Unit 12 / 12

AI Governance Framework: Roles, Approval, Audit and Incident Response

Gains:

  • Defining governance roles with a RACI matrix
  • Establish a balanced approval process and regular audit program
  • Implement AI and data breach incident response plan with 72 hour rule

From the first unit to this point, we wrote the policy, learned the legislation, and evaluated the risks. Now it's time to plug all of this into a working system. No matter how well a policy is written, if there are no roles, approval flows, auditing and incident response behind it, it remains on the shelf as a document. In this closing unit, we combine the four mechanisms that keep AI governance alive—roles (RACI), approval process, regular audit, and incident response—and complete the framework.

Clarifying roles: the RACI matrix

The first rule of governance: every task must have an owner. The classic tool to clarify this is the RACI matrix. RACI comes from the initials of four roles:

  • R (Responsible / Doer): The one who actually carries out the work.
  • A (Accountable): There should be only one person who is ultimately responsible.
  • C (Consulted): The one whose opinion is taken.
  • I (Informed): Informed.

Quest

Made by (R)

Accountable (A)

Consulted (C)

Informed (I)

Writing the policy

AI officer

compliance manager

Legal, IT, HR

senior management

New vehicle approval

IT/security

compliance manager

law

business unit

DPIA execution

Data protection officer

compliance manager

Related team

senior management

breach response

security team

senior management

law, communication

entire institution

Audit

internal audit

compliance manager

Units

senior management

Tip: Have only one "A" (Accountable) per line. Two are ultimately responsible, zero is responsible; This is where the phrase "I thought you were looking" at a time of crisis comes from. Fixing responsibility on a single role is the rule of thumb of governance.

Balanced approval process

A new AI tool or its use requires an approval process. Two traps are avoided: too loose (everything is free, shadow AI) and too rigid (everything awaits approval for months, no one bothers). The trade-off is gradual approval based on risk:

Risk level

example

Approval path

low

Text draft with open data

No approval required, free within policy

medium

Analysis with in-house data

Unit manager + approved vehicle requirement

high

Personal/private data, automatic decision

Compliance + legal approval + DPIA

Releasing low-risk uses allows teams to take ownership of the process; Putting high-risk ones under tight control manages real risk. Thus, the process is both fast and safe.

Regular inspection

Governance is a living system; Without regular supervision it dies. The audit checks: are the vehicles used still on the approved list, are there signs of shadow AI, are retention periods applied, are DPIAs up to date, have incidents been recorded. Audit frequency is determined by risk (e.g. quarterly for high-risk systems, every six months for general).

Attention: Auditing is not a tool to "blame someone", but a tool to "improve the system". A punishment-focused audit culture pushes employees to hide problems and fosters shadow AI. The goal is to see and fix problems early.

Incident response and the 72 hour rule

No matter how well managed, one day an incident will happen: data leak, wrong AI decision, confidential data getting into the wrong tool. An incident response plan prescribes what to do:

  1. Detection and containment: Recognize the incident, stop its spread (e.g. cut off access).
  2. Evaluation: Which data, how many people, how much were affected?
  3. Notification: In case of personal data breach, notify the relevant authority (KVKK Board) and relevant persons when necessary. GDPR requires notification to the authority within 72 hours of learning of the breach; KVKK also expects notification "as soon as possible".
  4. Correction and learning: Fix the root cause, take action to prevent a similar one, document the incident.
Attention: The 72-hour notice period starts from the moment you learn about the incident; The approach of "let's solve it internally first, then we will let you know" will miss the deadline. Having an incident response plan and communication chain ready in advance saves time during a crisis.

three mini cases

Case 1 — Unclaimed task. A company has an AI policy, but it is not clear "who updates the approved tool list". The list is not updated for 8 months, teams start using tools that are not on the list. If a RACI matrix pinned this task to a role, the gap would not occur.

Case 2 — 72 hours missed. An employee enters a mystery shopper list into the wrong tool. The team tries to resolve this internally and informs the law three days later. By the way, the notification period has passed. A prepared incident response plan and a clear communication chain would have moved the incident to the right channel within the first hour.

Case 3 — Shadow AI caught by audit. An organization detects three unapproved AI tools in network traffic during a routine semi-annual audit. Instead of punishment, he talks to the teams, understands why they need these tools, evaluates the two and adds them to the approved list. Audit both closes the risk and makes the real need visible.

Copiable templates

TEMPLATE 1 — RACI matrix outline: "Draft the RACI matrix for our organization's AI governance. Tasks: policy writing, tool approval, DPIA, breach response, audit, training. Roles: AI lead, compliance manager, legal, IT, HR, senior management. Only one 'A' in each role."

TEMPLATE 2 — Tiered approval flow: "Design a tiered AI approval process according to risk: separate approval paths for low/medium/high risk. Write example usage, approver role and required document (DPIA etc.) for each level. Make the process both fast and secure."

