Módulo 8: Proyecto Integrador — Ethics Audit of an AI System
Findings: Documentation + Governance
Descripción
Last findings section: Documentation and Governance. Usually los más "boring" findings but often where most gaps lie. Documentation creates audit trail; governance ensures process continues.
Al terminar tendrás complete findings de 6 sections del report.
Section: Documentation and Governance findings
# Section 9: Documentation and Governance Findings
## 9.1 Overview
Reviewed organizational and process aspects of AI governance: policies,
training, documentation completeness, governance cadence.
## 9.2 Status Summary
| Item | Description | Status | Critical |
|------|-------------|--------|----------|
| 6.1 | AI Use Policy current and signed | ⚠️ Partial | No |
| 6.2 | Documentation kept current | ❌ No | No |
| 6.3 | Team training conducted | ⚠️ Partial | No |
| 6.4 | Quarterly governance review | ✅ Yes | No |
Compliant: 1, partial: 2, gap: 1.
## 9.3 Detailed Findings
### Item 6.1: AI Use Policy — PARTIAL
**Current state**: AI Use Policy v1.0 exists in repo (created 2026-02-15).
Not formally signed by CEO. Not communicated to whole team.
**Required state**: Policy current, signed by senior leadership,
communicated to team.
**Gap**: Lack of formal authorization and team awareness.
**Evidence reviewed**:
- Policy document: ethics-framework/ai-use-policy-v1.0.md ✓
- CEO sign-off: not present
- Team awareness survey: not conducted
- Onboarding mentions: yes for new hires; older team members?
**Root cause**: Policy considered "engineering document"; missed
organizational integration.
**Impact**: Lower compliance authority; team may not feel bound by policy.
**Recommendation**:
1. CEO formally signs policy (1 hour)
2. All team members acknowledge policy (1 day)
3. Add to existing employee handbook
4. Quarterly mention in all-hands
**Priority**: LOW (administrative)
**Owner**: Tech Lead + CEO
**Effort**: 1-2 days total
**Target**: 2026-05-31
### Item 6.2: Documentation kept current — GAP
**Current state**: Many documents have last update date > 6 months ago.
Documents reviewed for currency:
- AI Use Policy: 4 months — acceptable
- RoPA: 5 months — outdated (should be after each significant change)
- DPIA: 8 months — significantly outdated
- Privacy policy (customer-facing): 14 months — outdated
**Required state**: Documents current, with formal review cadence.
**Gap**: No formal review cadence. Documents updated reactively only.
**Impact**:
- Audit risk (outdated docs ≠ no docs in audit)
- Compliance gap (DPIA must be reviewed when significant changes occur)
- Team using stale information
**Recommendation**:
1. Add review cadence to each doc (semi-annual minimum)
2. Calendar reminders for review dates
3. Refresh: RoPA, DPIA, privacy policy this quarter
**Priority**: MEDIUM
**Owner**: Tech Lead + DPO
**Effort**: 2-3 weeks for catch-up + ongoing
**Target**: 2026-Q3
### Item 6.3: Team training — PARTIAL
**Current state**: New hires have 1-hour intro to AI ethics in
onboarding. Existing team had one training in 2025-08.
**Required state**: Regular refresher training; awareness of
escalation paths; updated knowledge on regulations.
**Gap**:
- Refresher training not on regular cadence
- New regulations (EU AI Act new provisions) not covered
**Recommendation**:
1. Schedule annual refresher (1-hour sessions)
2. Add ad-hoc training for major changes
3. Track training completion
**Priority**: LOW
**Owner**: Tech Lead + HR
**Effort**: 2 hours quarterly
**Target**: Q2 schedule, Q3 implement
### Item 6.4: Quarterly governance review — Yes (with note)
**Current state**: Quarterly review meetings happening regularly.
Last 4 meetings: Q1 2026, Q4 2025, Q3 2025, Q2 2025.
**Required state**: Cadence maintained.
**Status**: ✅ Yes
**Notes**: Reviews are happening but follow-up on action items has
been inconsistent. Action items from Q3 2025 review still open in
2026.
**Recommendation**:
- Stronger tracking of action items between reviews
- Status check on prior items at start of each review
**Priority**: LOW (improvement, not gap)
## 9.4 Patterns and themes
**Pattern**: Documentation and governance treated as low priority.
Engineering work has clear ownership and tracking; governance work
falls behind.
**Root cause**: Cultural — governance not seen as "real work".
**Recommendation pattern**: Treat documentation maintenance as
first-class work. Allocate time. Track action items.
## 9.5 Recommendations summary
| ID | Recommendation | Priority | Target |
|----|---------------|----------|--------|
| DG-1 | CEO sign-off policy | LOW | 2026-05-31 |
| DG-2 | Establish doc review cadence | MEDIUM | 2026-Q3 |
| DG-3 | Refresh outdated docs (DPIA, etc.) | MEDIUM | 2026-Q3 |
| DG-4 | Annual training cadence | LOW | 2026-Q3 |
| DG-5 | Strengthen action item tracking | LOW | 2026-Q3 |
Aside: cross-section observations
After completing all 6 findings sections, often patterns emerge across sections. Document these.
# Cross-Section Observations
## Theme 1: "Customer-facing well-handled, internal underdeveloped"
Appears in:
- Section 6 (Transparency): user-facing OK, auxiliary decisions gap
- Section 8 (GDPR): Art. 22 OK, internal compliance gaps
- Section 9 (Documentation): customer-facing privacy policy outdated
Underlying cause: prioritization by visibility, not by risk.
## Theme 2: "Setup at creation, neglect during operation"
Appears in:
- Section 4 (Bias): baseline tested but not monitored
- Section 5 (Privacy): retention policy written but not enforced
- Section 9 (Documentation): policies created but not maintained
Underlying cause: One-time mentality. AI compliance is ongoing process.
## Theme 3: "Process exists but follow-through weak"
Appears in:
- Section 4 (Bias): mitigations done but not always verified
- Section 9 (Governance): reviews happen but actions linger
Underlying cause: Lack of follow-through discipline.
## Strategic recommendations
These cross-cutting themes suggest:
1. **Build operational habits**: bias monitoring, retention enforcement, doc updates should be automated/scheduled
2. **Track action items rigorously**: from creation to closure
3. **Audit cycle that catches drift**: this M8 audit is a good template
Trampas comunes
Trampa 1 — Skipping documentation/governance section. "Just process stuff". Auditors look here closely. It's organizational health.
Trampa 2 — Cross-section observations omitted. Each section in isolation = miss patterns. Synthesis adds value.
Trampa 3 — Recommendations sin pattern thinking. Recommending fixes per item but not addressing underlying cause. Address pattern.
Trampa 4 — Treating "compliance done" como achievement permanent. Static thinking. Compliance is process, not state.
Ejercicio
Complete tu report:
- Llené section "Documentation and Governance" para tu sistema
- Identifica 2-3 cross-section themes
- Estructuralos como strategic recommendations
Resumen
Aprendiste:
- ✅ Documentation/governance section structure
- ✅ Common items: policy sign-off, doc currency, training, governance cadence
- ✅ Cross-section observations capturing patterns
- ✅ Strategic recommendations addressing root causes
- ✅ Trampas: skipping, no synthesis, treating as static
Checkpoint: si tu report tiene 6 findings sections + cross-section observations, complete.
Siguiente cápsula
06 — Recommendations y prioritization. Findings identifican gaps. Recommendations prescriben action. Critical to prioritize bien.
Recursos
- Governance Best Practices (PWC) — corporate governance examples.
- Anthropic's audit/review approach — frontier lab governance.
- GitLab handbook — example of transparent docs.