says so?". **When to use it.** Write it at the start of the programme and have it formally approved. Refresh when scope, sponsorship, or mandate changes. **How to use it.** Keep it to two pages. The charter grants authority; it does not describe process. If you find yourself writing procedure, that belongs in the frameworks or the committee terms of reference instead. --- ### 1. Mandate The **[Data & AI Governance Programme]** is established by **[the Board / Executive Committee]** on **[date]** to ensure that **[Organisation]** manages its data and AI assets lawfully, safely, and in line with its stated risk appetite. ### 2. Why this exists **[Two or three sentences: the specific driver. Regulatory exposure, a board concern, an incident, an AI adoption push. Be concrete — a charter that could belong to any organisation will be ignored by this one.]** ### 3. Scope **In scope:** all data held or processed by the organisation; all AI systems built, bought, or embedded; all business units and geographies **[amend]**. **Out of scope:** **[be explicit — e.g. security operations, covered by the existing security programme]**. ### 4. Authority The programme, through its committee, is authorised to: - Set mandatory standards for data and AI within scope. - Require registration and classification of any AI system. - **Halt or require remediation** of a system presenting unacceptable risk. - Require evidence of compliance from any team or vendor. - Escalate unresolved matters directly to **[the Board / Audit & Risk]**. > **The halt right matters** > A programme that cannot stop anything is advisory. If the authority to > halt is not granted here, expect controls to be optional in practice. ### 5. Sponsorship & accountability | Role | Holder | Accountability | |---|---|---| | Executive Sponsor | [name] | Board-level accountability; resourcing. | | Programme Owner | [name] | Delivery of the programme. | | Committee Chair | [name] | Decision-making forum. | ### 6. Objectives & measures | Objective | Measure | Target | By | |---|---|---|---| | Complete AI inventory | % systems registered | 100% | [date] | | Risk classification | % classified | 100% | [date] | | Policy adoption | % staff attested | 90% | [date] | | Board visibility | Reports delivered | {{default:board-reports-per-year}} per year | Ongoing | ### 7. Resourcing **[Named roles and FTE commitment. A charter without resourcing is a statement of intent, not a mandate.]** ### 8. Review & approval | Version | Date | Approved by | |---|---|---| | 1.0 | [date] | [board / exco] | --- ## Adaptation notes - **Small organisations:** One page is enough. The essential clauses are authority (section 4) and named sponsorship (section 5) — the rest can be inherited from the frameworks. - **Group structures:** State clearly whether the charter binds subsidiaries directly or requires local adoption. Ambiguity here surfaces during the first cross-entity incident, at the worst possible moment. - **Public sector:** Reference the statutory basis for the mandate and any duties owed to citizens; add a public transparency objective to section 6. --- *From the [Open Data & AI Governance Kit](https://lsdeva.github.io/governance-kit/). Licensed [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/) — free to use, adapt, and share with attribution.* ***Not legal advice.** Adapt to your jurisdiction, sector, and risk appetite, and have qualified counsel review anything material.*