TEMPLATE 3 — Audit checklist: "Prepare checklist for six-month AI governance audit: approved tool compliance, shadow AI indications, retention periods, DPIAcurrency, event logs, training completion rate. Add 'how to check' method to each item."

TEMPLATE 4 — Incident response flow card: "Write a one-page incident response flow card for an AI/data breach: step by step (detection, containment, assessment, notification, remediation), responsible role and contact information at each step, 72-hour notification alert. Keep it simple enough to sit on the table in a crisis."

Weak prompt / Strong prompt

WEAK: “What should we do for AI governance?”-> The model gives a general list; roles, approval paths and incident plan would not be institution-specific and applicable. STRONG: "We are an organization of 60 people. To make AI governance work: (1) Produce a 5-task RACI matrix, (2) tiered approval flow for low/medium/high risk, (3) a one-page incident response card with a 72-hour rule. Let there be a single 'A' in each task; simple and applicable."-> The model produces organization-specific, immediately usable governance tools.

Common mistakes

  • Not fixing tasks to the role; Creating a "everyone's job is nobody's business" gap.
  • Defining more than one "A" (ultimate responsible) on a task.
  • Making the approval process either too lax or too strict; not stratifying according to risk.
  • Not carrying out the inspection at all or turning it into a tool of punishment and hiding the problems.
  • Considering the incident response plan after the incident occurs.
  • Missing the 72 hour notice period just to "let's fix it internally first".
  • Establishing governance once and not reviewing it again; However, it is a living system.

In summary

  • Four mechanisms make governance work: roles (RACI), tiered approval, regular auditing, and incident response.
  • In the RACI matrix, each task should have a single ultimate responsible person (A).
  • The approval process should be staged according to risk; low risk free, high risk strict control.
  • Regular auditing keeps governance alive; It is used as a means of healing, not punishment.
  • The incident response plan should be prepared in advance; The 72-hour notification rule should not be forgotten in case of personal data breach.

Application task

Gather a complete governance framework for your organization in a single document. First establish a RACI matrix of at least five tasks; Make sure there is only one "A" in each task. Then design a tiered approval flow for low, medium, and high risk, and add example usage, approving role, and required documentation at each level. Then create a six-month audit checklist. Finally, write a one-page incident response card for an AI/data breach; Include 72-hour notification alert and communication chain. These four pieces will be the document that turns what you have learned throughout the module into a working system.

checklist

  • [ ] I set up the RACI matrix; There is only one "A" in each mission.
  • [ ] I designed a gradual approval flow according to risk.
  • [ ] I have left low-risk uses reasonably liberal.
  • [ ] I prepared a six-month audit checklist.
  • [ ] I positioned auditing as a tool for improvement.
  • [ ] I wrote a one-page incident response card.
  • [ ] I have included the 72 hour notice rule and chain of communication.

Module Exam

1. What is the concept that refers to the unapproved use of AI by employees that occurs when organizations do not have a written AI policy?

  • A) Shadow AI (shadow AI) ✔
  • B) Open weight AI
  • C) Multimodal AI
  • D) Supervised AI

Description: The use of AI without the knowledge and approval of the institution is called 'shadow AI' and poses serious risks such as data leakage.

2. What should be the basic approach of a good corporate AI policy?

  • A) Banning the use of AI as completely as possible
  • B) To be a framework that enables responsible use and provides clarity and trust ✔
  • C) Being a technical document known only to the IT department
  • D) Being as long as possible and written only in legal language

Explanation: A good policy is not a list of prohibitions, but a framework that enables responsible use. Banning it completely will not eliminate use; It just makes it invisible and uncontrolled.

3. What determines data classification, the most critical part of an enterprise AI policy?

  • A) The token price of the AI model
  • B) The company's annual AI budget
  • C) Which type of data can be entered into which AI tool ✔
  • D) Which employee will receive which salary?

Description: Data classification; It stipulates clear rules about which types of open, internal, confidential and proprietary data can and cannot be entered into which AI tool.

4. What does the KVKK's "data minimization" (relevance, limited and proportionate) principle mean in the use of AI?

  • A) Entering only the necessary data into the AI and no more ✔
  • B) Get better results by inputting as much data as possible into the AI
  • C) Storing data indefinitely
  • D) Make sure to transfer all data abroad

Explanation: Data minimization refers to entering into the AI only the data necessary for the purpose and no more. If possible, data is entered anonymised or masked.

5. What is considered in terms of KVKK when entering a text containing personal data into an AI tool that processes the data on the provider's server?

