AI Governance & Ethical Risk Manager (AIGERM)
Make AI governance a live, connected model — from the AI system inventory and its use cases and data, through lifecycle risk and ethical assessment, controls, human oversight, transparency and approval, to monitoring, incidents, complaints, change and controlled retirement.
Its central question:
For each AI system, is its use justified and assessed for ethical risk, are effective controls and human oversight in place, was deployment approved against evidence, is it monitored for adverse outcomes and bias, and is change and retirement governed?
It sits beside the agency's AI/ML platforms, model registry and risk register — it owns the inventory → assessment → controls → approval → monitoring → incident → change → retirement governance lifecycle and the ethical-risk relationships around it.
The governance spine
Entity / AI System → Use Case / Data Source → Risk Assessment → Ethical Risk / Principle Assessment / Legal Compliance → Control / Human Oversight / Transparency → Evidence → Approval Gate → Monitoring Metric / Observation → Adverse-Outcome Incident / Complaint → AI Change → Training → Retirement Plan.
The documents
| Page | What's in it |
|---|---|
| 00 — Overview | What the app is, the domain, the 22 models by area, the demo scenario |
| 01 — Quick Reference | Menu map, every model, key status vocabularies, the demo data set |
| 02 — System Diagram | The AI-governance data model as a diagram (+ interactive viewer) |
| 03 — Phase 2 Scope | The runtime not yet built: lifecycle/approval state machine, risk scoring, monitoring breach detection, reassessment triggers and the DomainEvents outbox |
Status
Phase 1 (built): all 22 models render as an AI-Safe CRUD register with a dashboard, seeded with one coherent QAO-style AI-governance scenario (38 rows) — a public generative assistant (with an adverse-outcome incident and linked complaint, and a model change needing reassessment) and an automated decision model (fairness risk, human oversight, conditional approval, a monitoring breach), plus a retired pilot.
Phase 2 (scoped, not built): the AI-system lifecycle and approval-gate state machine,
risk scoring, monitoring threshold-breach detection, deployment guard rules, reassessment
triggers on material change, retirement-checklist enforcement, and the DomainEvent
outbox — see page 03.
Prototype system; draft. All entities, AI systems, assessments, risks, incidents and decisions in the demo data are fictional; values demonstrate structure only and are not real audit findings.