Skip to main content

The First 3 Steps to Building Data and AI Governance

Sunil Senan
Infosys

In today’s data and AI driven world, enterprises across industries are utilizing AI to invent new business models, reimagine business and achieve efficiency in operations. However, enterprises may face challenges like flawed or biased AI decisions, sensitive data breaches and rising regulatory risks, if not controlled and governed. To mitigate these risks, enterprises must embrace robust principles of responsible AI and embed them across all layers of the AI ecosystem — data, model and usage.

  • Data: Ensure data used for training AI is accurate, representative, and free from biases, with strong privacy and security controls.
  • AI Models: Controls for accuracy, relevance, explainability and fairness along with security measures for trusted reliable AI models.
  • Usage and Consumption: Monitor AI initiatives continuously and apply moderation layers to ensure ethical and compliant outputs, maintaining trust in AI solutions.

Enterprises must establish controls across the three layers based on:

  • Trust: Trust policy and guardrails to make AI explainable, traceable, accurate, reproducible and accountable
  • Ethics: Ethics policy and procedures to ensure AI initiatives are fair, free of biases and are protecting fundamental human rights
  • Privacy: Ensure privacy remains at the center of all initiatives, preserving privacy of individuals
  • Compliance: Ensure lawful and auditable AI initiatives
  • Security: Robust and secure data and AI ecosystems

On these fundamentals, enterprises must take the first three concrete steps to ensure robust governance over AI and data initiatives:

Step 1: Outline an organization-wide AI Governance Strategy

Enterprise's leadership should clearly outline the organization's strategy, vision and mission to ensure that responsible data and AI consumption is the primary focus of all individuals idealizing, developing and consuming data and AI.

Enterprise should define comprehensive policies and procedures at enterprise level around the five principles, actively govern the initiatives and educate its employees.

Step 2: Establish Operating Model

Subsequently, the next area of focus should be the people, processes and technology involved in these initiatives.

  • Enterprises must set up a Governance CoE, identify all the personas responsible along with clear roles and responsibilities assigned to different personas.
  • Enterprises must set up robust framework to govern the data and AI initiatives along with monitoring to ensure governance and compliance with the evolving regulations.
  • Enterprises must modernize their tools and technologies to manage and govern the initiatives. (e.g. tools for assessment, controls implementation, audit and monitoring)

Step 3: Operationalize the data and AI Governance Framework

Enterprises at this stage will be ready to govern each and every data and AI initiative by design.

  • Enterprises should start with documenting the AI use cases with governance related fingerprints.
  • Next, enterprises must prioritize the use cases and assess the risk for each of the use cases to enforce appropriate control for governance.

These three steps help enterprises to ensure responsible and sustainable data and AI initiatives, leading to better brand value and customer satisfaction.

Sunil Senan is Global Head of Data, Analytics and AI at Infosys

Hot Topics

The Latest

Rapid AI adoption and the unique ways AI workloads operate is redefining the scope and structure of what these teams must deliver. This shift is forcing organizations to rethink how they manage scale, automation, and control, according to The State of SRE and Platform Engineering 2026, a new report from Dynatrace ...

AI is usually talked about as a software tool, but it also depends heavily on the network behind it. Whether a company is using AI for chatbots, automation, monitoring, analytics, or employee support, all of that information has to move across the network in a reliable and secure way. That means AI is not just an application decision. It is also an infrastructure decision. Before organizations rush into AI, they should ask a simple question: Is our network ready to support it? ...

Enterprise AI often lacks governed access to where business processes actually execute. Without that access, AI agents may be able to reason, but they cannot operate reliably across enterprise workflows. For AI agents to effectively carry out workflows, they will require integration-layer context and controls. Organizations can implement these prerequisites by providing AI with managed access to the middleware layer ...

Enterprise networks rarely behave the same way for very long. A routing adjustment in one region may unexpectedly alter application performance in another. A cloud migration may introduce hidden dependencies that go unnoticed until an outage occurs. All the while, the network is managed by several different teams, each of whom use different tool sets — and as a result, have different views of the network ... There’s usually an engineer who remembers why traffic fails over a certain way between sites, or which transparent firewall was added where. The problem is that human memory cannot scale alongside enterprise-scale networks ...

