AI Governance

Governance that stays current, tied to what actually runs.

For each AI system and each vendor, one page answers what it is, who owns it, how it was assessed, who approved it, under what conditions, until when, and what has changed since.

The model

Six separate records. On purpose.

A completed assessment is not an approval. A classification is not a field on an assessment. Keeping them apart is what makes each one auditable.

01

AI system

The inventory record: name, owners, purpose, vendor, models, linked agents and MCP servers. Observed in traffic or declared by a person.

02

Assessment

Answers to a versioned questionnaire. Every answer is kept with who gave it and when, and records the hash of the exact question answered.

03

Risk classification

A level, the rules version, the facts read and the reason for each factor. Only an administrator can override, with a reason.

04

Privacy review

A reviewer's decision, findings, conditions and the organisation's own DPIA position. It is not a DPIA.

05

Security review

Six areas rated, from access to tool and MCP access. Exceptions always carry an expiry date. It is not a certification.

06

Approval

An administrator's decision on a request, with a reason, conditions and an end date at most three years ahead.

Separation of duties

The approver is never the requester.

An operator or administrator requests. A different administrator decides. The two are compared on a stable operator id, so renaming an account does not get round it.

  • A request needs its prerequisites. A current classification, every required review decided without objection, and an approved vendor where one is required. A refused request lists every missing piece.
  • The basis is pinned. Classification, source assessment, reviews, vendor approval and a snapshot of the inventory fields that matter.
  • Approval checks the basis again. If anything changed since the request, approval is refused.
  • The server enforces roles. Hiding a control in the console is not the check.

Governance status

One status per system and vendor. No score.

The status is derived by a fixed precedence, and the parts it was derived from are always shown beside it. Missing information stays missing.

StatusMeaning
Not assessedNo baseline assessment has been completed. Never shown as low risk.
Classification requiredNot classified, or the classification is out of date.
Ready for approvalEverything required is in place and nobody has asked.
Pending approvalA request is waiting for a decision.
ApprovedA granted approval holds.
Review requiredA granted approval is questioned, or a required review is missing or out of date.
Approval expiredA granted approval passed its end date.
Evidence mismatchA stored decision does not match the evidence record that made it. Shown above everything else.

When facts change

Nothing is revoked automatically. Nothing is approved automatically.

MERIDVAR cannot reliably tell whether a change is material. It says an approval needs review, and says why. A person then decides: renew or revoke. Every earlier decision stays readable.

An approval reads "review required" when

  • the classification changed or is out of date
  • a newer, objecting or out of date review exists
  • the vendor approval no longer holds
  • an inventory field in the pinned snapshot changed
  • the system was retired

Where it fits

The AI record your wider programme can rely on.

Beside your GRC platform

MERIDVAR is the AI specific system of record. It supplies inventory, decisions and evidence to the enterprise risk programme you already run.

A faithful record

MERIDVAR records the decisions people make and the facts they state, with who and when, in a log where any later edit is detectable.

People stay accountable

Every approval is a named person's decision. Legal and regulatory determinations remain with the organisation and its counsel.

See MERIDVAR refuse a request on your own network.

A working session with the founder. We install the appliance with you, route a test request and walk through the evidence it leaves behind.