The Art of Defensible Data and AI Governance for Data Citizens

Key Takeaways

  • Informing Human Judgment: The Ethical Assessment Review (EAR) guides human judgment on AI ethics, avoiding automated conclusions.
  • Proportional Risk Tiering: Review depth scales with human impact – Full Review for extensive projects, Short Form for targeted cases.
  • The 7 Ethical Domains & Evidence Core: Assessments evaluate seven core domains plus verifiable evidence for robust impact evaluation and ethical practices.
  • Mandatory Human Accountability (“Absence as Control”): AI must not create domain answers, assess risk, or produce compliance evidence; human input is essential.
  • The Denominator Principle: Enterprise portfolio governance necessitates tracking assessed use cases to ensure complete compliance reporting.
  • Strict Segregation of Duties: Data stewards propose verdicts, while a governance council ensures impartial review and oversight.
  • Verifiable Evidence Standards: Each piece of evidence must exist, be dated, attributed, owned, and accessible by direct link.
  • Strict Refusal Criteria: Use cases are rejected if they lack human need, clear benefits, harm mitigation, or feedback loops.
  • Defensible Due Diligence: An ethical review demonstrates due diligence and impact evaluation but does not eliminate risk.

Webinar Details

Title: The Art of Defensible Data and AI Governance for Data Citizens
URL: https://youtu.be/lK_CCfc7LyA
Date: 2026-09-10
Presenter: Howard Diesel
Meetup Group: African Data Management Community
Write-up Author: Howard Diesel

How should AI Initiatives be Ethically Evaluated?

AI governance requires standard operating procedures (SOPs) and proportional risk tiering to evaluate whether artificial intelligence initiatives are ethical. Rather than applying uniform scrutiny across all projects, organisations must scale oversight based on potential impacts on human lives.

Unconstrained AI agent deployments introduce severe operational and ethical safety risks, which is why high-impact enterprise use cases demand rigorous ethical assessment reviews, while low-risk productivity pilots remain out of scope.

Key Takeaways

  • Standard operating procedures structure the ethical assessment review of enterprise AI use cases.
  • Proportional risk tiering ensures governance intensity matches a project’s real-world impact.
  • High-risk AI applications demand full ethical reviews, while low-impact internal tools remain out of scope.


FAQ

  • What is the primary purpose of an ethical assessment review instrument? It provides standard operating procedures to inform human judgment on whether an AI use case is ethical.

Figure 1 The Human in the Machine: Standard Operating Procedures of the Ethical Assessment Review (EAR)

What are the Seven Core Ethical Domains?

A defensible AI governance framework evaluates use cases across seven core ethical domains: purpose, collective benefit, human outcomes, authority to control, outcome equity, ethical sustainability, and community impact. An eighth domain mandates verifiable evidence to justify every governance decision.

To maintain strict human accountability, AI software is explicitly prohibited from generating verdicts or writing domain answers. The denominator principle also tracks the total number of enterprise use cases assessed against the entire portfolio to prevent partial reporting.

Key Takeaways

  • Governance frameworks evaluate seven thematic domains plus an eighth element for verifiable evidence.
  • AI tools must never generate verdicts or automate ethical answers.
  • The denominator principle measures assessed use cases against the total enterprise portfolio.

FAQ

  • Can AI assist in deciding if a use case is ethical? No, human stewards must drive the review; AI is strictly barred from suggesting verdicts or answering domain questions.

Figure 2 Ethical Maturity Assessment

What is the Role of the Ethical Assessment Review?

The ethical assessment review functions as an evidence-collection compute framework rather than an automated decision engine. It consolidates compliance evidence into a single location to make audits simpler.

To prevent fraud, data stewards collect evidence for accountable owners, while governance councils independently ratify decisions. If a council misses a review deadline, the case is flagged as “deemed ratified,” requiring governance teams to investigate the oversight.

Key Takeaways

  • The framework acts as a central repository for collecting and structuring governance evidence.
  • Segregation of duties prevents fraud by separating evidence assessors from decision ratifiers.
  • Deemed ratified cases highlight unreviewed deadlines that governance teams must audit.

FAQ

  • How does the framework prevent fraud in ethical reviews? It enforces segregation of duties between stewards who collect evidence and governance councils who ratify results.

Figure 3 The Ethical Assessment Review

Figure 4 The System Equation: The Instrument Informs the Judgement. It never makes it.

Figure 5 Ethical Assessment Review: The Process

Figure 6 The One Rule: The Instrument Informs the Judgement. It never makes it.

What is Defensible AI Governance’s Main Focus?

Defensible AI governance operates across three parallel life cycles: Accountable Owner definition, Review Process execution, and continuous Maturity Assessment. Ethical evaluations must occur before selecting specific technical AI architectures.

Human authorship is mandatory for all documentation, and evidence must be verified for existence, date, personal attribution, ownership, and direct link access. Use cases are refused if they lack human need, mitigation plans, or measurable benefits.

Key Takeaways

  • Governance runs across three continuous cycles covering ownership, review execution, and maturity assessments.
  • Ethical reviews must precede technical AI model selection.
  • All governance evidence requires explicit personal attribution, ownership, and accessible links.

