Context
A pan-European enterprise with five autonomous business divisions was running 47 AI initiatives with no central visibility, inconsistent risk assessment, and no clear accountability when issues arose. The board had mandated an AI governance structure ahead of EU AI Act implementation deadlines.
Prior attempts at centralized governance had failed due to divisional resistance and process overhead. The question was not whether to build a Program Office — it was how to build one that divisions would actually use.
Approach
Phase 1 · Weeks 1–2
Diagnostic
Stakeholder interviews across all five divisions, inventory of 47 active AI initiatives, failure mode analysis of the previous governance attempt, and identification of 12 high-risk systems requiring immediate attention.
Phase 2 · Weeks 3–4
Operating Model Design
Program Office charter, RACI matrix across eight roles, three-track review process (fast/standard/extended based on risk tier), intake form and scoring methodology, and documented escalation paths and decision rights.
Phase 3 · Weeks 5–6
Portfolio Architecture
Standardized initiative data model, portfolio health metrics, division-level reporting templates, board quarterly review format, and incident classification and response protocol.
Phase 4 · Weeks 7–8
Change Management & Launch
Division lead onboarding workshop design, communication plan for initiative owners, 90-day adoption monitoring plan, and vendor evaluation framework for third-party AI procurement.
Program Office Simulator
The governance process designed in this engagement is reproduced here as a working simulator. Use the intake form to classify a new AI initiative, review the live portfolio of eight governed initiatives, and step through a governance decision for a high-risk system — the same three workflows that the Program Office runs in production.
New Initiative
Submit an AI initiative for Program Office review and risk classification.
Technical Depth
Decision 1
Why three review tracks instead of one
Single-track governance fails because low-risk initiatives get stuck behind high-risk ones, creating backlog and divisional resistance. Three tracks (2/6/12 weeks) preserve speed for low-risk work while ensuring rigor where it matters. The fast track alone reduced projected review wait time for minimal-risk initiatives by more than 70%.
Decision 2
Why the Program Office reports to the CDO, not the CRO
Risk-first governance creates a compliance mindset that slows value creation. CDO ownership positions the Program Office as an enabler of AI investment, not a gatekeeper — critical for divisional adoption. The previous governance attempt failed partly because it was perceived as a control function.
Decision 3
Why change management was 25% of the engagement scope
The previous governance attempt failed not because the framework was wrong but because division leads were not involved in its design. Co-creation workshops and clear WIIFM (what's in it for me) messaging for each division were the actual unlock — not the RACI or the process flow.