Module 8: Capstone Project — Ethics Audit of an AI System
Findings: Documentation + Governance
Description
The last findings section: Documentation and Governance. Usually the most "boring" findings, but often where most of the gaps are. Documentation creates the audit trail; governance ensures the process continues.
By the end you'll have complete findings for 6 sections of the report.
Section: Documentation and Governance findings
# Section 9: Documentation and Governance Findings
## 9.1 Overview
We reviewed the organizational and process aspects of AI governance: policies,
training, documentation completeness, governance cadence.
## 9.2 Status Summary
| Item | Description | Status | Critical |
|------|-------------|--------|----------|
| 6.1 | AI Use Policy current and signed | ⚠️ Partial | No |
| 6.2 | Documentation kept current | ❌ No | No |
| 6.3 | Team training conducted | ⚠️ Partial | No |
| 6.4 | Quarterly governance review | ✅ Yes | No |
Compliant: 1, partial: 2, gap: 1.
## 9.3 Detailed Findings
### Item 6.1: AI Use Policy — PARTIAL
**Current state**: The AI Use Policy v1.0 exists in the repo (created 2026-02-15).
It isn't formally signed by the CEO. It hasn't been communicated to the whole team.
**Required state**: The policy is current, signed by senior leadership, and
communicated to the team.
**Gap**: A lack of formal authorization and team awareness.
**Evidence reviewed**:
- The policy document: ethics-framework/ai-use-policy-v1.0.md ✓
- CEO sign-off: not present
- A team awareness survey: not conducted
- Onboarding mentions: yes for new hires; what about longer-tenured team members?
**Root cause**: The policy was treated as an "engineering document"; it missed
organizational integration.
**Impact**: Lower compliance authority; the team may not feel bound by the policy.
**Recommendation**:
1. The CEO formally signs the policy (1 hour)
2. All team members acknowledge the policy (1 day)
3. Add it to the existing employee handbook
4. A quarterly mention at the all-hands
**Priority**: LOW (administrative)
**Owner**: Tech Lead + CEO
**Effort**: 1-2 days total
**Target**: 2026-05-31
### Item 6.2: Documentation kept current — GAP
**Current state**: Many documents have a last-update date > 6 months ago.
Documents reviewed for currency:
- The AI Use Policy: 4 months — acceptable
- The RoPA: 5 months — outdated (it should be updated after each significant change)
- The DPIA: 8 months — significantly outdated
- The privacy policy (customer-facing): 14 months — outdated
**Required state**: The documents are current, with a formal review cadence.
**Gap**: There's no formal review cadence. Documents get updated reactively only.
**Impact**:
- Audit risk (outdated docs ≠ no docs in an audit)
- A compliance gap (the DPIA must be reviewed when significant changes occur)
- The team is using stale information
**Recommendation**:
1. Add a review cadence to each doc (semi-annual minimum)
2. Calendar reminders for the review dates
3. Refresh: the RoPA, the DPIA, the privacy policy this quarter
**Priority**: MEDIUM
**Owner**: Tech Lead + DPO
**Effort**: 2-3 weeks to catch up + ongoing
**Target**: 2026-Q3
### Item 6.3: Team training — PARTIAL
**Current state**: New hires get a 1-hour intro to AI ethics during
onboarding. The existing team had one training session in 2025-08.
**Required state**: Regular refresher training; awareness of the
escalation paths; updated knowledge on the regulations.
**Gap**:
- Refresher training isn't on a regular cadence
- New regulations (the EU AI Act's new provisions) aren't covered
**Recommendation**:
1. Schedule an annual refresher (1-hour sessions)
2. Add ad-hoc training for major changes
3. Track training completion
**Priority**: LOW
**Owner**: Tech Lead + HR
**Effort**: 2 hours quarterly
**Target**: Schedule in Q2, implement in Q3
### Item 6.4: Quarterly governance review — Yes (with a note)
**Current state**: The quarterly review meetings are happening regularly.
The last 4 meetings: Q1 2026, Q4 2025, Q3 2025, Q2 2025.
