Skip to content

Governance Charter

Draft

Draft

This page is usable but has not had a full review pass. Corrections and improvements are welcome — see Contributing.

Purpose. A short, board-approved mandate that establishes the governance programme: why it exists, what authority it has, what it covers, and how success is measured. It is what you point to when someone asks "who says so?".

When to use it. Write it at the start of the programme and have it formally approved. Refresh when scope, sponsorship, or mandate changes.

How to use it. Keep it to two pages. The charter grants authority; it does not describe process. If you find yourself writing procedure, that belongs in the frameworks or the committee terms of reference instead.

Closes assessment gaps

This template addresses Q01, Q04, Q25 in the readiness assessment.


The template

1. Mandate

The [Data & AI Governance Programme] is established by [the Board / Executive Committee] on [date] to ensure that [Organisation] manages its data and AI assets lawfully, safely, and in line with its stated risk appetite.

2. Why this exists

[Two or three sentences: the specific driver. Regulatory exposure, a board concern, an incident, an AI adoption push. Be concrete — a charter that could belong to any organisation will be ignored by this one.]

3. Scope

In scope: all data held or processed by the organisation; all AI systems built, bought, or embedded; all business units and geographies [amend].

Out of scope: [be explicit — e.g. security operations, covered by the existing security programme].

4. Authority

The programme, through its committee, is authorised to:

  • Set mandatory standards for data and AI within scope.
  • Require registration and classification of any AI system.
  • Halt or require remediation of a system presenting unacceptable risk.
  • Require evidence of compliance from any team or vendor.
  • Escalate unresolved matters directly to [the Board / Audit & Risk].

The halt right matters

A programme that cannot stop anything is advisory. If the authority to halt is not granted here, expect controls to be optional in practice.

5. Sponsorship & accountability

Role Holder Accountability
Executive Sponsor [name] Board-level accountability; resourcing.
Programme Owner [name] Delivery of the programme.
Committee Chair [name] Decision-making forum.

6. Objectives & measures

Objective Measure Target By
Complete AI inventory % systems registered 100% [date]
Risk classification % classified 100% [date]
Policy adoption % staff attested 90% [date]
Board visibility Reports delivered FourUnless: Add an extraordinary report after any S1 incident or regulatory contact, rather than waiting for the next scheduled one. per year Ongoing

7. Resourcing

[Named roles and FTE commitment. A charter without resourcing is a statement of intent, not a mandate.]

8. Review & approval

Version Date Approved by
1.0 [date] [board / exco]

Adaptation notes

  • Small organisations: One page is enough. The essential clauses are authority (section 4) and named sponsorship (section 5) — the rest can be inherited from the frameworks.
  • Group structures: State clearly whether the charter binds subsidiaries directly or requires local adoption. Ambiguity here surfaces during the first cross-entity incident, at the worst possible moment.
  • Public sector: Reference the statutory basis for the mandate and any duties owed to citizens; add a public transparency objective to section 6.

Not legal advice

These templates are a head start, not a substitute for professional judgement. Adapt them to your jurisdiction, sector, and risk appetite, and have qualified counsel review anything material before you rely on it.