top of page

Why This AI Governance Article Deserves Your Attention

AI Governance Policy Benchmarking

In the consulting world, the instinct is almost always to treat another firm or industry voice as competition. I've watched it happen more times than I can count: someone puts out solid work, and the reaction from the rest of the field is to dismiss it, ignore it, or quietly borrow it without ever saying where it came from. This article does the opposite.


I want to publicly recognize the value of a piece published by the Internal Audit Collective, written by Tom O'Reilly: "How to Do an AI Governance Review: What Are the Key Components of an AI Governance Policy?" We read it. We sat with it. And frankly, it's some of the most practical, well-organized guidance on AI governance policy I've come across from anyone in this space.


At Efficient Advice, LLC, one of the solutions we build for clients (auditors, compliance teams, risk-adjacent professionals across the US and Latin America), is an AI governance policy package. It's core to what we do. When a resource like this lands in front of me, I don't just skim it and move on. I test it.


O'Reilly's article laid out 20 core components that a comprehensive AI policy should address: purpose, scope, definitions, governance and accountability, risk classification, data privacy, security, human review, fairness, disclosure, inventory, training, third-party management, compliance monitoring, incident response, exceptions, ownership and change management - and more. It's a checklist pulled from a real practitioner experience within the Internal Audit Collective's community, not a theoretical exercise.


I took that list and ran it directly against our standard AI governance policy templates. Line by line. No shortcuts.


Here's what I found: we fully capture 18 of the 20 components. The other two were partially addressed, and one of those two is a component the article itself flags as optional (the AI development lifecycle controls, which apply only to organizations building their own AI models rather than deploying third-party tools). In practice, our coverage is stronger than the raw number suggests.


That's a meaningful benchmark, and I'm grateful to have had it to measure against. It's easy to believe your own materials are thorough. It's another thing entirely to hold them up against an independent, well-researched standard and see where the gaps actually are. That's the value of work like this — it doesn't just inform, it holds the rest of us accountable to a higher bar.


The Internal Audit Collective is also releasing a full 50-page eBook, the AI Governance Playbook for Internal Audit, later this month, with real-world examples from more than 50 practitioners. That's the kind of resource our profession needs, built by people doing the work, for people doing the work.


Here is my honest takeaway: if you're building or reviewing an AI governance policy and you haven't read this piece, stop what you're doing and read it. Then run your own materials against it, the way we just did. You might be surprised by what you find, in either direction.


Credit belongs where credit is earned. This is one of those cases.

Comments


bottom of page