Where AI governance engineering sits

Where AI governance engineering sits An architecture diagram generated by Archify. AI compliance / legal · interprets obligations · Governance functions AI compliance / legal interprets obligations Responsible AI / ethics · sets values & principles · Governance functions Responsible AI / ethics sets values & principles AI safety research · studies models in principle · Governance functions AI safety research studies models in principle GRC engineering · the parent discipline · Governance functions GRC engineering the parent discipline MLOps / LLMOps · builds, deploys, serves · Build & run MLOps / LLMOps builds, deploys, serves AI Governance Engineering · governance as engineered systems · Build & run AI Governance Engineering governance as engineered systems AI security engineering · the sibling, defends · Build & run AI security engineering the sibling, defends AI systems & agents · the object, in production · Architecture component AI systems & agents the object, in production Model risk management · validates models (SR 11-7) · Architecture component Model risk management validates models (SR 11-7) Audit-ready evidence · machine-readable proof · Architecture component Audit-ready evidence machine-readable proof Auditors / regulators · read & query the proof · Architecture component Auditors / regulators read & query the proof obligation → control values → controls consumes research AI specialisation defended system as input gates the pipeline builds & serves governs continuously validates the model emits runtime evidence audit is a query Governance functions Build & run Legend Backend Database Cloud Security External

The definition

  • • Engineering practice applied to the governance of AI systems
  • • A capability, not a job title
  • • Measured by realised risk reduction and audit-ready evidence

Distinct from its neighbours

  • • Governs what MLOps ships; gates the same pipeline
  • • Extends model risk management to runtime and agents
  • • Sibling of AI security engineering, often the same person

The object and the proof

  • • Models, systems, agents, data and the organisation
  • • Agents acting under delegated authority are the hardest object
  • • Evidence an auditor or regulator can query, not a screenshot