CDAIO Playbook
Governance & Trust

Play for level 2: Establishing

Set up a risk-tiered AI review

When to run it
When one review board slows every project
Who is in the room
Risk, legal, security, data protection officer
What you leave with
Three risk tiers with approval paths
Time
Half a day

Steps

  1. Classify current use cases, including against the EU AI Act categories.
  2. Define three tiers with clear entry criteria.
  3. Assign an approval path and a target turnaround per tier.
  4. Pre-approve standard patterns so low-risk work moves without review.

See this level on the map