HomeTemplates › AI Use-Case Governance Register

AI Use-Case Governance Register

From the FDE Toolkit appendix of GenAI for Business. Free to copy and adapt with attribution.

Chapter 13's obligations become operational through one unglamorous artifact: a register with a row for every AI use case, filled in at intake and updated at each review. Ten fields cover what boards, auditors, and (for EU-touching deployments) regulators ask.

Template A.4: AI Use-Case Register Fields
#FieldThe question it answers
1Use case & ownerWhat does it do, and who is accountable by name?
2Autonomy classAssistant, Automation, or Agent (Chapter 7 behavioral test)? What actions can it take alone?
3Data touchedPersonal data? Confidential data? Which tier of vendor agreement covers it?
4EU AI Act tierProhibited / high-risk / limited / minimal, and in which jurisdictions it operates (incl. US state exposure).
5Injection surfaceDoes it process untrusted content? Does the lethal trifecta apply (Chapter 3)?
6Eval & pass rateLink to the A.2 eval; current pass rate; date last run.
7Human oversightWhere is the human in the loop, and what do they see when overriding?
8MonitoringWhat is logged, who reviews it, on what cadence, and what triggers escalation?
9LabelingIs output disclosed as AI-generated where required (EU transparency, China labeling rules)?
10Review & sunsetNext scheduled review; conditions for decommissioning.

Run intake as a fifteen-minute conversation, not a compliance ambush: the goal is that filling the row is easier than avoiding it. A register like this is also the fastest possible answer to the two questions executives increasingly face from boards: "where are we using AI?" and "how do we know it is behaving?" If Chapter 14 gave you the offense, this page is the defense, and organizations that run both are the ones for which the technology compounds instead of surprises.

This template is part of the FDE Toolkit in GenAI for Business. The method behind it is in Chapter 14: Working Like a Forward Deployed Engineer.