AI Leadership
D3 · Governance and Risk
An AI governance operating model, a risk taxonomy, data handling and residency, vendor and model risk, the enterprise controls in ChatGPT Business and Enterprise, and the difference between governance that enables and governance that is theatre.
This domain carries 18% of the mock — roughly 9 of 50 items. It tests whether you can build governance that enables safe adoption rather than governance that merely performs caution. Leaders who get this wrong either block everything (and drive shadow AI) or wave everything through (and inherit an incident). The material: a governance operating model with clear ownership and decision rights, a risk taxonomy you can apply to any use case, data-handling and residency rules, vendor and model risk, and the concrete enterprise controls available in ChatGPT Business and Enterprise. This connects directly to the credential landscape and to adoption: governance that is all friction is the surest way to kill adoption.
What you need to know
Governance is an operating model, not a document. It names who owns AI risk, who decides what, which policies apply, where use cases are reviewed, and how exceptions are granted. A usable risk taxonomy spans accuracy, privacy, security, IP, regulatory, reputational and workforce risk — each with a different owner and control. Data handling turns on classification and residency: what data may enter a tool, where it is processed, and whether it trains a model. The enterprise editions of ChatGPT ship real controls — SSO, SCIM, EKM, RBAC, compliance logs, data residency in ten regions, and no training on business data by default — that let a leader say “yes, safely” instead of “no”. The recurring judgement is telling enabling governance from governance theatre.
Learning objectives
By the end of this page you should be able to:
- Design an AI governance operating model with ownership, decision rights, policy, review boards and exception paths.
- Apply a seven-category risk taxonomy to classify and control any AI use case.
- Decide data-handling and residency rules from data classification, not habit.
- Assess vendor and model risk, including data-training and residency posture.
- Map enterprise controls in ChatGPT Business/Enterprise to specific governance requirements.
- Distinguish governance that enables safe adoption from governance that is theatre.
3.1 The governance operating model
Governance fails when nobody can say who decides. A working model answers five questions explicitly.
| Element | Question it answers | Typical answer |
|---|---|---|
| Ownership | Who is accountable for AI risk overall? | A named executive sponsor (often CIO/CDO/CISO jointly) |
| Decision rights | Who approves a use case at each risk tier? | Low: team lead; medium: function + risk; high: review board |
| Policy | What rules bind everyone? | Acceptable-use, data-classification, human-review policy |
| Review board | Where are non-standard cases judged? | A small cross-functional AI review board, meeting on a cadence |
| Exception path | How do you say yes to a hard case safely? | Time-boxed, conditions attached, logged, revisited |
AI GOVERNANCE OPERATING MODEL ┌──────────────────────────────────────────────────┐ │ Executive sponsor (owns AI risk) │ └───────────────┬──────────────────────────────────┘ │ ┌───────────┴───────────┐ ▼ ▼ Policy & standards AI review board (acceptable use, (cross-functional: data classes, risk, legal, security, human review) data, a business voice) │ │ ▼ ▼ Tiered decision rights Exception path low → team (time-boxed, conditioned, medium → function+risk logged, reviewed) high → review boardThe tiering is the load-bearing idea: most decisions never reach the board. A governance model that routes every request to a committee is theatre — it produces delay, not safety.
Assessment signal
Stems about “who approves”, “escalation”, “a committee reviews every request”, “an exception” are testing the operating model. Correct answers tier decisions and reserve the board for genuine risk; distractors centralise everything or leave approval undefined.
3.2 The risk taxonomy
You cannot control a risk you cannot name. Seven categories cover almost every AI use case, and each has a distinct owner and control.
| Risk | What it is | Primary control | Owner |
|---|---|---|---|
| Accuracy | Wrong or fabricated output relied upon | Human review proportional to stakes | Business owner |
| Privacy | Personal data mishandled | Data classification, minimisation, residency | DPO / privacy |
| Security | Prompt injection, data exfiltration, access | RBAC, SSO, monitoring, secure connectors | CISO |
| IP | Confidential input leaks; output IP unclear | No-training terms, input rules, contract review | Legal |
| Regulatory | Breach of sector or data law | Legal review, residency, audit logs | Compliance |
| Reputational | Public harm, biased or off-brand output | Review gates on external content, brand rules | Comms / brand |
| Workforce | Fear, deskilling, unfair impact | Transparent change plan, enablement | HR (D5) |
The leadership point: these risks do not share an owner, so a single “AI risk lead” cannot carry them all. Governance assigns each category to the function that already owns that risk class.