Ask an infrastructure team how confident they are in their ability to govern AI, and most will tell you they've got it handled. A recent survey of 406 IT decision-makers and platform engineering leaders found 86% expressing exactly that confidence. Ask the same group whether they have a formal written AI governance policy, and the number drops to 30%, according to Spacelift's Infrastructure Automation Report ...

In MEAN TIME TO INSIGHT Episode 27, Shamus McGillicuddy, EMA VP of Research, Network Infrastructure and Operations, and Parker Hathcock, EMA Research Director covering IT Service/Operations (ServiceOps), discuss observability unification in modern IT operations ... 

Virtual Private Networks became a cornerstone of enterprise security at a time when corporate infrastructure looked very different from today ... For years, this model worked well. But the architecture behind VPNs assumed a centralized corporate environment—one where the network itself was the hub of activity. In a cloud — first world, that assumption no longer holds ...

Website outages get resolved just as fast in August as they do in November. I went looking for the opposite: the summer slowdown everyone assumes is there once the people who fix things are away. It isn't in the data we collected, covering 1.8 million confirmed outages across tens of thousands of websites ...

This year, many of the cloud infrastructure contracts signed in the early days of the AI boom will come up for renewal. As the year goes on, I anticipate we'll see a significant amount of cloud vendor swapouts and multi-cloud adoption, and the reason isn't just GPU depreciation. It's because they're tired of their current cloud providers ...

There's a moment the many observability teams have experienced days into bringing a new service into production: you realize that the vendor's claims of "intelligent" behavior included a large serving of hype. Their dashboards look nice until they don't, the failure modes are a black box, and no one on the team can confidently explain why the system did what it did at 2 am. Agentic AI is about to force every Ops team to relive that moment at web-scale until they start treating these systems as the dependencies they actually are ...

The First 3 Steps to Building Data and AI Governance

Sunil Senan
Infosys

In today’s data and AI driven world, enterprises across industries are utilizing AI to invent new business models, reimagine business and achieve efficiency in operations. However, enterprises may face challenges like flawed or biased AI decisions, sensitive data breaches and rising regulatory risks, if not controlled and governed. To mitigate these risks, enterprises must embrace robust principles of responsible AI and embed them across all layers of the AI ecosystem — data, model and usage.

  • Data: Ensure data used for training AI is accurate, representative, and free from biases, with strong privacy and security controls.
  • AI Models: Controls for accuracy, relevance, explainability and fairness along with security measures for trusted reliable AI models.
  • Usage and Consumption: Monitor AI initiatives continuously and apply moderation layers to ensure ethical and compliant outputs, maintaining trust in AI solutions.

Enterprises must establish controls across the three layers based on:

  • Trust: Trust policy and guardrails to make AI explainable, traceable, accurate, reproducible and accountable
  • Ethics: Ethics policy and procedures to ensure AI initiatives are fair, free of biases and are protecting fundamental human rights
  • Privacy: Ensure privacy remains at the center of all initiatives, preserving privacy of individuals
  • Compliance: Ensure lawful and auditable AI initiatives
  • Security: Robust and secure data and AI ecosystems

On these fundamentals, enterprises must take the first three concrete steps to ensure robust governance over AI and data initiatives:

Step 1: Outline an organization-wide AI Governance Strategy

Enterprise's leadership should clearly outline the organization's strategy, vision and mission to ensure that responsible data and AI consumption is the primary focus of all individuals idealizing, developing and consuming data and AI.

Enterprise should define comprehensive policies and procedures at enterprise level around the five principles, actively govern the initiatives and educate its employees.

Step 2: Establish Operating Model

Subsequently, the next area of focus should be the people, processes and technology involved in these initiatives.

