21 pages
Momento Media AI Governance Policy
AI Governance Policy
Purpose: Set the rules for how a small creative company uses generative AI on client work.
Setting: Momento Media, my own company, as the case study.
Context: Momento Media uses generative AI on client campaigns, and I wanted to see what real governance looks like for a company that size: named owners and clear approval paths, without pretending there is a compliance department.
Scope:
- 11 sections covering risk tiers, approval paths, data and model controls, monitoring, incidents, procurement, exceptions and review
- 6 appendices: a model card, a risk assessment, an audit checklist, two forms, and a crosswalk to NIST AI RMF and ISO/IEC 42001
- Three risk tiers that decide who approves each use case
- One worked example running through it all: a custom image-generation model for a skincare brand
What this demonstrates:
- Draft policy language a small team can enforce
- Design role-based accountability with independent audit
- Set approval thresholds for spend and data
- Map internal rules to external frameworks
Deliverable: 21-page policy, v1.0, effective 30 July 2026, reviewed quarterly.