Back/Operations/ChatGPT
IntermediateOperations

How to Create an AI Governance Framework and Tool Library for Your Company

Create one maintained source of truth for approved AI tools, data rules, access, and experiments, using a baseline survey to focus governance on the questions employees actually have.

How to Create an AI Governance Framework and Tool Library for Your Company

Brian measures AI sentiment and policy awareness, then shows Pendo’s cross-functional AI Knowledge Center with approved tools, data-sharing rules, access instructions, and a fast request path.

Before you start

What you need

  • Baseline employee feedback about AI use and uncertainty
  • Legal, security, IT, finance, procurement, and business owners
  • An inventory of current and requested AI tools
  • Company data classifications and handling rules
  • An intranet or knowledge-base owner

What you’ll make

A current AI knowledge center that tells employees what each tool may be used for, what data it may receive, how to get access, and how to request a new evaluation.

Tools used

Step by step

The workflow

Follow the sequence once, then adapt the prompts, checks, and handoffs to your own setup.

6 steps

Step01

Measure Baseline Sentiment and Awareness

Run a short anonymous baseline survey on current tools, frequency, sentiment, policy awareness, data uncertainty, and blocked use cases. Segment results only where anonymity remains protected.

Example prompt
Draft a 7-question anonymous baseline survey covering AI tool use, frequency, confidence, perceived value, policy awareness, uncertainty about data handling, and one blocked use case. Use neutral wording and include “not sure” where appropriate.
Step02

Identify Key Knowledge Gaps

Turn the results into a ranked list of governance gaps, such as unclear customer-data rules, unknown approved tools, personal-account use, or slow access. Publish the baseline and the questions the program will answer.

Step03

Collaborate with Cross-Functional Stakeholders

Form a working group with legal, security, IT, finance, procurement, privacy, and business representatives. Assign one accountable owner and decision rights for tool approval, data rules, and exceptions.

Example prompt
Draft a concise email to invite representatives from our Legal, Security, IT, and Finance departments to a new cross-functional working group. The purpose of this group is to create [company name]'s first official AI governance policy and tool guidelines. The email should explain the goal is to enable safe and effective AI use, state the expected time commitment (e.g., one 60-minute meeting per week for the next month), and ask them to nominate a representative from their team. Keep the tone collaborative and proactive.
Step04

Build a Centralized AI Knowledge Center

Build the knowledge center around a structured tool inventory: purpose, owner, approval status, licensed plan, permitted data, prohibited data, retention or training terms, integrations, access steps, and review date.

Step05

Define Clear Data-Sharing Guidelines

Define company data tiers and map each tool to allowed examples. Include plain-language cases for public, internal, confidential, customer, personal, regulated, and source-code data.

Step06

Create a Process for New Tool Requests

Create a request path for access, experiments, and new tools with required use case, data, integrations, users, cost, and urgency. Show status and service level, then repeat the baseline survey after the program has run.

Example prompt
New AI tool request
Use case and expected value: [ ]
Users and duration: [ ]
Data types involved: [ ]
Required integrations and permissions: [ ]
Vendor and model: [ ]
Retention or training settings: [ ]
Cost and owner: [ ]
Requested decision date: [ ]

What good looks like

  • Every tool has an owner, approval status, permitted data tier, and review date.
  • Employees can distinguish personal experimentation from approved company use.
  • New-tool requests have a visible status, reviewer, and target response time.
  • Repeat surveys show whether policy and tool awareness improves.

Build your next product with ChatPRD

Turn an idea into a PRD, user stories, and a plan.

Try ChatPRD free

After the steps

Runbook notes

How to recover when the loop fails and where human judgment helps.

Recover

If it goes sideways

The policy says to use AI safely without defining safe data or tools
Map company data classes to concrete allowed and prohibited examples for each approved tool.
The tool table becomes outdated as products and contracts change
Assign owners and review dates, and trigger re-review on material model, terms, retention, or integration changes.
A slow request path pushes employees toward personal accounts
Publish service levels, offer a fast sandbox path for low-risk trials, and explain why a request is pending or denied.
The baseline misses actual unapproved usage
Use an anonymous survey, separate learning from enforcement, and combine self-report with privacy-respecting license and access data.

Start shipping
better products.

Join 100,000+ product managers who use ChatPRD to write better docs, align teams faster, and build products users love.

Free to start
No credit card
SOC 2 certified
Enterprise ready