Skip to main content

What are you looking for?

Explore our services and discover how we can help you achieve your goals

AI workflow governance questions: what to settle before you sign the approval

Before approving an AI workflow, settle who owns it, what it is for and not for, which data it uses, who may overrule it, what record it leaves, how dependent it makes you on its supplier, and how it is changed, monitored and switched off. An approval without those answers approves a demonstration, not a system.

Submit a project Explore AI workflow automation

Reviewed by David Nguyen (CEO) · Updated 28 Sep 2026 · 10 min read

star

OutsourcingVN is operated by Netbase JSC, which builds AI workflows and will sometimes be the supplier answering these questions, so weigh the list accordingly. It is written for the executive, risk owner or operations lead asked to sign off an AI workflow, and it deliberately stops short of test design and review queues, which have their own guides.

Contents

What is governance here, and what is it not?

Governance is the set of decisions about accountability that surround a workflow: who decided it should exist, who answers for it, and on what evidence it was allowed to run. It is different from testing whether outputs are good, which the AI workflow evaluation and testing guide covers, and from designing where people review outputs, which human-in-the-loop AI workflows covers. Governance asks whether those two pieces of work were done, by whom, and who accepts what remains.

NIST's AI Risk Management Framework (AI RMF 1.0, released 2023-01-26) puts "Govern" alongside Map, Measure and Manage as one of its four core functions, and its Generative AI Profile (NIST AI 600-1, 2024) extends that to generative systems. Both are voluntary frameworks. They are useful here as a checklist of what an organisation should be able to show, not as a certificate a workflow can earn.

Which questions should the approver settle?

Each question needs a named person to answer it and a piece of evidence that can be filed with the approval.

Area Question Who answers Evidence for the file
Purpose What decision or task does the workflow support, and what is it explicitly not for? Business owner A one-page purpose and exclusions statement
Ownership Who is accountable for the workflow's behaviour after launch? Executive sponsor A named owner with authority to pause it
Data Which data does it read and write, where is it processed, and on what basis? Data or privacy owner A data inventory with processing locations and retention
Decision rights Which outputs take effect automatically, and who can overrule them? Process owner The review design and the escalation route
Affected people Who is affected by its outputs, and how can they question one? Customer or HR owner A contact route and a response commitment
Evidence of quality What testing was done, against which thresholds, with what result? Delivery lead The evaluation report and its limitations
Security Which systems can it reach, with what permissions? Security owner The tool and access map
Audit trail Can a single output be traced to its input, model version, prompt and reviewer? Delivery lead A sample trace from the test environment
Supplier and model dependency What happens if the model or supplier changes terms, versions or availability? Procurement A dependency list and a fallback
Change control Who approves changes to the model, prompts, data sources or tools? Business owner A change procedure naming the approver
Monitoring and incidents What is watched in production, and who is called when it goes wrong? Operations lead Monitoring list and an incident contact
Retirement How is the workflow paused, and what replaces it if it is switched off? Business owner A documented manual fallback

A workflow that reaches tools or external systems needs one more document: the permission map described in the AI agent tool permissions guide. Where the workflow processes personal data through a supplier, the data security and compliance guide lists the contractual questions to add.

What should the approval record contain?

  1. The purpose and exclusions

    , in plain language, dated.

  2. The named owner

    , with authority to pause the workflow without further approval.

  3. The evidence pack

    evaluation results, review design, access map, data inventory and a sample trace.

  4. The accepted risks

    , each with an owner and a review date.

  5. The conditions of approval

    , such as a pilot group, a volume cap or a sunset date.

  6. The change rule

    which changes need a new approval and which the owner may sign alone.

  7. The review date

    , when the approver looks at production evidence and decides to continue, change or stop.

Keep the record short enough that the approver reads it. Two pages plus attachments is usually enough, and a record nobody reads is not governance.

Worked scenario: approving an invoice-coding assistant

A property management company proposes an assistant that reads supplier invoices, suggests the cost code and building, and posts approved lines to the accounting system. The finance director is asked to approve it. The scenario is illustrative and describes no client.

  • Purpose and exclusions. Suggest codes for supplier invoices; excluded are payments, supplier onboarding and anything over a set value, which stay fully manual.
  • Ownership. The financial controller owns the workflow and can pause it; the finance director remains the approver.
  • Data. Invoices contain supplier bank details and some tenant names. The data inventory shows where the model is hosted and that invoices are kept only as long as the accounting records require.
  • Decision rights. Suggestions take effect only after an accounts clerk accepts them; the evaluation report shows accuracy by invoice type, with two supplier categories excluded from the pilot for low accuracy.
  • Dependency. The assistant uses one commercial model through an API. The fallback is the existing manual coding screen, which stays in place.
  • Conditions. A three-month pilot on two buildings, a weekly exception report, and a review date at the end of the pilot.

