Module 8: Capstone Project — Ethics Audit of an AI System

Findings: Documentation + Governance

Description

The last findings section: Documentation and Governance. Usually the most "boring" findings, but often where most of the gaps are. Documentation creates the audit trail; governance ensures the process continues.

By the end you'll have complete findings for 6 sections of the report.


Section: Documentation and Governance findings

# Section 9: Documentation and Governance Findings

## 9.1 Overview

We reviewed the organizational and process aspects of AI governance: policies,
training, documentation completeness, governance cadence.

## 9.2 Status Summary

| Item | Description | Status | Critical |
|------|-------------|--------|----------|
| 6.1 | AI Use Policy current and signed | ⚠️ Partial | No |
| 6.2 | Documentation kept current | ❌ No | No |
| 6.3 | Team training conducted | ⚠️ Partial | No |
| 6.4 | Quarterly governance review | ✅ Yes | No |

Compliant: 1, partial: 2, gap: 1.

## 9.3 Detailed Findings

### Item 6.1: AI Use Policy — PARTIAL

**Current state**: The AI Use Policy v1.0 exists in the repo (created 2026-02-15).
It isn't formally signed by the CEO. It hasn't been communicated to the whole team.

**Required state**: The policy is current, signed by senior leadership, and
communicated to the team.

**Gap**: A lack of formal authorization and team awareness.

**Evidence reviewed**:
- The policy document: ethics-framework/ai-use-policy-v1.0.md ✓
- CEO sign-off: not present
- A team awareness survey: not conducted
- Onboarding mentions: yes for new hires; what about longer-tenured team members?

**Root cause**: The policy was treated as an "engineering document"; it missed
organizational integration.

**Impact**: Lower compliance authority; the team may not feel bound by the policy.

**Recommendation**:
1. The CEO formally signs the policy (1 hour)
2. All team members acknowledge the policy (1 day)
3. Add it to the existing employee handbook
4. A quarterly mention at the all-hands

**Priority**: LOW (administrative)
**Owner**: Tech Lead + CEO
**Effort**: 1-2 days total
**Target**: 2026-05-31

### Item 6.2: Documentation kept current — GAP

**Current state**: Many documents have a last-update date > 6 months ago.

Documents reviewed for currency:
- The AI Use Policy: 4 months — acceptable
- The RoPA: 5 months — outdated (it should be updated after each significant change)
- The DPIA: 8 months — significantly outdated
- The privacy policy (customer-facing): 14 months — outdated

**Required state**: The documents are current, with a formal review cadence.

**Gap**: There's no formal review cadence. Documents get updated reactively only.

**Impact**:
- Audit risk (outdated docs ≠ no docs in an audit)
- A compliance gap (the DPIA must be reviewed when significant changes occur)
- The team is using stale information

**Recommendation**:
1. Add a review cadence to each doc (semi-annual minimum)
2. Calendar reminders for the review dates
3. Refresh: the RoPA, the DPIA, the privacy policy this quarter

**Priority**: MEDIUM
**Owner**: Tech Lead + DPO
**Effort**: 2-3 weeks to catch up + ongoing
**Target**: 2026-Q3

### Item 6.3: Team training — PARTIAL

**Current state**: New hires get a 1-hour intro to AI ethics during
onboarding. The existing team had one training session in 2025-08.

**Required state**: Regular refresher training; awareness of the
escalation paths; updated knowledge on the regulations.

**Gap**:
- Refresher training isn't on a regular cadence
- New regulations (the EU AI Act's new provisions) aren't covered

**Recommendation**:
1. Schedule an annual refresher (1-hour sessions)
2. Add ad-hoc training for major changes
3. Track training completion

**Priority**: LOW
**Owner**: Tech Lead + HR
**Effort**: 2 hours quarterly
**Target**: Schedule in Q2, implement in Q3

### Item 6.4: Quarterly governance review — Yes (with a note)

**Current state**: The quarterly review meetings are happening regularly.
The last 4 meetings: Q1 2026, Q4 2025, Q3 2025, Q2 2025.

