Governance Charter¶
Draft
Draft
This page is usable but has not had a full review pass. Corrections and improvements are welcome — see Contributing.
Purpose. A short, board-approved mandate that establishes the governance programme: why it exists, what authority it has, what it covers, and how success is measured. It is what you point to when someone asks "who says so?".
When to use it. Write it at the start of the programme and have it formally approved. Refresh when scope, sponsorship, or mandate changes.
How to use it. Keep it to two pages. The charter grants authority; it does not describe process. If you find yourself writing procedure, that belongs in the frameworks or the committee terms of reference instead.
Closes assessment gaps
This template addresses Q01, Q04, Q25 in the readiness assessment.
The template¶
1. Mandate¶
The [Data & AI Governance Programme] is established by [the Board / Executive Committee] on [date] to ensure that [Organisation] manages its data and AI assets lawfully, safely, and in line with its stated risk appetite.
2. Why this exists¶
[Two or three sentences: the specific driver. Regulatory exposure, a board concern, an incident, an AI adoption push. Be concrete — a charter that could belong to any organisation will be ignored by this one.]
3. Scope¶
In scope: all data held or processed by the organisation; all AI systems built, bought, or embedded; all business units and geographies [amend].
Out of scope: [be explicit — e.g. security operations, covered by the existing security programme].
4. Authority¶
The programme, through its committee, is authorised to:
- Set mandatory standards for data and AI within scope.
- Require registration and classification of any AI system.
- Halt or require remediation of a system presenting unacceptable risk.
- Require evidence of compliance from any team or vendor.
- Escalate unresolved matters directly to [the Board / Audit & Risk].
The halt right matters
A programme that cannot stop anything is advisory. If the authority to halt is not granted here, expect controls to be optional in practice.
5. Sponsorship & accountability¶
| Role | Holder | Accountability |
|---|---|---|
| Executive Sponsor | [name] | Board-level accountability; resourcing. |
| Programme Owner | [name] | Delivery of the programme. |
| Committee Chair | [name] | Decision-making forum. |
6. Objectives & measures¶
| Objective | Measure | Target | By |
|---|---|---|---|
| Complete AI inventory | % systems registered | 100% | [date] |
| Risk classification | % classified | 100% | [date] |
| Policy adoption | % staff attested | 90% | [date] |
| Board visibility | Reports delivered | FourUnless: Add an extraordinary report after any S1 incident or regulatory contact, rather than waiting for the next scheduled one. per year | Ongoing |
7. Resourcing¶
[Named roles and FTE commitment. A charter without resourcing is a statement of intent, not a mandate.]
8. Review & approval¶
| Version | Date | Approved by |
|---|---|---|
| 1.0 | [date] | [board / exco] |
Adaptation notes¶
- Small organisations: One page is enough. The essential clauses are authority (section 4) and named sponsorship (section 5) — the rest can be inherited from the frameworks.
- Group structures: State clearly whether the charter binds subsidiaries directly or requires local adoption. Ambiguity here surfaces during the first cross-entity incident, at the worst possible moment.
- Public sector: Reference the statutory basis for the mandate and any duties owed to citizens; add a public transparency objective to section 6.
Related¶
- Committee Charter (Terms of Reference) — Ready
- Roles & Responsibilities — Ready
- AI Governance Framework — Ready
- Board Pack Template — Ready
Not legal advice
These templates are a head start, not a substitute for professional judgement. Adapt them to your jurisdiction, sector, and risk appetite, and have qualified counsel review anything material before you rely on it.