The director approves with those conditions. The approval takes one meeting because every answer arrived with its evidence, not because the workflow was simple.

What does the supplier's side of the answers look like?

An approver should expect the supplier to answer for its own practice, not only the client's. Netbase applies the ISO/IEC 42001 AI management system framework to its own AI delivery practice; this is an applied practice rather than a certification, and it does not extend to the workflow a client approves. Netbase works with commercial and open-source AI models chosen per project (model-agnostic); no vendor partnership is implied, which matters for the dependency question because the model can be changed per project.

On data and security, Netbase's compliance practices are GDPR alignment for data privacy in Europe, HIPAA-aligned methodologies for healthcare data handling, and CCPA compliance for clients with U.S. customer bases. These are practices, not certificates, and the client's own legal compliance remains the client's to establish. Security practices include secure code review and version control, role-based access control, MFA for admin dashboards, contributors under NDA, and NDAs and DPAs on request.

On delivery, for a client that is not named, Netbase built a WhatsApp Business AI chatbot with intent and conversation-flow handling, an LLM API (GPT-4 in the stack) and CRM synchronisation for lead capture, customer data and workflow automation; the WhatsApp chatbot record shows the kind of system whose data and change questions this page lists. Netbase has also delivered anonymised client AI projects including retrieval-based knowledge assistants, document AI and MLOps pipelines.

Which questions should you put to the supplier directly?

  • Which model and version will run in production, and how will we hear about a change?
  • Where is our data processed and stored, and is any of it used to train a model?
  • Can you produce a trace for one output, end to end, before approval?
  • Who on your side can pause the workflow, and who on ours?
  • What do you hand over if we end the engagement: prompts, evaluation sets, configuration, documentation?
  • Which of your practices apply to our workflow, and which are only about your own organisation?

The model selection guide covers the model-specific questions in more depth.

What goes wrong in AI workflow governance?

  • Approval of a demonstration. Signal: the evidence is a recorded demo. Correction: require evaluation results on your own cases.
  • An owner in name only. Signal: the owner cannot pause the workflow without asking IT. Correction: give the owner the switch.
  • Silent changes. Signal: prompts or models change between reviews without a record. Correction: a change rule in the approval.
  • No route for affected people. Signal: a customer disputes an output and nobody knows who answers. Correction: a named contact and response commitment.
  • No exit. Signal: the manual process was retired at launch. Correction: keep a fallback until the review date proves it can go.

How this guide is sourced and where it stops

Framework references are NIST AI RMF 1.0 and NIST AI 600-1, listed and dated under Sources. Statements about Netbase are approved claim-register entries in their registered wording; the methodology explains how they are reviewed. The invoice scenario is illustrative. Netbase's published record here is the WhatsApp chatbot and anonymised AI delivery; Netbase has no published record of running a client's AI governance or approval process, so this page offers a question set and scoped support, not a governance track record. It is not legal advice.

Plan the next step for your project

Common questions

The person accountable for the business process it changes, with sign-off from data, security and operations owners where their areas are touched. The approver should not be the person who built it.

Scale the record to the consequence. An internal drafting aid needs a purpose, an owner and a data check; a workflow that affects customers, money or employment needs the full list.

At the end of any pilot, after any significant change to the model, data or tools, and on a fixed schedule set in the approval, commonly every few months at first.

No. It is a voluntary framework that helps organise risk management; legal obligations depend on your jurisdiction, sector and data, and need their own review.

Human-in-the-loop design decides where people review outputs and on what thresholds. Governance decides who is accountable, what evidence was required and what conditions the approval carries, including whether that review design is adequate.

Bring the workflow and the approver

The AI workflow automation guide sets out how a workflow is chosen and built, and AI Workflow Automation is the service that delivers it with an evidence pack an approver can use.

OutsourcingVN is Netbase's own outsourcing-services platform. Submit a project with the workflow, the person who will approve it and the questions above you cannot yet answer, and a person will reply with what it would take to answer them.

AI workflow automation with evaluation and human control AI workflow automation with evaluation and human control

One operating workflow automated, with an agreed way to judge it and a person on uncertain cases.

Learn More
line

Tell us what you want to build or automate.

Submit a project