  • A) An ordinary transaction with no legal consequences
  • B) An action that is strictly prohibited under all circumstances
  • C) An operation that is significant only if the data is open
  • D) A transaction and often a transfer; Requires legal basis and assurance ✔

Explanation: This is a 'processing' and often a 'transfer' as the data is processed on the provider's server (often abroad); It requires valid legal basis and appropriate contract/guarantee.

6. What is the basic approach of the EU AI Act?

  • A) Subjecting all AI systems to the same strict rules
  • B) Classify AI systems according to their potential risk and apply rules accordingly ✔
  • C) Completely ban the use of AI across the EU
  • D) Controlling only the token price of the model

Explanation: The EU AI Law does not lump all AI together; It divides systems into four risk classes (prohibited, high, limited, minimal) according to their potential harm and tightens the rules as the risk increases.

7. According to the EU AI Law, which risk class would an AI system that screens out candidates in hiring decisions most likely fall into?

  • A) High risk ✔
  • B) Minimal risk
  • C) Limited risk
  • D) Risk-free

Description: Areas that seriously affect people's lives, such as recruitment, credit and healthcare, generally fall into the 'high risk' category and are subject to strict obligations (recording, human monitoring, data quality).

8. Under the EU AI Law, which category do state-sponsored “social scoring” systems, which score people based on their behavior or characteristics and socially disadvantage them, fall into?

  • A) Limited risk
  • B) High risk
  • C) Prohibited (unacceptable risk) practice ✔
  • D) Minimal risk

Description: Social scoring, subliminal manipulation and certain biometric surveillance practices are among the 'prohibited practices'; These cannot be released even if the risk is reduced, they are completely prohibited.

9. What does Article 22 GDPR protect individuals against?

  • A) Against the high prices of AI tools
  • B) Only against advertising emails
  • C) Against the use of deficit-weighted models
  • D) Against decisions that significantly affect the person and are made only automatically ✔

Explanation: Article 22 of the GDPR protects the individual against decisions that affect the individual to a legal or similarly significant extent and are based solely on automated processing (including AI); It provides the right to request human intervention and object.

10. What is required in terms of KVKK/GDPR when you want to process personal data on the server of an AI provider abroad?

  • A) No additional conditions; data can be transferred freely
  • B) Appropriate assurance (letter of undertaking/standard contract clauses) or a mechanism such as express consent ✔
  • C) Only encryption of the data is sufficient
  • D) Only verbal approval from the employee is sufficient

Explanation: Cross-border transfers, as a rule, require mechanisms that include explicit consent or an adequate commitment to protection (appropriate safeguards such as a letter of undertaking, standard contractual clauses); data cannot be transferred randomly.

11. What determines whether an AI-generated output is copyrightable in most legal systems?

  • A) Level of human creativity and contribution in the content ✔
  • B) Token price of the model used
  • C) Only the length of the output
  • D) Country of origin of the AI tool

Description: In many legal systems, copyright protection requires human creativity. The greater human direction, selection, regulation and unique contribution, the greater the likelihood of preserving the output.

12. What does “human control”, the most critical principle of the AI ​​governance framework, refer to?

  • A) AI makes all decisions alone and automatically
  • B) People stop using AI completely
  • C) AI is a tool; The final say and responsibility in important decisions always belongs to the person ✔
  • D) Use only the most expensive model

Description: The principle of human control emphasizes that AI is a tool and that responsibility always remains with the human. An authorized person has the final say in important decisions; 'AI said so' is not an excuse.

13. When should a Data Protection Impact Assessment (DPIA) usually be carried out?

  • A) After a data breach occurs
  • B) At the design stage, before starting high-risk processing ✔
  • C) Only if the auditor requests it
  • D) Routinely, years after the project

Description: DPIA should be performed at the design stage BEFORE starting an AI processing activity that uses new technology, involves large-scale or systematic monitoring, or poses a high risk to individuals.

14. In accordance with the KVKK's "purpose limitation" and retention principles, what should be done for personal data in the chat history of an AI tool?

  • A) It should be kept forever
  • B) No rules required, it is the provider's problem
  • C) It is reviewed annually only at the request of the manager.
  • D) It should be linked to a storage and destruction policy, and should be deleted or anonymized when the purpose is completed ✔

Explanation: Personal data cannot be kept longer than necessary for the purpose for which it is processed. AI chat histories should also be tied to a retention and destruction policy; When the purpose is no longer there, it should be deleted or anonymized.

15. Which registry is required for data controllers who exceed certain thresholds to register their personal data processing activities in Türkiye?

  • A) VERBIS (Data Controllers Registry Information System) ✔
  • B) MERSIS trade registry
  • C) EU AI Law database
  • D) TAXPAYER REGISTER

Description: VERBIS (Data Controllers Registry Information System) is the official registry where data controllers register their processing inventories; A new AI-based processing activity must be reflected in the inventory and, if necessary, in the VERBIS record.