Governance
Governance of the AI Red Team function
The governance pattern lives in Playbook chapter 4. This page summarizes the headline points; read the chapter for context.
Where the function sits
Second line of defense (independent assurance over first-line AI engineering). Some programs start in the first line; plan to move to second by the second annual review.
Oversight committee
AI Governance Committee chaired by an executive with risk authority (CISO, CRO, Chief AI Officer). Reviews findings monthly; escalates to the board quarterly.
Escalation paths
- Active customer impact → stop testing, notify Sponsor and CISO, hand to IR.
- Pre-existing compromise discovered → stop testing, preserve evidence, notify CISO, hand to IR.
- Regulator-relevant evidence → notify Legal and Compliance before any external communication.
Reporting
- Executive summary (1–2 pages) monthly to AI Governance Committee.
- Audit-ready findings (10–20 pages) per engagement.
- Technical findings (engineering depth) per engagement.