A monthly AI governance review should turn changes into decisions with an owner, a deadline and evidence of follow-through. Start with what needs a decision: a new use, an unresolved incident, an expanded permission or a control that did not work. Leave with a clear operating boundary and a way to check the result.
Ada recommends a monthly review as a practical starting point. The right frequency depends on the work and its risks. NIST’s AI Risk Management Framework calls for ongoing monitoring and periodic review with defined responsibilities in GOVERN 1.5; it does not prescribe a monthly meeting. Guidance: NIST AI RMF.
A systematic review by Birkstedt and colleagues (2023) identified, among the central knowledge gaps, limited understanding of how AI governance is implemented and uncertain effectiveness of ethical principles and regulation. Treat the review routine as something to evaluate through completed actions and operating evidence, rather than assuming that a meeting makes governance effective.
Scheduled review and immediate reassessment
Use the scheduled review to connect evidence across the portfolio. Reassess a material change before the changed operation begins: a different purpose, model, supplier, data source, tool permission or degree of autonomy may invalidate the earlier approval. An incident or failed control can require an immediate pause and escalation. Waiting for the next meeting is not a control.
Illustrative customer-support example
An AI agent may read approved guidance and draft a reply in an authorised workspace. Sending replies or modifying customer records requires separate authority and technical permissions. A drafting approval does not cover either action. This is a fictional example, not a client result.
Five areas to review
1. Active uses and authority
Keep the AI use-case register current. Record the owner who authorises the use, permitted and prohibited actions, tool and data permissions, approval events and the person who can stop operation. In the support example, check that sending and customer-record changes remain unavailable to the drafting agent.
2. Supplier and operating changes
Compare the approved configuration with current settings, integrations and terms. Ask for evidence of changed permissions and revocation behaviour using the vendor worksheet. Assign a responsible technical specialist to validate enforcement; a policy statement cannot establish that a permission is blocked.
Authority
Decision to record: Reading and drafting only
Evidence to inspect: Denied send and record-change attempts
Human review
Decision to record: Named reviewer and approval event
Evidence to inspect: Source comparison, corrections and approval record
Follow-up
Decision to record: Owner, deadline and next decision
Evidence to inspect: Completed action and a dated effectiveness check
3. Incidents, near misses and control effectiveness
Review sampled activity records, reviewer corrections, blocked actions, exceptions and recovery tests. Check whether the control prevented the unwanted action and whether a workaround bypassed it. For the support example, retain a test showing a denied send attempt and evidence that revoked delegated access no longer works.
4. Skills and practical review
Use recurring mistakes to choose exercises in approving, challenging, stopping and escalating proposed actions. Where the EU AI Act applies, Article 4, as replaced by Regulation (EU) 2026/1744 with effect from 27 July 2026, requires providers and deployers to take measures to support the development of AI literacy of their staff and of others dealing with the operation and use of AI systems on their behalf. The measures must take into account those people’s technical knowledge, experience, education and training, the context of use and the people on whom the systems are to be used. Article 4 does not require providers or deployers to guarantee a specific level of AI literacy for any individual, and it does not prescribe a format: this meeting and worksheet are one way to organise such measures. Legislation: consolidated AI Act, Articles 2 and 4.
5. Decisions for leadership
Make the requested decision explicit: continue within scope, change conditions, expand after validation, pause or retire. Name the person with authority, the evidence considered, unresolved questions and the consequences of delay. Escalate decisions that exceed the review group’s mandate.
A simple monthly agenda
- Check previous actions against completion evidence and overdue items.
- Review new uses, status changes and current action boundaries.
- Inspect supplier changes, incidents and control test results.
- Agree role-specific learning and guidance updates.
- Make or escalate the decisions requiring leadership authority.
- Assign actions, deadlines, effectiveness checks and the next review.
Use the monthly-review worksheet to connect each decision to evidence. Test changed boundaries with the pilot worksheet before requesting expanded operation.
Evidence of follow-through
Meeting minutes show what was discussed. They do not establish that actions were completed or controls were effective. For a permission correction, retain the decision, the configuration change, a dated test of the denied action and the responsible reviewer’s conclusion. Set appropriate access and retention for those records.
At the next review, ask whether the change worked and what remains unresolved. That evidence supports a decision to continue or revise the operating scope. Ada’s governance service helps teams establish this routine; bring your current governance question.