The governance operating model
Board, committee and the three lines around one set of gates, with the AI governance engineer in the second line and evidence flowing to audit and the board.
Text alternative
The board, the governing body, sets AI risk appetite and the AI policy, and reads a few indicators computed from live systems rather than self-reported: KPIs that say whether the program is doing its job and KRIs that say whether risk is moving towards the edge of appetite. The AI governance committee decides what the gates cannot (risk acceptance, exceptions, value trade-offs and policy), and its exceptions reach the gates as data. The second line (risk, compliance, privacy, security and AI governance) sets method and policy, builds the paved path and challenges first-line ratings; the AI governance engineer usually sits here, building the gates, the registry and the evidence path the first line runs. The first line (product owners, engineering and operators) builds and runs systems inside the gates and owns their risks. The gates (Layer 01 Govern-as-Code) enforce, and the evidence they leave (registry entries, eval results, runtime logs and verdicts) lands in the evidence store (Layer 05 Assurance & Continuous Compliance). The third line, internal audit, gives independent assurance by testing the gates, not the documents about them: it re-performs policy decisions for a sample of releases from the stored inputs, hunts bypasses and checks exception hygiene. The model describes roles, not boxes on an org chart; the committee decides, the gates enforce.
Download
Every file carries the attribution band "aigovernanceengineer.com · CC BY 4.0 · v0.5.0" inside the image, and the version is in the file name, so a copy always says where it came from and which edition it shows. The SVGs keep the text live: the first follows the viewer's light or dark setting, the other two fix one theme for slides and print. The PNGs are drawn with the site's own typefaces.
Reuse and credit
The figure is published under CC BY 4.0: you may copy, share and adapt it, commercially too, provided you give appropriate credit, link to the licence and say if you changed it. Keep the attribution band in the image. A credit line that covers title, author, source and licence:
“The governance operating model” by Jorge García Aibar, aigovernanceengineer.com (https://aigovernanceengineer.com/figures/governance-operating-model), v0.5.0. Licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/).
Embed with HTML
<figure>
<img src="https://aigovernanceengineer.com/downloads/figures/governance-operating-model-v0.5.0-light-1600.png" alt="Board, committee and the three lines around one set of gates, with the AI governance engineer in the second line and evidence flowing to audit and the board." width="800" height="1108" loading="lazy">
<figcaption>
<a href="https://aigovernanceengineer.com/figures/governance-operating-model">The governance operating model</a> by Jorge García Aibar,
aigovernanceengineer.com, v0.5.0.
Licensed under <a href="https://creativecommons.org/licenses/by/4.0/">CC BY 4.0</a>.
</figcaption>
</figure> Embed with Markdown

*[The governance operating model](https://aigovernanceengineer.com/figures/governance-operating-model) by Jorge García Aibar, aigovernanceengineer.com, v0.5.0. Licensed under [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/).*