Tier 2: Evidence-grade controls
AI-related data governance and lineage
Control of data sources, quality, permissions, and traceability, so AI outputs can be tied back to the data used to train and operate the system.
Board-defensible evidence
- Data lineage maps showing source systems, transformations, feature engineering steps, and where data is stored and accessed across training, testing, and production environments.
- Data access and consent evidence showing legal basis or permissioning for data use, including purpose limitation, retention rules, and approvals for sensitive data categories.
- Data quality controls showing validation checks, missingness thresholds, label quality reviews, and documented decisions when data quality is insufficient but the model proceeds with mitigations.
- Dataset versioning and provenance evidence showing when datasets changed, who approved changes, and which model versions were trained on which dataset versions.
- Third-party data governance artifacts (if applicable) showing vendor data sourcing assurances, contractual restrictions, audit rights, and compliance attestations tied to the data supply chain.
Why this matters
When outputs are challenged, lineage is how you prove what data was used, whether it was permitted, and whether it was fit for purpose.
How ready is your board on evidence-grade controls?
Twelve questions, scored across all four tiers, with your gaps named — or take the whole framework into your next meeting.