AI Governance

The framework the platform runs on, and why a shared national marketplace requires it.

AI governance is how the state decides what AI may be built and deployed, under what conditions, and who is answerable for the outcome.

The rules, the roles, and who is answerableGOVERNruns through all threeKnow what it is, and who it reachesMap01Test it against the risks identifiedMeasure02Act on what the tests find, and keep actingManage03GovernThe rules, the roles, and who is answerablePolicy and risk appetiteDecision rights per roleA named owner on every decisionMapKnow what it is, and who it reachesIntended and out-of-scope useData classification and lineageWho the decision affectsMeasureTest it against the risks identifiedAccuracy per group, not just overallBias assessment at publish and retrainDrift, measured continuouslyManageAct on what the tests find, and keep actingGates that block, not warnPurpose-bound accessRetrain, recall, retire

Govern is not the first step. It runs through the other three, which is why governance cannot be a document somebody signs at the end.

What it has to cover

People, process, technology and data. Each fails differently, and a gap in any one is enough.

People

7

roles with distinct decision rights

Who decides, and can they actually decide?

  • Decision rights defined per role, not per person
  • A named officer on every consequential decision
  • Reviewers with the evidence, the time and the authority to say no
  • Publisher qualification before an entity can list anything

Without it: Oversight becomes a signature. Someone approves forty cases an hour and nothing is really reviewed.

Process

27

governed sub-processes

Where in the life of an asset does governance apply?

  • Nine stages, from entity accreditation to retirement
  • Every stage has named sub-processes with a trigger and an artefact
  • Agents run what is checkable, people decide what is consequential
  • Gates that block a release, not warnings that get dismissed

Without it: Governance happens once, at the end, when every expensive choice has already been made.

Technology

9

governance agents in the path

Where do the controls actually live?

  • Controls run in the platform, not in a policy document
  • Sandbox isolated with no egress; compute inside the perimeter
  • Model registry, agent manifests and a declared tool surface
  • An immutable audit record written by the system, not by hand

Without it: The rules exist but nothing enforces them, so compliance depends on who remembered.

Data

100%

catalog assets carry a classification

What is it trained on, who may use it, and where can it go?

  • Classification set at source and inherited by every derived asset
  • PII and sensitive-field scanning on every ingestion
  • Purpose-bound, time-bound entitlements rather than standing access
  • Residency enforced at the perimeter; held-out evaluation sets owned by the platform
  • Lineage from a live endpoint back to the data it learned from

Without it: A model is governed while the dataset underneath it is not, so the restriction is lost the moment it is trained on.

Each pillar fails differently, and a gap in any one is enough. Rules nobody owns are unenforced, owners with no tooling leave no evidence, and all three are undone by a dataset that was never classified.

The marketplace value chain, and the agents inside it

Nine stages. Pick one to see its sub-processes, which agents run them, and where a person still decides.

Publish & certify

New capability enters the catalog only after it clears intake, assurance and Responsible AI gates.

3 unattended3 with a person
  • Intake triage and conformance

    Agent runs itTrust

    Triggered by: An asset is submitted with its manifest

    Intake Triage Agent

    Leaves: Classification, check profile and routing record

  • Automated assurance

    Agent runs itTrust

    Triggered by: Intake routes a conforming submission

    Assurance Agent

    Leaves: Check report: quality, security, bias, malicious content, supply chain

  • Review case assembly

    Agent prepares, person decidesTrust

    Triggered by: A check report is attached to the case

    Certification Case AgentOfficer reads the pack before signing

    Leaves: Reviewer pack with recommendation, basis and precedent

  • Certification decision

    Person decidesTrust

    Triggered by: A reviewer pack reaches the queue

    Certification Case AgentOfficer of the TASMU AI governance authority signs

    Leaves: Certification with scope, conditions and expiry; the AI Asset Passport

  • Pricing and tier approval

    Person decidesValue exchange

    Triggered by: A publisher proposes commercial terms

    No agent in the pathMCIT marketplace operator sets the tier

    Leaves: Approved licence and price on the asset card

  • Versioning

    Agent runs itAssets

    Triggered by: A new version is pushed

    Intake Triage Agent

    Leaves: Version history with digest and consumer notice

27 governed sub-processes across 9 stages, with 9 agents in the path.