**Required state**: The cadence is maintained.

**Status**: ✅ Yes

**Notes**: The reviews are happening, but follow-up on the action items has
been inconsistent. Action items from the Q3 2025 review are still open in
2026.

**Recommendation**:
- Stronger tracking of action items between reviews
- A status check on the prior items at the start of each review

**Priority**: LOW (an improvement, not a gap)

## 9.4 Patterns and themes

**Pattern**: Documentation and governance are treated as low priority.
Engineering work has clear ownership and tracking; governance work
falls behind.

**Root cause**: Cultural — governance isn't seen as "real work."

**Recommendation pattern**: Treat documentation maintenance as
first-class work. Allocate the time. Track the action items.

## 9.5 Recommendations summary

| ID | Recommendation | Priority | Target |
|----|----------------|----------|--------|
| DG-1 | CEO sign-off on the policy | LOW | 2026-05-31 |
| DG-2 | Establish a doc review cadence | MEDIUM | 2026-Q3 |
| DG-3 | Refresh the outdated docs (DPIA, etc.) | MEDIUM | 2026-Q3 |
| DG-4 | An annual training cadence | LOW | 2026-Q3 |
| DG-5 | Strengthen action item tracking | LOW | 2026-Q3 |

Aside: cross-section observations

After completing all 6 findings sections, patterns often emerge across sections. Document these.

# Cross-Section Observations

## Theme 1: "Customer-facing well handled, internal underdeveloped"
It appears in:
- Section 6 (Transparency): user-facing is OK, the auxiliary decisions are a gap
- Section 8 (GDPR): Art. 22 is OK, internal compliance has gaps
- Section 9 (Documentation): the customer-facing privacy policy is outdated

The underlying cause: prioritization by visibility, not by risk.

## Theme 2: "Set up at creation, neglected during operation"
It appears in:
- Section 4 (Bias): the baseline was tested but isn't monitored
- Section 5 (Privacy): the retention policy was written but isn't enforced
- Section 9 (Documentation): the policies were created but aren't maintained

The underlying cause: a one-time mentality. AI compliance is an ongoing process.

## Theme 3: "The process exists but follow-through is weak"
It appears in:
- Section 4 (Bias): mitigations were done but aren't always verified
- Section 9 (Governance): reviews happen but the actions linger

The underlying cause: a lack of follow-through discipline.

## Strategic recommendations

These cross-cutting themes suggest:

1. **Build operational habits**: bias monitoring, retention enforcement, and doc updates should be automated/scheduled
2. **Track action items rigorously**: from creation to closure
3. **An audit cycle that catches drift**: this M8 audit is a good template

Common traps

Trap 1 — Skipping the documentation/governance section. "It's just process stuff." Auditors look here closely. It's organizational health.

Trap 2 — Omitting the cross-section observations. Each section in isolation = you miss the patterns. Synthesis adds value.

Trap 3 — Recommendations with no pattern thinking. Recommending fixes per item without addressing the underlying cause. Address the pattern.

Trap 4 — Treating "compliance done" as a permanent achievement. Static thinking. Compliance is a process, not a state.


Exercise

Complete your report:

  1. Fill in the "Documentation and Governance" section for your system
  2. Identify 2-3 cross-section themes
  3. Structure them as strategic recommendations

Summary

You learned:

  • ✅ The documentation/governance section structure
  • ✅ The common items: policy sign-off, doc currency, training, governance cadence
  • ✅ Cross-section observations that capture the patterns
  • ✅ Strategic recommendations that address the root causes
  • ✅ The traps: skipping it, no synthesis, treating it as static

Checkpoint: if your report has 6 findings sections + cross-section observations, it's complete.


Next capsule

06 — Recommendations and prioritization. The findings identify the gaps. The recommendations prescribe the action. Prioritizing well is critical.


Resources

  1. Governance Best Practices (PWC) — corporate governance examples.
  2. Anthropic's audit/review approach — frontier lab governance.
  3. GitLab handbook — an example of transparent docs.