Governing AI without slowing the business
The AI governance committee has spent six weeks reviewing a case any analyst would clear in two days. Nobody calls that slowing the business down. It is exactly that, and nobody has measured it.
Carlos Andrés Ramírez ·
The AI governance committee has spent six weeks reviewing a case any analyst would clear in two days. Nobody calls that slowing the business down. It is exactly that, and nobody has measured it.
Every AI governance committee I have sat through opens with the same promise. Classify by risk tier, and low-risk work moves fast while high-risk work gets real scrutiny. It reads clean on the first slide. Six months later, everything routes through the same committee, on the same schedule, and nobody remembers who decided this particular case was low, medium or high risk in the first place. The taxonomy died in the meeting where it got approved.
The problem isn't the idea of tiering by risk. It's treating it as a principle on a slide instead of a process with an owner, a deadline, and someone who classifies each case the day it lands. Without that, governing by risk is a phrase said in the steering committee and one more line in an approval queue nobody prioritizes.
The symptom
How do you govern AI without slowing the business down?
The answer circulating in almost every consulting deck says the same thing: govern by risk tier, wave through the trivial cases fast, slow down for the critical ones. It's correct, and it's useless without two pieces almost nobody writes down: who classifies each case the day it arrives, and how long the committee actually takes to decide. Without those two, the risk framework is a nice poster over a real bottleneck.
- The case enters the general queue even when anyone in the room could tell, just by looking, that it's low risk.
- Nobody has the authority to classify a case without convening the full committee, so even the trivial ones wait their turn.
- The committee meets every three weeks, and that calendar sets the pace of the business more than any risk analysis does.
- The team that built the case starts polishing the write-up so it slides into the fast lane, and nobody audits that classification.
- The business stops asking for permission and uses the case anyway, while the committee is still meeting to discuss something already settled in practice.
The problem underneath
The committee that never times its own delay is the one slowing things down the most, and the one that knows it least.
An AI governance committee thinks of itself as a quality filter. It never measures itself as a queue. And every queue has a transit time whether anyone tracks it or not. If nobody tracks it, the transit time gets set by the committee's own calendar, not by the case's urgency or its actual risk. That's the blind spot. Governance doesn't slow the business down through excess rigor. It slows it down for lack of a deadline nobody has been willing to put in writing.
And here is the uncomfortable part almost nobody says out loud in the steering committee: writing down a deadline (three days for low risk, two weeks for high risk) forces an admission that no such deadline exists today, and that the real turnaround depends on how full the chair's calendar happens to be. It is more comfortable to keep talking about risk culture than to set a number somebody can publicly miss.
A committee that doesn't measure how long it takes to decide isn't governing risk. It's governing the chair's calendar.
BECOME
The framework
What does it take for risk to clear fast without slowing everything else down?
- Classifier
- Whoever decides a case's risk tier the same day it's proposed, without waiting to convene the full committee. If classifying requires everyone in the room, classification itself becomes the first bottleneck.
- Tiers with examples
- Three or four risk tiers defined with the company's own real cases, not with abstract categories borrowed from a generic framework. High risk without an in-house example is a label every team interprets differently.
- Decision deadline
- The written maximum time between a case entering review and coming out with a yes or a no. Without that number, the committee sets the business's pace with its own calendar, and nobody can push back on it.
- Fast lane
- An approval path for low risk that doesn't route through the full committee: someone with delegated authority signs off alone, and the committee audits a sample afterward, not beforehand.
- Exception log
- Every time the business acts without waiting for full approval because the deadline lapsed. That log is the proof the deadline is real, not just a line in a document.
None of the five decisions requires hiring anyone or buying a tool. It requires the committee to measure itself with the same rigor it applies to the risk it reviews. A committee that doesn't know how long it takes to decide can't claim it governs without slowing things down, because it has never checked whether that's true.
Take the last ten cases that went through the committee and time each one, from the day it entered to the day it came out with a decision. If nobody has that number on hand, there is no AI governance. There is a recurring meeting everyone calls governance because it sounds better than a queue.
Frequently asked questions
How do you govern AI without slowing the business down?
By classifying every case by risk tier the same day it's proposed, using a taxonomy written with the company's own real examples, and setting a maximum decision deadline for each tier. Low risk needs a lane that skips the full committee, and high risk needs a deadline the committee holds itself to as strictly as it holds the business.
Why does an AI governance committee end up slowing the business down even when nobody decides that on purpose?
Because nobody measures how long the committee itself takes to decide, so the pace of approval gets set by the meeting calendar instead of the actual risk of each case. A trivial case waits in the same queue as a critical one, and that unmeasured wait is what the business experiences as friction, even while the committee believes it is being diligent.
Who should be able to classify the risk of an AI case without convening the full committee?
Someone with delegated authority and a written standard, not the team that built the case, because whoever built it has an incentive to call it low risk and skip the review. The committee audits a sample of those calls afterward instead of reviewing every one beforehand, so low risk can move without waiting its turn.
What happens when an AI governance committee misses its own decision deadline?
The business stops asking permission and proceeds anyway, because waiting indefinitely costs more than the risk of getting it wrong. That is the moment governance stops functioning in practice while it still exists on paper, and no committee finds out until it reviews a case that has already been running for months without ever going through it.
Let's design your governance framework
From the idea to the operation
Scaling under control means deciding limits, oversight and traceability first. Adding them later means rebuilding.
About the author
Carlos Andrés Ramírez — Transformation Director
Specialist in business transformation and reinvention. Director of Specialised Programmes and lecturer in Artificial Intelligence at UPC's Graduate School.