Approaches for Implementing Governance Strategies
Five governance approaches
The story: A hospital introducing a new robot surgeon:
- Writes clear rules for when the robot can be used, who supervises it, and how its work is checked, and updates them each year.
- Holds regular reviews: monthly for risky procedures, less often for routine ones, with doctors, lawyers, and patient representatives.
- Reviews both the technical side (is it accurate and reliable?) and the ethical side (is it fair and legal?), tests before each new use, and sets clear rules for when a human surgeon takes over.
- Publishes what the robot can and can't do, and gives patients a way to give feedback.
- Trains staff on fairness and safe use, gets departments working together, and keeps certifications current.
In AI/AWS terms:
- Policies: clear policies on the organization's approach to generative AI, covering data management, training, output validation, safety, human oversight, IP, bias, and privacy. Review them regularly.
- Review cadence: regular technical, legal, and responsible AI reviews, for example monthly, quarterly, or twice a year depending on risk, with diverse stakeholders.
- Review strategies: technical reviews (performance, data quality, robustness) and non-technical reviews (policy, ethics, regulation), testing before deployment, and clear rules for when to intervene.
- Transparency standards: publish information about models, training data, and key decisions. Document capabilities, limitations, and intended use. Give stakeholders a feedback channel.
- Team training: bias mitigation and responsible AI training, cross-functional collaboration, ongoing certification.
For the exam: The five governance approaches are policies, review cadence, review strategies, transparency standards, and team training.
Monitoring an AI system
The story: Separate from those policies, the hospital's technicians watch the robot's daily readings: how accurate and fast it is, how hot its motors run, whether it treats some patient groups differently, and whether it stays within the rules.
In AI/AWS terms: These are operational practices, separate from the governance approaches above:
- Performance metrics: accuracy, precision, recall, F1, latency
- Infrastructure: CPU, GPU, memory, network, storage, logs
- Bias and fairness, especially in healthcare, finance, and HR
- Compliance and responsible AI
For the exam: Monitoring metrics are operational practices, not one of the five governance approaches.
Generative AI Security Scoping Matrix
The story: Five ways to get a meal, from least to most responsibility:
- Eat at a public food court.
- Your company contracts a catering service that delivers to the office.
- Buy a ready-made meal kit and cook it at home.
- Buy the meal kit but change the recipe with your own ingredients.
- Grow your own vegetables and cook from scratch.
The more you do yourself, the more you're responsible for food safety.
In AI/AWS terms: The Generative AI Security Scoping Matrix classifies an application into one of five scopes, from least to most ownership:
| Meal | Scope | You... | Example |
|---|---|---|---|
| Food court | 1. Consumer app | Use a public generative AI service | A public chatbot |
| Office catering | 2. Enterprise app | Use a third-party business app with generative AI built in, under a business agreement | A scheduling app that drafts agendas |
| Meal kit | 3. Pre-trained models | Build your app on an existing FM | An app calling a model in Amazon Bedrock |
| Adjusted meal kit | 4. Fine-tuned models | Fine-tune an existing FM with your data | A model tuned on your support tickets |
| Grow your own | 5. Self-trained models | Train a model from scratch on your data | Your own FM |
For each scope, the matrix covers four security disciplines: governance and compliance, legal and privacy, risk management, and controls and resilience.
- Controls are security measures that reduce risk, such as controlling who can use which FMs and who can reach inference endpoints.
- Resilience means staying available and meeting SLAs, for example by checking each service is available in your Region.
For the exam: Scope 3 = using an FM like Bedrock as is. Scope 4 = fine-tuning. Scope 5 = training from scratch. The four disciplines: governance and compliance, legal and privacy, risk management, controls and resilience.