By Quin Rodriguez, VP, Strategy and Innovation, GRC, Riskonnect, Inc.
AI adoption is outpacing AI governance. Organizations are deploying AI across functions, often without a clear view of where it’s used, what risks it creates, or whether the right controls are in place. Regulators increasingly expect companies to demonstrate that those controls work, too. With this, evidence has become the real test of AI governance.
In the classic 1980 comedy Caddyshack, groundskeeper Carl Spackler wages an obsessive, increasingly elaborate war against a single gopher. He sets traps. He floods tunnels. He eventually detonates the entire golf course – and the gopher still wins. His increasingly elaborate efforts fail because he never addresses the problem in a controlled, systematic way.
AI governance can follow the same path. Without clear controls, small gaps can become larger problems as AI use spreads across your organization.
Effective AI governance requires ways to demonstrate that AI systems remain within defined boundaries and that someone’s accountable for them. Nine practical controls can help make that governance visible and provable.
1. Know What You Have: Control Starts with Visibility
Ty Webb could sink a putt blindfolded because he’d already seen the green. AI governance requires the same kind of visibility. Before you can assess risk or put controls in place, you need to know what AI systems and models your organization uses.
Build a living inventory that covers every AI system, whether your teams built it internally, purchased it from a vendor, or adopted it independently. That includes the “shadow AI” that enters the business without formal approval.
Your inventory should capture:
- The model or system name and version
- The business function it serves and who owns it
- The data it consumes and the outputs it produces
- Its risk classification
- Who approved it and when
A complete inventory gives leaders a clear view of the organization’s AI footprint and provides the foundation for the controls that follow. Without that visibility, gaps in oversight can stay hidden as AI use expands.
2. Classify Risk Before You Build (or Buy)
In Caddyshack, the Yacht Club pool serves very different guests with very different risk tolerances. A suspected contamination event is a different problem than a damp towel on the deck.
AI requires the same distinction: Not all AI is equal risk. Your governance framework should match the level of oversight to the potential consequences.
A practical three-tier approach separates low-risk AI that supports routine productivity, medium-risk AI that influences business decisions, and high-risk AI that affects people’s rights, access, safety, or financial outcomes. Each tier should trigger an appropriate level of review and oversight.
| Risk Tier | Examples | Governance Response |
|---|---|---|
| High | HR decisions, credit scoring, medical triage, legal research | Human-in-the-loop required; mandatory audit trail; regular bias testing |
| Medium | Customer service chatbots, content summarization | Periodic review; output monitoring; user feedback loops |
| Low | Internal productivity tools, autocomplete | Baseline logging; periodic spot-checks |
The goal is proportional control. A meme generator doesn’t need the same governance process as an AI system making high-stakes decisions. Treating them the same can make governance unnecessarily burdensome. Focus scrutiny where the consequences demand it.
3. Human Oversight: Keep Someone’s Hand on the Wheel
“I don’t think the heavy stuff is gonna come down for quite a while.” – Carl Spackler (right before it pours)
Overconfidence is the enemy of control. Meaningful human oversight gives people defined opportunities to review, correct, or halt AI-driven decisions before they cause harm.
This means:
- Human-in-the-loop (or HITL) for decisions with material consequences to individuals
- Human-on-the-loop (or HOTL) for automated workflows, where humans monitor and can intervene
- Clear escalation paths, so any employee can flag a concern without fear of being dismissed like a caddy who dares question a member’s swing
Effective oversight also requires clear accountability. Document who is responsible for oversight, when they review the system, and what authority they have to override it. Those three details make human oversight tangible rather than theoretical.
4. Explainability is Evidence of Control
Judge Smails demanded decorum and order. But when pressed on why a rule existed, the answer was usually “because I said so.” That might work at Bushwood. It won’t work in front of a regulator, a board, or an affected customer.
- Explainability is a governance imperative. For every material AI system, you should be able to answer:
- What data was used to train it and whether that data was representative and fairly sourced
- What the model is designed to optimize and whether that objective could conflict with human values
- How it makes decisions and whether those decisions can be explained in plain language to a non-technical audience
- Where it can fail and what limitations users need to understand
Model cards and AI system datasheets provide a structured way to document this information throughout a model’s lifecycle. Think of them as the scorecard for your AI.
5. Bias, Fairness, and Testing
“This is a hybrid… I’ve been workin’ on for about twelve years.” – Carl, on his combination Bill Murray/Dalai Lama spiritual moment.