  • Enterprises must set up a Governance CoE, identify all the personas responsible along with clear roles and responsibilities assigned to different personas.
  • Enterprises must set up robust framework to govern the data and AI initiatives along with monitoring to ensure governance and compliance with the evolving regulations.
  • Enterprises must modernize their tools and technologies to manage and govern the initiatives. (e.g. tools for assessment, controls implementation, audit and monitoring)

Step 3: Operationalize the data and AI Governance Framework

Enterprises at this stage will be ready to govern each and every data and AI initiative by design.

  • Enterprises should start with documenting the AI use cases with governance related fingerprints.
  • Next, enterprises must prioritize the use cases and assess the risk for each of the use cases to enforce appropriate control for governance.

These three steps help enterprises to ensure responsible and sustainable data and AI initiatives, leading to better brand value and customer satisfaction.

Sunil Senan is Global Head of Data, Analytics and AI at Infosys

Hot Topics

The Latest

Rapid AI adoption and the unique ways AI workloads operate is redefining the scope and structure of what these teams must deliver. This shift is forcing organizations to rethink how they manage scale, automation, and control, according to The State of SRE and Platform Engineering 2026, a new report from Dynatrace ...

AI is usually talked about as a software tool, but it also depends heavily on the network behind it. Whether a company is using AI for chatbots, automation, monitoring, analytics, or employee support, all of that information has to move across the network in a reliable and secure way. That means AI is not just an application decision. It is also an infrastructure decision. Before organizations rush into AI, they should ask a simple question: Is our network ready to support it? ...

Enterprise AI often lacks governed access to where business processes actually execute. Without that access, AI agents may be able to reason, but they cannot operate reliably across enterprise workflows. For AI agents to effectively carry out workflows, they will require integration-layer context and controls. Organizations can implement these prerequisites by providing AI with managed access to the middleware layer ...

Enterprise networks rarely behave the same way for very long. A routing adjustment in one region may unexpectedly alter application performance in another. A cloud migration may introduce hidden dependencies that go unnoticed until an outage occurs. All the while, the network is managed by several different teams, each of whom use different tool sets — and as a result, have different views of the network ... There’s usually an engineer who remembers why traffic fails over a certain way between sites, or which transparent firewall was added where. The problem is that human memory cannot scale alongside enterprise-scale networks ...

Ask an infrastructure team how confident they are in their ability to govern AI, and most will tell you they've got it handled. A recent survey of 406 IT decision-makers and platform engineering leaders found 86% expressing exactly that confidence. Ask the same group whether they have a formal written AI governance policy, and the number drops to 30%, according to Spacelift's Infrastructure Automation Report ...

In MEAN TIME TO INSIGHT Episode 27, Shamus McGillicuddy, EMA VP of Research, Network Infrastructure and Operations, and Parker Hathcock, EMA Research Director covering IT Service/Operations (ServiceOps), discuss observability unification in modern IT operations ... 

Virtual Private Networks became a cornerstone of enterprise security at a time when corporate infrastructure looked very different from today ... For years, this model worked well. But the architecture behind VPNs assumed a centralized corporate environment—one where the network itself was the hub of activity. In a cloud — first world, that assumption no longer holds ...

Website outages get resolved just as fast in August as they do in November. I went looking for the opposite: the summer slowdown everyone assumes is there once the people who fix things are away. It isn't in the data we collected, covering 1.8 million confirmed outages across tens of thousands of websites ...

This year, many of the cloud infrastructure contracts signed in the early days of the AI boom will come up for renewal. As the year goes on, I anticipate we'll see a significant amount of cloud vendor swapouts and multi-cloud adoption, and the reason isn't just GPU depreciation. It's because they're tired of their current cloud providers ...

There's a moment the many observability teams have experienced days into bringing a new service into production: you realize that the vendor's claims of "intelligent" behavior included a large serving of hype. Their dashboards look nice until they don't, the failure modes are a black box, and no one on the team can confidently explain why the system did what it did at 2 am. Agentic AI is about to force every Ops team to relive that moment at web-scale until they start treating these systems as the dependencies they actually are ...