3.3 Data handling and residency
Almost every AI incident traces to data — the wrong data entering a tool, or leaving a jurisdiction it should not. Two decisions govern this: classification (what may enter) and residency (where it is processed and stored).
Data class May it enter an AI tool? ───────────────────────────────────────────── Public Yes Internal Yes, in a governed workspace Confidential Only in a governed workspace with no-training terms + access control Regulated / PII Only with a DPIA/legal sign-off, residency confirmed, minimised Secret / restricted No, unless explicitly clearedResidency asks where data is processed and stored. ChatGPT Enterprise offers data residency in ten regions — US, EU, UK, Japan, Canada, Korea, Singapore, India, Australia and the UAE — which lets a global firm keep regulated data in-region. By contrast, some newer developer surfaces (for example the managed Agents API) are US data residency only with no zero-data-retention at launch — a fact a leader must weigh before routing regulated data through them.
The default that changes the whole risk conversation: in ChatGPT Business and Enterprise, business data is not used to train OpenAI’s models by default. That single fact is often the difference between “no” and “yes, in the governed workspace” for confidential data.
3.4 Vendor and model risk
Choosing a provider is a governance decision, not just a procurement one. Assess vendors on the controls that matter to your risk taxonomy.
| Vendor question | Why it matters |
|---|---|
| Is our data used to train models? | Default no-training on business data protects IP and privacy |
| Where is data processed and stored? | Residency drives regulatory compliance |
| What identity and access controls exist? | SSO, SCIM, RBAC gate who can do what |
| What logging and audit is available? | Compliance API logs and audit events enable oversight |
| What certifications are held? | SOC 2 Type 2, ISO 27001/27017/27018/27701 signal maturity |
| How is encryption handled? | TLS 1.2 in transit, AES-256 at rest; EKM for key control |
Model risk adds a second layer: models change, deprecate and behave differently. A governed programme pins which models are approved for which risk tier and reviews changes — not every new model is automatically fit for a regulated workflow.
3.5 Enterprise controls in ChatGPT Business/Enterprise
A leader must know which control answers which requirement, because “we can’t use AI, it’s not secure” is usually false — the controls exist, they simply have to be turned on.
| Control | What it does | Governance need it meets |
|---|---|---|
| SAML SSO | Central sign-in via your IdP | Access control, offboarding |
| SCIM | Automated user provisioning/deprovisioning | Joiner-mover-leaver hygiene |
| EKM | Enterprise-managed encryption keys | Key control for regulated data |
| RBAC | Role-based permissions | Least-privilege, separation of duties |
| Compliance API logs / audit events | Exportable activity records | Oversight, investigations, audit |
| Data residency (10 regions) | Choose processing/storage region | Regulatory and sovereignty needs |
| No training on business data (default) | Inputs not used to train models | IP and privacy protection |
| Domain verification, IP allowlisting | Control access surface | Reduce account and network risk |
| SOC 2 Type 2, ISO 27001/17/18/27701 | Independent assurance | Vendor risk sign-off |
Note the split: SSO, SCIM, EKM, RBAC and the ten-region residency and default no-training posture are enterprise-grade capabilities; a leader mapping a requirement to a plan should confirm the specific edition rather than assume every control is in every tier.
Assessment signal
Stems naming a requirement — “we must deprovision leavers automatically”, “keep EU data in the EU”, “prove who did what”, “control our own keys” — are asking you to name the control: SCIM, data residency, compliance logs, EKM respectively. Distractors reach for a blanket ban or a custom build.
3.6 Governance that enables vs governance that is theatre
The most examined leadership judgement in this domain is the difference between control that reduces risk and ritual that only signals caution.
| Enabling governance | Governance theatre |
|---|---|
| Tiered decision rights; most cases decided fast | Every request goes to a monthly committee |
| Clear acceptable-use policy people can apply | A 90-page policy nobody reads |
| Approved tool list with a safe default | Blanket ban that drives shadow AI |
| Exception path that says “yes, with conditions” | Exceptions impossible, so people route around |
| Controls turned on (SSO, RBAC, logs) | A signed policy but no technical control |
| Review focused on genuinely risky cases | Sign-off ritual on trivial ones |
Theatre feels safe and is dangerous: it delays value and increases risk, because a blocked workforce moves to ungoverned personal tools. Enabling governance channels demand into the governed workspace where the controls actually apply.