Twelve years of well-intentioned tinkering can still produce something that explodes on the green. Bias doesn’t announce itself. It can hide in training data, emerge from proxy variables, or surface outcomes that look fair in aggregate while disadvantaging specific groups.
Ongoing bias and fairness testing should include:
- Pre-deployment bias audits across protected characteristics such as race, gender, age, and disability
- Disparate impact analysis that examines whether model performance remains consistent across groups
- Red-teaming to probe for edge cases, unintended behaviors, and other weaknesses
- Post-deployment monitoring to detect drift as models and the environments around them change
A model can perform fairly at launch and produce different results later as its data, users, or operating environment changes. Testing should continue throughout the model’s lifecycle.
6. Data Governance: You Are What You Eat
AI learns from data, and the quality and integrity of that data shape the systems built on top of it. Data governance is AI governance.
Your training and inference data should be:
- Legally and ethically sourced
- Accurate and up-to-date
- Collected with appropriate consent when it includes personal data
- Stored and accessed securely
These practices give organizations a clearer basis for evaluating the systems that rely on their data and managing the risks those systems introduce.
Data governance also requires data lineage: a traceable record of where data came from and where it flows. Think of it as the caddie’s yardage book; every distance, every hazard, every bounce documented, so there are no surprises.
7. Your Response Demonstrates whether you were ever in Control: Have a Plan Before the Pool Turns Brown
The Caddyshack pool scene is a masterclass in what happens when no one has an incident response plan. Panic. Overreaction. Unnecessary evacuation. And a Baby Ruth bar that didn’t deserve the blame.
AI systems will fail. Generative AI models can hallucinate. Outputs will surprise you. Feedback loops will go wrong. When they do, your organization needs a defined process for containing the problem, understanding what happened, and preventing a repeat.
A mature AI incident response plan includes:
- Detection: How you identify that something has gone wrong through monitoring, alerts, or user reports
- Containment: How you limit the damage through model suspension, output filtering, or fallback systems.
- Investigation: How you determine whether the root cause lies in the data, model, prompt, or deployment configuration
- Remediation: What you fix and how you verify that the fix worked
- Communication: Who you notify, when, and what you communicate to customers, regulators, and leadership
- Post-mortem: What you learned and which governance controls need to change
Test the plan before an incident puts it to work.
8. Policies, Accountability, and Culture
“I want to party with you, cowboy.” – Ty Webb
Technology can’t carry AI governance on its own. People need clear responsibilities, leadership needs to reinforce them, and employees need to feel comfortable raising concerns when something goes wrong.
That requires:
- Clear AI policies: Define acceptable use, prohibited applications, and employee responsibilities.
- Defined accountability: Identify the AI risk owner, and establish who participates in AI ethics or review boards.
- Training and awareness: Ensure everyone who uses AI understands their role in governance.
- A speak-up culture: Give employees a clear path to raise concerns about AI systems without fear of retaliation.
Good AI governance depends on people working together and taking responsibility for the systems they oversee. When those expectations are clear, accountability becomes part of how the organization operates.
9. Regulatory Alignment
Every golf course has its own local rules. AI governance works the same way. Requirements vary by jurisdiction and industry, with frameworks and regulations including the EU AI Act, NIST AI RMF, ISO 42001, and sector-specific guidance from financial and health regulators.
A strong governance program should include:
- Mapping your AI inventory to applicable regulatory requirements
- Maintaining documentation that satisfies audit and supervisory requests
- Monitoring regulatory developments and updating your program accordingly
- Engaging legal and compliance as active partners in AI governance, not a final checkpoint
Regulations will continue to evolve. Know which rules apply to your organization and keep the program current as those requirements change.
The Caddyshack lesson, beneath the golf carts and gopher explosions, is deceptively simple: chaos follows when no one owns the problem. Judge Smails had the title of authority. Carl had responsibility for the grounds. Neither had the controls needed to keep the course under control.
AI governance requires that same clarity of ownership and accountability. Leaders should be able to answer basic questions about their AI systems at any time:
- What is being used?
- Why is it being used?
- Who is responsible for it?
- What happens when it fails?
- Can the organization intervene?
That’s what credible AI governance looks like: clear evidence that AI is understood, accountable, monitored, and controlled.
For more on AI governance, read the article, AI Governance: 5 Ways to Embed AI Oversight into GRC and check out Riskonnect’s AI Governance solution.


