AI Governance
Governance that stays current, tied to what actually runs.
For each AI system and each vendor, one page answers what it is, who owns it, how it was assessed, who approved it, under what conditions, until when, and what has changed since.
The model
Six separate records. On purpose.
A completed assessment is not an approval. A classification is not a field on an assessment. Keeping them apart is what makes each one auditable.
01
AI system
The inventory record: name, owners, purpose, vendor, models, linked agents and MCP servers. Observed in traffic or declared by a person.
02
Assessment
Answers to a versioned questionnaire. Every answer is kept with who gave it and when, and records the hash of the exact question answered.
03
Risk classification
A level, the rules version, the facts read and the reason for each factor. Only an administrator can override, with a reason.
04
Privacy review
A reviewer's decision, findings, conditions and the organisation's own DPIA position. It is not a DPIA.
05
Security review
Six areas rated, from access to tool and MCP access. Exceptions always carry an expiry date. It is not a certification.
06
Approval
An administrator's decision on a request, with a reason, conditions and an end date at most three years ahead.
Separation of duties
The approver is never the requester.
An operator or administrator requests. A different administrator decides. The two are compared on a stable operator id, so renaming an account does not get round it.
- A request needs its prerequisites. A current classification, every required review decided without objection, and an approved vendor where one is required. A refused request lists every missing piece.
- The basis is pinned. Classification, source assessment, reviews, vendor approval and a snapshot of the inventory fields that matter.
- Approval checks the basis again. If anything changed since the request, approval is refused.
- The server enforces roles. Hiding a control in the console is not the check.
Governance status
One status per system and vendor. No score.
The status is derived by a fixed precedence, and the parts it was derived from are always shown beside it. Missing information stays missing.
| Status | Meaning |
|---|---|
| Not assessed | No baseline assessment has been completed. Never shown as low risk. |
| Classification required | Not classified, or the classification is out of date. |
| Ready for approval | Everything required is in place and nobody has asked. |
| Pending approval | A request is waiting for a decision. |
| Approved | A granted approval holds. |
| Review required | A granted approval is questioned, or a required review is missing or out of date. |
| Approval expired | A granted approval passed its end date. |
| Evidence mismatch | A stored decision does not match the evidence record that made it. Shown above everything else. |
When facts change
Nothing is revoked automatically. Nothing is approved automatically.
MERIDVAR cannot reliably tell whether a change is material. It says an approval needs review, and says why. A person then decides: renew or revoke. Every earlier decision stays readable.
An approval reads "review required" when
- the classification changed or is out of date
- a newer, objecting or out of date review exists
- the vendor approval no longer holds
- an inventory field in the pinned snapshot changed
- the system was retired
Where it fits
The AI record your wider programme can rely on.
Beside your GRC platform
MERIDVAR is the AI specific system of record. It supplies inventory, decisions and evidence to the enterprise risk programme you already run.
A faithful record
MERIDVAR records the decisions people make and the facts they state, with who and when, in a log where any later edit is detectable.
People stay accountable
Every approval is a named person's decision. Legal and regulatory determinations remain with the organisation and its counsel.
See MERIDVAR refuse a request on your own network.
A working session with the founder. We install the appliance with you, route a test request and walk through the evidence it leaves behind.