FAQ

  • What causes an AI use case to be refused during review? Use cases are refused if they lack a clear human need, defined mitigation owners, or measurable benefit metrics.

Figure 7 The Shape of It: 3 Lifecycles, not one Process

Figure 8 The Lifecycles, Not One Process

Figure 9 The Architecture of Ethical Oversight

What is the Ethical Review Process by Impact?

A proportionality matrix dictates the depth of ethical review based on domain impact. Projects impacting all seven domains undergo a Full Review, those affecting one or two receive a Short Form Review, and zero-impact cases are categorised as Out of Scope.

Strict segregation of duties prohibits individuals from evaluating their own projects. Non-accountable team members are also blocked from unilaterally lowering a project’s required review depth.

Key Takeaways

  • Review depth scales dynamically into Full, Short Form, or Out of Scope based on domain impact.
  • Segregation rules strictly enforce that no practitioner marks their own homework.
  • Accountable owners alone determine review depth thresholds.

FAQ

  • Can a project lead lower their AI review requirements? No, strict controls prevent unauthorised team members from setting a lighter review depth than assigned.

Figure 10 Evidence: Four Tests, and a Repository Name is not a Location

Figure 11 The Proportionality Matrix

Figure 12 Segregation of Duties: Nobody Marks their own Homework

Can Lack of Feedback Lead to AI Failures?

AI systems lacking structured human feedback loops can fail catastrophically in real-world deployments. For instance, a teacher evaluation model failed because it lacked human feedback mechanisms to explain erroneous retrenchment decisions.

To ensure operational accountability, stewards present evidence while governance councils ratify decisions, attach conditions, or request revisions. Completing an ethical review proves thorough due diligence was conducted, though it cannot guarantee absolute perfection.

Key Takeaways

  • Deployed AI models require structured human feedback channels to prevent automated errors.
  • Governance councils ratify steward decisions, append conditions, or demand revisions.
  • Ethical assessments demonstrate defensible due diligence rather than absolute immunity from risk.

FAQ

  • Does passing an ethical review mean an AI use case is 100% ethical? No, it proves that the organisation thoroughly reviewed risks and recorded defensible evidence.

Figure 13 Domain Evaluation & Hard Refusals

Figure 14 Who Decides: The Reviewer Decides. The Council Ratifies. It does not Decide.

Figure 15 Where this Leaves You

How does “Absence as Control” Impact Governance Processes?

The principle of “absence as control” prevents automated software from generating governance evidence or selecting assessment grades. Evidence validation demands verifiable integrity, including wet-ink signatures where required by legal standards.

Governance councils require structured operational procedures, such as distributing council packs three days prior to meetings and establishing voting quorums. Governance roles must also be assigned to named individuals to maintain personal accountability.

Key Takeaways

  • Automated tools are prohibited from self-generating compliance documentation.
  • Governance council packs must be distributed three days in advance to quorums.
  • Accountability requires assigning governance responsibilities to named individuals.

FAQ

  • What is “absence as control” in AI governance? It is a restriction ensuring automated systems cannot self-generate evidence or grade domain risks.

Figure 16 The Absence is the Control

Figure 17 The Architecture of Integrity: Scaling Ethical Maturity with the EAR Instrument

Figure 18 EAR Instrument Operationalising Ethical Maturity

Figure 19 Ethical Assessment Review: Council Pack

How can Structured Expertise Improve AI Productivity?

Ethical governance principles apply to human decision-making and data products, not just AI algorithms. Organisations must educate executives to distinguish between vendor sales hype and real enterprise capabilities.

Uncritical reliance on commercial AI yields poor outcomes, whereas combining structured human domain expertise with AI tools yields dramatic productivity improvements. For example, enterprise data modelling pilots achieved up to 85% productivity gains when guided by structured business inputs.

Key Takeaways

  • Governance frameworks protect against human bias and data product flaws alongside AI risks.
  • Vendor-recommended use cases should undergo heightened ethical scrutiny.
  • Human-guided AI workflows can boost technical productivity by up to 85%.

FAQ

  • How should organisations handle vendor-promoted AI use cases? Vendor-recommended cases should start at a lower priority and undergo stricter ethical reviews.

How does Product Ethics Integrate with Technology Solutions?

Integrating product ethics ensures technology solutions align with fundamental business values. Technical grounding requires pairing business inputs with domain ontologies to validate AI data structures.

Advanced architectures use specialised role-based agents (such as business analyst, data architect, and compliance agents) under human-in-the-loop sign-off. This supervision mirrors historical enterprise management practices, showing that human oversight still matters as AI capabilities mature.

Key Takeaways

  • Combining top-down business goals with bottom-up domain ontologies ensures technical grounding.
  • Specialised multi-agent architectures require mandatory human-in-the-loop signoffs.
  • AI oversight mirrors traditional enterprise supervision to maintain operational control.

FAQ

  • How do multi-agent validation workflows maintain safety? Specialised agents perform defined validation tasks, but final approvals require human sign-off.

Figure 20 The Paradigm Shift: AI as Assistant, Not Authority

Figure 21 Two Diverging AI Paradigms Leave a Reality Gap

Figure 22 The Golden Rule: The Business Decides. AI Facilitates.

Scroll to Top