Decision framework
The G-U-A-R-D use-case review
Route each proposed use case through five checks. It replaces “does the committee like it?” with a repeatable test that most cases pass without a committee at all.
| Letter | Check | Outcome |
|---|---|---|
| Grade the risk | Which taxonomy categories apply, at what tier? | Sets the decision right |
| Use-of-data | What data class enters; is residency and no-training satisfied? | Blocks unlawful inputs |
| Accountable human | Who reviews output and owns the decision? | Ensures human-in-the-loop where needed |
| Rights & access | Are SSO/RBAC/SCIM correctly scoped? | Least-privilege enforced |
| Document & revisit | Is the decision logged with a review date? | Auditability, not permanence |
Low-tier cases clear G-U-A-R-D in minutes at the team level; only high-tier cases reach the review board.
Common mistakes
| Mistake | Why it happens | What to do instead |
|---|---|---|
| Routing every request to a committee | Feels thorough and safe | Tier decision rights; reserve the board for high risk |
| Blanket ban on AI tools | Fear of the unknown | Provide a governed default; ban drives shadow AI |
| Treating governance as a document | A policy is easy to produce | Turn on technical controls; policy without control is theatre |
| Assuming enterprise tools are insecure | Old intuition about SaaS | Map requirements to real controls (SSO, EKM, residency, no-training) |
| One “AI risk owner” for all risk | Simplicity in an org chart | Assign each taxonomy category to its natural owner |
| Ignoring data residency | It is invisible until audited | Confirm processing region against the data class |
| No exception path | Simplicity, or caution | Provide a time-boxed, conditioned, logged exception route |
| Approving a model for all tiers because it is newest | Newer feels better | Pin approved models per risk tier; review model changes |
| Confidential data blocked reflexively | “AI trains on everything” myth | Default no-training in governed workspaces enables safe use |
Scenario challenge
Scenario. You chair the AI review board at a European bank. Adoption is stalling: staff complain that every AI request — even summarising a public regulator circular — must wait for the monthly board, and three teams have quietly started using personal ChatGPT accounts on their phones to get work done. Meanwhile the head of wealth management wants to pilot an assistant that reads client portfolio data (regulated, EU-resident) to draft review notes, and legal is nervous about “AI training on client data”. The CISO asks you to fix both the bottleneck and the shadow-AI problem.
Expert reasoning trace.
-
Diagnose the bottleneck as theatre. Sending a public-circular summary to a monthly board is pure ritual: it adds delay and, worse, it causes the shadow-AI risk by making the governed path unusable. The fix is tiered decision rights — public and internal-class, low-stakes use cases decided at team level under a clear policy, with only high-risk cases reaching the board.
-
Address shadow AI by making the governed path faster than the ungoverned one. Personal-account use is the real incident risk: no logging, no residency control, no no-training guarantee. I provide a governed ChatGPT Business/Enterprise workspace with SSO and SCIM (so access follows employment) and communicate that it is both allowed and faster than waiting for the board. Enabling governance channels the demand back inside the controls.
-
Apply G-U-A-R-D to the wealth-management pilot. Grade: privacy + regulatory + reputational, high tier. Use-of-data: regulated client PII, so residency must be EU (ChatGPT Enterprise’s EU region) and the no-training-on-business-data default must be confirmed in writing — which directly answers legal’s fear. Accountable human: an adviser reviews and owns every drafted note. Rights: RBAC limits the assistant to the advisers who own those clients. Document: logged via the Compliance API, with a review date.
-
Answer legal precisely, not vaguely. “AI trains on our client data” is false for the governed workspace by default; I cite the no-training default and EU residency rather than debating in the abstract. The pilot proceeds as a high-tier, conditioned exception — human review, EU residency, RBAC, logging — not a blanket yes and not a reflexive no.
-
Close the loop. The board’s new job is high-risk cases and policy, not rubber-stamping trivia. Adoption recovers because the governed path is now the fast path.
Board-ready outcome: tiered decision rights end the bottleneck; a governed workspace with SSO/SCIM/logging pulls shadow AI back inside the controls; the wealth pilot proceeds under EU residency, default no-training, RBAC and human review as a documented high-tier exception; legal’s concern is answered with the specific control, not a slogan.
