03Four-Question AI Governance Baseline

Listen to this framework

Four Diagnostic Questions for AI Governance

0:00
03

Four-Question AI Governance Baseline

Derived from the governance framework applied across Singapore IMDA, Saudi NDMO, and Oman TRA regulatory environments at Meinhardt Group. Referenced in the Group Annual Sustainability Report.

Most organisations treating AI governance as a documentation exercise discover the gap when something goes wrong. The four questions below are diagnostic, not procedural: they expose structural governance gaps before deployment, not after incident. The complexity of the deployment is irrelevant. The questions are the same whether you are deploying across three regulatory jurisdictions or adding a single AI assistant to one team.

Four faces, nothing more
Q1

What can it do without asking you?

Maps the scope of autonomous action. Every action the AI system can take without human approval must be explicitly defined, not assumed to be limited. Gaps in this list are gaps in your governance. For agentic systems, this includes read access, write access, external communications, and financial commitments.

Q2

Who checks the output?

Names a human: not a team, a role, or a process, but a named person accountable for reviewing AI output before it produces consequences. "The system checks itself" is not an answer. If nobody is named, governance does not exist regardless of what the policy document says.

Q3

What happens when it is wrong?

Documents the error response procedure before the first error occurs. Covers: who is notified, what is reverted or corrected, how the incident is logged, who has authority to suspend the system, and what constitutes a reportable event under applicable regulatory frameworks. Absence of a documented procedure means the first error will be handled inconsistently.

Q4

Can your staff still do this manually?

Tests operational resilience. AI system failures, regulatory suspensions, or model updates can remove capability without warning. If staff cannot perform the task manually, the organisation has created a critical dependency without a fallback. This is a governance risk in regulated environments and an operational risk in any environment.

Application: Run these four questions against every active or planned AI deployment in your organisation. Any deployment that cannot answer all four is not governed. It is running on trust. For multi-jurisdiction deployments, apply the questions against each regulatory environment separately, then identify the common governance floor that satisfies all of them simultaneously.

What are the four AI governance questions?

What can it do without asking you, who checks the output, what happens when it is wrong, and can your staff still do this manually. They are diagnostic, not procedural, and apply whether the deployment spans three regulatory jurisdictions or adds one AI assistant to one team.

Why does someone need to be named, not a team?

"The system checks itself" or "the team reviews it" is not an answer. If no single person is accountable for reviewing AI output before it produces consequences, governance does not exist regardless of what the policy document says.

Does this apply to small AI deployments too?

Yes. The complexity of the deployment is irrelevant to the four questions. A single AI assistant added to one team needs the same answers as a multi-jurisdiction agentic rollout, just at a smaller scale.

How does this work across multiple regulatory jurisdictions?

Apply the four questions against each regulatory environment separately, then identify the common governance floor that satisfies all of them simultaneously. This baseline has been applied across Singapore IMDA, Saudi NDMO, and Oman TRA environments.

Terence Kok
Before You Go

Q2 is the one people try to talk their way out of. Everyone's happy to write down what the system can do and what happens when it breaks, but naming one person, not a team, not a process, to actually check the output makes the accountability real in a way a policy document doesn't. I've watched good engineers get uncomfortable at that question, which tells me it's the right one. If you can't name the person, that's not a paperwork gap. That's the actual governance gap. Naming them fixes more than any audit does.

Terence Kok