Three Lines of Defence in AI Governance
Tags: Frameworks
TL;DR
- Governance is organised into 3 lines: Project Team (builds and mitigates), PSC/PAT (sets acceptance criteria, independently reviews, approves), and IT Board/CIO (reviews high-risk AI; may be advised by an Ethical AI Committee).
- High‑risk AI gets additional senior scrutiny and ongoing monitoring.
Why it matters for HK marketers: Knowing who signs off—and when—helps you plan timelines and evidence packs for AI-powered campaigns.
Roles and responsibilities
- First line — Project Team:
- Develops AI applications, documents the AI Assessment, and executes risk mitigations.
- Defines acceptance criteria, performs independent review, provides final approval before delivery, ensures Ethical AI Principles are addressed via the assessment.
- Third line — IT Board/CIO (with optional Ethical AI Committee):
- Reviews, advises on, and monitors high-risk AI applications; Ethical AI Committee can include external advisors.
Approval flow highlights
- Independent challenge is built-in before go-live.
- High-risk classification triggers senior oversight; ongoing monitoring is expected.
3 lines of defence defined.
High-risk AI requires senior review and ongoing monitoring.
So what for marketers
Map your AI projects to the governance lines early—schedule PSC/PAT reviews and prep explainability, bias, and privacy evidence to avoid launch delays.
← Back to Knowledge Base