Módulo 8: Proyecto Integrador — Ethics Audit of an AI System

Findings: Documentation + Governance

Descripción

Last findings section: Documentation and Governance. Usually los más "boring" findings but often where most gaps lie. Documentation creates audit trail; governance ensures process continues.

Al terminar tendrás complete findings de 6 sections del report.


Section: Documentation and Governance findings

# Section 9: Documentation and Governance Findings

## 9.1 Overview

Reviewed organizational and process aspects of AI governance: policies,
training, documentation completeness, governance cadence.

## 9.2 Status Summary

| Item | Description | Status | Critical |
|------|-------------|--------|----------|
| 6.1 | AI Use Policy current and signed | ⚠️ Partial | No |
| 6.2 | Documentation kept current | ❌ No | No |
| 6.3 | Team training conducted | ⚠️ Partial | No |
| 6.4 | Quarterly governance review | ✅ Yes | No |

Compliant: 1, partial: 2, gap: 1.

## 9.3 Detailed Findings

### Item 6.1: AI Use Policy — PARTIAL

**Current state**: AI Use Policy v1.0 exists in repo (created 2026-02-15).
Not formally signed by CEO. Not communicated to whole team.

**Required state**: Policy current, signed by senior leadership,
communicated to team.

**Gap**: Lack of formal authorization and team awareness.

**Evidence reviewed**:
- Policy document: ethics-framework/ai-use-policy-v1.0.md ✓
- CEO sign-off: not present
- Team awareness survey: not conducted
- Onboarding mentions: yes for new hires; older team members?

**Root cause**: Policy considered "engineering document"; missed
organizational integration.

**Impact**: Lower compliance authority; team may not feel bound by policy.

**Recommendation**:
1. CEO formally signs policy (1 hour)
2. All team members acknowledge policy (1 day)
3. Add to existing employee handbook
4. Quarterly mention in all-hands

**Priority**: LOW (administrative)
**Owner**: Tech Lead + CEO
**Effort**: 1-2 days total
**Target**: 2026-05-31

### Item 6.2: Documentation kept current — GAP

**Current state**: Many documents have last update date > 6 months ago.

Documents reviewed for currency:
- AI Use Policy: 4 months — acceptable
- RoPA: 5 months — outdated (should be after each significant change)
- DPIA: 8 months — significantly outdated
- Privacy policy (customer-facing): 14 months — outdated

**Required state**: Documents current, with formal review cadence.

**Gap**: No formal review cadence. Documents updated reactively only.

**Impact**:
- Audit risk (outdated docs ≠ no docs in audit)
- Compliance gap (DPIA must be reviewed when significant changes occur)
- Team using stale information

**Recommendation**:
1. Add review cadence to each doc (semi-annual minimum)
2. Calendar reminders for review dates
3. Refresh: RoPA, DPIA, privacy policy this quarter

**Priority**: MEDIUM
**Owner**: Tech Lead + DPO
**Effort**: 2-3 weeks for catch-up + ongoing
**Target**: 2026-Q3

### Item 6.3: Team training — PARTIAL

**Current state**: New hires have 1-hour intro to AI ethics in
onboarding. Existing team had one training in 2025-08.

**Required state**: Regular refresher training; awareness of
escalation paths; updated knowledge on regulations.

**Gap**:
- Refresher training not on regular cadence
- New regulations (EU AI Act new provisions) not covered

**Recommendation**:
1. Schedule annual refresher (1-hour sessions)
2. Add ad-hoc training for major changes
3. Track training completion

**Priority**: LOW
**Owner**: Tech Lead + HR
**Effort**: 2 hours quarterly
**Target**: Q2 schedule, Q3 implement

### Item 6.4: Quarterly governance review — Yes (with note)

**Current state**: Quarterly review meetings happening regularly.
Last 4 meetings: Q1 2026, Q4 2025, Q3 2025, Q2 2025.

**Required state**: Cadence maintained.

**Status**: ✅ Yes

**Notes**: Reviews are happening but follow-up on action items has
been inconsistent. Action items from Q3 2025 review still open in
2026.