**Required state**: The cadence is maintained.
**Status**: ✅ Yes
**Notes**: The reviews are happening, but follow-up on the action items has
been inconsistent. Action items from the Q3 2025 review are still open in
2026.
**Recommendation**:
- Stronger tracking of action items between reviews
- A status check on the prior items at the start of each review
**Priority**: LOW (an improvement, not a gap)
## 9.4 Patterns and themes
**Pattern**: Documentation and governance are treated as low priority.
Engineering work has clear ownership and tracking; governance work
falls behind.
**Root cause**: Cultural — governance isn't seen as "real work."
**Recommendation pattern**: Treat documentation maintenance as
first-class work. Allocate the time. Track the action items.
## 9.5 Recommendations summary
| ID | Recommendation | Priority | Target |
|----|----------------|----------|--------|
| DG-1 | CEO sign-off on the policy | LOW | 2026-05-31 |
| DG-2 | Establish a doc review cadence | MEDIUM | 2026-Q3 |
| DG-3 | Refresh the outdated docs (DPIA, etc.) | MEDIUM | 2026-Q3 |
| DG-4 | An annual training cadence | LOW | 2026-Q3 |
| DG-5 | Strengthen action item tracking | LOW | 2026-Q3 |
Aside: cross-section observations
After completing all 6 findings sections, patterns often emerge across sections. Document these.
# Cross-Section Observations
## Theme 1: "Customer-facing well handled, internal underdeveloped"
It appears in:
- Section 6 (Transparency): user-facing is OK, the auxiliary decisions are a gap
- Section 8 (GDPR): Art. 22 is OK, internal compliance has gaps
- Section 9 (Documentation): the customer-facing privacy policy is outdated
The underlying cause: prioritization by visibility, not by risk.
## Theme 2: "Set up at creation, neglected during operation"
It appears in:
- Section 4 (Bias): the baseline was tested but isn't monitored
- Section 5 (Privacy): the retention policy was written but isn't enforced
- Section 9 (Documentation): the policies were created but aren't maintained
The underlying cause: a one-time mentality. AI compliance is an ongoing process.
## Theme 3: "The process exists but follow-through is weak"
It appears in:
- Section 4 (Bias): mitigations were done but aren't always verified
- Section 9 (Governance): reviews happen but the actions linger
The underlying cause: a lack of follow-through discipline.
## Strategic recommendations
These cross-cutting themes suggest:
1. **Build operational habits**: bias monitoring, retention enforcement, and doc updates should be automated/scheduled
2. **Track action items rigorously**: from creation to closure
3. **An audit cycle that catches drift**: this M8 audit is a good template
Common traps
Trap 1 — Skipping the documentation/governance section. "It's just process stuff." Auditors look here closely. It's organizational health.
Trap 2 — Omitting the cross-section observations. Each section in isolation = you miss the patterns. Synthesis adds value.
Trap 3 — Recommendations with no pattern thinking. Recommending fixes per item without addressing the underlying cause. Address the pattern.
Trap 4 — Treating "compliance done" as a permanent achievement. Static thinking. Compliance is a process, not a state.
Exercise
Complete your report:
- Fill in the "Documentation and Governance" section for your system
- Identify 2-3 cross-section themes
- Structure them as strategic recommendations
Summary
You learned:
- ✅ The documentation/governance section structure
- ✅ The common items: policy sign-off, doc currency, training, governance cadence
- ✅ Cross-section observations that capture the patterns
- ✅ Strategic recommendations that address the root causes
- ✅ The traps: skipping it, no synthesis, treating it as static
Checkpoint: if your report has 6 findings sections + cross-section observations, it's complete.
Next capsule
06 — Recommendations and prioritization. The findings identify the gaps. The recommendations prescribe the action. Prioritizing well is critical.
Resources
- Governance Best Practices (PWC) — corporate governance examples.
- Anthropic's audit/review approach — frontier lab governance.
- GitLab handbook — an example of transparent docs.