Assessment traps
| Trap | Why it is tempting | The discriminator |
|---|---|---|
| Send every AI request to the review board | It looks maximally careful | Tiering is safer and faster; universal review is theatre that breeds shadow AI |
| Ban AI outright until “it’s proven safe” | Feels like the cautious default | Governed workspace + controls is the safe path; bans push data to personal tools |
| Refuse confidential data because “AI trains on it” | A common, outdated belief | Business data is not used for training by default in Business/Enterprise |
| Treat a signed 90-page policy as governance | A document is tangible proof | Governance requires technical controls turned on, not just prose |
| Give one person all AI risk to own | Clean on an org chart | Each risk category has its natural owner (DPO, CISO, legal, comms, HR) |
| Route EU regulated data through a US-only surface | It is the newest capability | Residency must match the data class; confirm the region before routing |
Practice questions
Each item states how many responses to select. Commit before revealing.
Q1 · Staff complain that summarising a public document requires monthly-board approval, and some have switched to personal ChatGPT accounts. What is the ROOT problem? (Select one)
A. Staff are simply undisciplined. B. Governance theatre: undifferentiated review creates delay that drives shadow AI. C. The model is not capable enough. D. The policy document is too short.
Answer: B. Routing low-risk work to a committee is theatre that both delays value and pushes users to ungoverned tools. Blaming staff (A) ignores the design fault; model capability (C) and policy length (D) are unrelated to the bottleneck.
Q2 · A firm must automatically remove AI-tool access when an employee leaves. Which enterprise control MOST directly meets this? (Select one)
A. EKM B. SCIM C. Data residency D. Prompt caching
Answer: B. SCIM automates provisioning and deprovisioning so access follows employment. EKM (A) controls encryption keys, residency (C) controls where data lives, and prompt caching (D) is a performance feature.
Q3 · Legal worries that client data entered into ChatGPT will train OpenAI's models. In a governed Business/Enterprise workspace, what is accurate? (Select one)
A. All input trains the model; the concern is valid. B. Business data is not used to train models by default, so the concern is addressed by the default posture plus contract confirmation. C. Training can only be stopped by building a private model. D. Only public data is ever safe to enter.
Answer: B. The default no-training-on-business-data posture directly answers the concern; confirm it in the terms. The blanket-training claim (A) is false; a private model (C) is unnecessary; restricting to public data only (D) is overly conservative.
Q4 · Which categories belong in a working AI risk taxonomy? (Select two)
A. Accuracy of relied-upon output. B. Regulatory breach exposure. C. The colour of the product UI. D. The number of prompt tokens used per day. E. The vendor’s marketing budget.
Answer: A and B. Accuracy and regulatory exposure are core risk categories with distinct owners and controls. UI colour (C), token counts (D) and vendor marketing (E) are not governance risks.
Q5 · A global firm must keep EU customers' regulated data processed within the EU. Which capability makes this possible? (Select one)
A. Faster model reasoning. B. ChatGPT Enterprise data residency, which supports processing in specific regions including the EU. C. A larger context window. D. Prompt caching.
Answer: B. Data residency lets a firm pin processing to a region such as the EU. Reasoning speed (A), context window (C) and caching (D) do not affect where data is processed.
Q6 · A single 'AI risk lead' is asked to own accuracy, privacy, security, IP, regulatory, reputational and workforce risk alone. What is the FLAW? (Select one)
A. None; one owner is simplest. B. These risks have different natural owners (DPO, CISO, legal, comms, HR); concentrating them creates gaps. C. There should be no owner at all. D. Only security matters.
Answer: B. Each risk category maps to the function that already owns that class; concentrating them in one person guarantees blind spots. A single owner (A) is not simplest in practice; no owner (C) is worse; and security alone (D) ignores the rest.
Q7 · A team wants to pilot an assistant on regulated client PII. Applying G-U-A-R-D, which TWO conditions are essential before approval? (Select two)
A. Confirm EU/in-region residency and the default no-training posture for the data class. B. Ensure a named human reviews and owns each output. C. Choose the newest available model regardless of tier. D. Grant every employee access to speed adoption. E. Skip logging to reduce overhead.