**Recommendation**:
- Stronger tracking of action items between reviews
- Status check on prior items at start of each review

**Priority**: LOW (improvement, not gap)

## 9.4 Patterns and themes

**Pattern**: Documentation and governance treated as low priority.
Engineering work has clear ownership and tracking; governance work
falls behind.

**Root cause**: Cultural — governance not seen as "real work".

**Recommendation pattern**: Treat documentation maintenance as
first-class work. Allocate time. Track action items.

## 9.5 Recommendations summary

| ID | Recommendation | Priority | Target |
|----|---------------|----------|--------|
| DG-1 | CEO sign-off policy | LOW | 2026-05-31 |
| DG-2 | Establish doc review cadence | MEDIUM | 2026-Q3 |
| DG-3 | Refresh outdated docs (DPIA, etc.) | MEDIUM | 2026-Q3 |
| DG-4 | Annual training cadence | LOW | 2026-Q3 |
| DG-5 | Strengthen action item tracking | LOW | 2026-Q3 |

Aside: cross-section observations

After completing all 6 findings sections, often patterns emerge across sections. Document these.

# Cross-Section Observations

## Theme 1: "Customer-facing well-handled, internal underdeveloped"
Appears in:
- Section 6 (Transparency): user-facing OK, auxiliary decisions gap
- Section 8 (GDPR): Art. 22 OK, internal compliance gaps
- Section 9 (Documentation): customer-facing privacy policy outdated

Underlying cause: prioritization by visibility, not by risk.

## Theme 2: "Setup at creation, neglect during operation"
Appears in:
- Section 4 (Bias): baseline tested but not monitored
- Section 5 (Privacy): retention policy written but not enforced
- Section 9 (Documentation): policies created but not maintained

Underlying cause: One-time mentality. AI compliance is ongoing process.

## Theme 3: "Process exists but follow-through weak"
Appears in:
- Section 4 (Bias): mitigations done but not always verified
- Section 9 (Governance): reviews happen but actions linger

Underlying cause: Lack of follow-through discipline.

## Strategic recommendations

These cross-cutting themes suggest:

1. **Build operational habits**: bias monitoring, retention enforcement, doc updates should be automated/scheduled
2. **Track action items rigorously**: from creation to closure
3. **Audit cycle that catches drift**: this M8 audit is a good template

Trampas comunes

Trampa 1 — Skipping documentation/governance section. "Just process stuff". Auditors look here closely. It's organizational health.

Trampa 2 — Cross-section observations omitted. Each section in isolation = miss patterns. Synthesis adds value.

Trampa 3 — Recommendations sin pattern thinking. Recommending fixes per item but not addressing underlying cause. Address pattern.

Trampa 4 — Treating "compliance done" como achievement permanent. Static thinking. Compliance is process, not state.


Ejercicio

Complete tu report:

  1. Llené section "Documentation and Governance" para tu sistema
  2. Identifica 2-3 cross-section themes
  3. Estructuralos como strategic recommendations

Resumen

Aprendiste:

  • ✅ Documentation/governance section structure
  • ✅ Common items: policy sign-off, doc currency, training, governance cadence
  • ✅ Cross-section observations capturing patterns
  • ✅ Strategic recommendations addressing root causes
  • ✅ Trampas: skipping, no synthesis, treating as static

Checkpoint: si tu report tiene 6 findings sections + cross-section observations, complete.


Siguiente cápsula

06 — Recommendations y prioritization. Findings identifican gaps. Recommendations prescriben action. Critical to prioritize bien.


Recursos

  1. Governance Best Practices (PWC) — corporate governance examples.
  2. Anthropic's audit/review approach — frontier lab governance.
  3. GitLab handbook — example of transparent docs.