Skip to main content
AIRed Team Framework GitHub

Governance

Governance of the AI Red Team function

The governance pattern lives in Playbook chapter 4. This page summarizes the headline points; read the chapter for context.

Where the function sits

Second line of defense (independent assurance over first-line AI engineering). Some programs start in the first line; plan to move to second by the second annual review.

Oversight committee

AI Governance Committee chaired by an executive with risk authority (CISO, CRO, Chief AI Officer). Reviews findings monthly; escalates to the board quarterly.

Escalation paths

  1. Active customer impact → stop testing, notify Sponsor and CISO, hand to IR.
  2. Pre-existing compromise discovered → stop testing, preserve evidence, notify CISO, hand to IR.
  3. Regulator-relevant evidence → notify Legal and Compliance before any external communication.

Reporting

  • Executive summary (1–2 pages) monthly to AI Governance Committee.
  • Audit-ready findings (10–20 pages) per engagement.
  • Technical findings (engineering depth) per engagement.