Answer: A and B. Regulated PII demands correct residency/no-training and a human-in-the-loop owner. Picking the newest model (C) ignores tiering; universal access (D) violates least-privilege; skipping logging (E) removes auditability.
Q8 · Which is an example of governance that ENABLES rather than theatre? (Select one)
A. A blanket ban on all AI tools until further notice. B. Tiered decision rights with a fast path for low-risk cases and a board only for high-risk ones. C. Sending every request to a monthly committee. D. A 90-page policy with no technical controls enabled.
Answer: B. Tiering decides most cases quickly and reserves scrutiny for genuine risk. A ban (A), universal committee review (C) and an unenforced policy (D) are all forms of theatre.
Q9 · A regulator asks the bank to prove who accessed an AI assistant and what they did over the past year. Which control provides this? (Select one)
A. Compliance API logs and audit events. B. A faster model. C. A larger team. D. Prompt caching.
Answer: A. Exportable compliance logs and audit events provide the who-did-what record a regulator needs. Model speed (B), team size (C) and caching (D) are irrelevant to auditability.
Q10 · A leader must decide whether confidential (not regulated) data may enter a governed AI workspace. What is the MOST appropriate rule? (Select one)
A. Never; confidential data must stay out of all AI tools. B. Yes, in a governed workspace with no-training terms and access control, per the classification gate. C. Yes, in any tool including personal accounts. D. Only after building a private model.
Answer: B. Confidential data is permissible in a governed workspace with no-training terms and access controls. A total ban (A) is over-conservative; personal accounts (C) lack controls; a private model (D) is unnecessary.
Q11 · A team proposes routing EU regulated data through a newly launched managed agent surface that is US-only with no zero-data-retention. What is the correct governance call? (Select one)
A. Approve it; newer surfaces are always better. B. Decline for that data class until an in-region, compliant path exists; the residency requirement is not met. C. Approve if the team promises to be careful. D. Approve and add a note to the risk register.
Answer: B. Residency must match the data class; a US-only, no-ZDR surface cannot carry EU regulated data. Novelty (A), promises (C) and a mere register note (D) do not satisfy the regulatory requirement.
Q12 · What is the PURPOSE of a time-boxed, conditioned exception path in a governance model? (Select one)
A. To make exceptions impossible so nobody asks. B. To let leaders say ‘yes, with conditions and a review date’ to hard cases instead of forcing workarounds. C. To route all decisions to the executive sponsor. D. To avoid logging difficult decisions.
Answer: B. A good exception path enables safe yeses on hard cases, conditioned and revisited. Making exceptions impossible (A) drives workarounds; centralising all decisions (C) is a bottleneck; avoiding logging (D) destroys auditability.
Q13 · A CISO wants the organisation to control its own encryption keys for AI-processed data. Which control addresses this? (Select one)
A. RBAC B. EKM (enterprise key management) C. SSO D. Domain verification
Answer: B. EKM lets the enterprise manage its own encryption keys. RBAC (A) governs role permissions, SSO (C) governs sign-in, and domain verification (D) controls the account surface — none of which is key management.
Q14 · During a use-case review, which factors set the DECISION RIGHT (who approves)? (Select two)
A. The risk tier derived from the applicable taxonomy categories. B. The data class that will enter the tool. C. How enthusiastic the requesting team is. D. Which model version is newest. E. The size of the requesting team’s budget.
Answer: A and B. Risk tier and data class determine the decision right and the review path. Team enthusiasm (C), model recency (D) and budget size (E) do not govern who must approve.
Key takeaways
- Governance is an operating model — ownership, tiered decision rights, policy, a review board and an exception path — not a document.
- Use a seven-category risk taxonomy (accuracy, privacy, security, IP, regulatory, reputational, workforce), each assigned to its natural owner.
- Data handling turns on classification and residency; ChatGPT Enterprise offers residency in ten regions and does not train on business data by default.
- Assess vendor and model risk on training posture, residency, access controls, logging and certifications; pin approved models per risk tier.
- Know the enterprise controls — SSO, SCIM, EKM, RBAC, compliance logs, residency — and map each to the requirement it meets.
- Enabling governance decides most cases fast and channels demand into the governed workspace; theatre blocks everything and breeds shadow AI.
- Run G-U-A-R-D on each use case: grade risk, check use-of-data, name the accountable human, scope rights, document and revisit.
Last updated Sep 18, 2026