What the framework holds a system to

Eight standards. A system is measured against these, not against whether it was delivered on time.

Valid and reliable

It does what it claims, repeatably

Fair

Comparable people get comparable outcomes

Accountable

A person owns the decision

Transparent

Its use is disclosed

Explainable

The basis can be given to the person affected

Privacy-preserving

Lawful basis, purpose limited

Secure and resilient

Holds under attack and under load

Safe

No harm to life, rights or property

Obligations scale with consequence

The tier is decided by what the system affects, not by how it was built. It is what makes human review mandatory.

MINIMAL

No effect on a person's rights or access

Requires: Model card, classification, audit trail

Human review: Not required

LIMITED

Informs a decision about a person, reversibly

Requires: Bias assessment, accuracy per group, bounded access

Human review: At the decision

HIGH

Decides or shapes rights, money, safety or access to a service

Requires: Impact assessment, attestation, explainability, appeal route

Human review: Mandatory, and enforced

How an asset gets certified

A submitted test report can be written rather than run. Each level removes the publisher from the evidence.

Too restrictive

Nothing gets published. Entities build in isolation again and the marketplace has no reason to exist.

The balance we are aiming at

Effort has to match consequence. A summariser over public circulars and a model that refuses a permit cannot carry the same burden of proof, and treating them alike fails in both directions at once.

Too lenient

The first failure is a public one, and the platform loses the trust it needs to be adopted at all.

What is being certified, and how far does it reach

Does the output affect a person's rights, money, safety or access to a service?

Yes. So how far does it reach?

Data classification does not change the level. It changes how the testing is done.

L3

Independently evaluated

They cannot tune to a test they cannot see.

Publisher submits
The model. Not the evaluation set
Platform does
Runs it against a held-out national evaluation set. Accuracy reported per group, not only overall
Human in the loop
A named officer signs the result before listing
Re-certification
6 months, or on each new version

L3 and L4 depend on held-out evaluation sets the platform owns and the publisher has never seen. Building and curating those per domain is a standing obligation of the platform, not of the publisher.

If the data is above Public, at any level

  • Evaluation runs inside the sovereign perimeter. The model does not leave, and neither does the test set
  • A DPIA is completed before the certification result can be signed
  • The data steward of the source approves the evaluation use, separately from the publisher
  • Results are published per group, but the evaluation records stay Restricted

Why a shared marketplace requires it

Four reasons the platform model itself creates, each with what it has already cost elsewhere.

1

A marketplace concentrates risk by design

1 : 12

one flaw, every consumer

The value of a shared platform is that one asset serves many entities. The same property means one flaw reaches every consumer at once, and without lineage the resulting incidents look unrelated.

Twelve entities on separate systems produce twelve independent errors. Twelve entities on one shared model produce the same error twelve times.

2

Assets get used beyond the context they were built for

A model is published by one entity for one population and one decision, then discovered by entities with different populations and different decisions. Nothing in the model signals that the second use is invalid.

A no-show predictor trained on one hospital's patients, applied to a region with a different demographic profile.

3

Failures are systematic, and surface late

26,000

families wrongly accused

AI errors are not randomly distributed. They concentrate in particular groups, they read as objective because the output is a number, and they typically surface through appeals that the most affected are least likely to file.

The Dutch tax administration used nationality as a fraud risk signal. Around 26,000 families were wrongly accused and ordered to repay. The government resigned in 2021.

4

Decisions about citizens have to be defensible

Under PDPPL and national AI policy an entity must be able to state who decided, on what basis, and how the decision can be challenged. A system log reconstructed a year later is not a decision record.

A refused permit that cannot be traced to a named decision-maker is not a defensible administrative act.