Governance Resources

  • Executive Liability Brief in AI Deployments

    Executive Liability in AI Deployments: What Boards Need to Know FairByDesign | 2025 Introduction Boards of directors and senior executives increasingly face direct liability for how their organizations deploy artificial intelligence (AI). Regulators are making it clear that governance failures in AI are not just technical lapses but leadership failures. Executives cannot delegate all…

  • Bias and Safety Testing Method

    FairByDesign Bias & Safety Testing Method(v1.0, 2025) Bias and safety testing ensures AI agents operate within acceptable ethical and compliance boundaries. Mercury applies structured scenarios, measurable acceptance criteria, and reproducible methods to demonstrate readiness for regulators and boards. 1. Purpose Bias & safety testing validates that AI agents: Treat users consistently across demographic, regional,…

  • AI Governance Readiness Checklist

    AI Governance Readiness Checklist FairByDesign | 2025 Introduction Before engaging in a formal audit, organizations benefit from a quick self-assessment of their readiness for AI governance. This checklist is designed to help teams at any knowledge level identify where they stand. It does not replace an independent audit but provides a clear baseline for…

  • Hitl-sop

    Human-in-the-Loop & Escalation SOP FairByDesign | 2025 Introduction Human oversight is a cornerstone of responsible AI deployment. No AI system should operate without defined escalation pathways that allow humans to intervene in real time. This Standard Operating Procedure (SOP) describes how human-in-the-loop (HITL) oversight is designed, tested, and maintained for AI agents. The EU…

  • Logging-Retention

    Logging & Retention Policy FairByDesign | 2025 Introduction Effective logging and retention practices are critical for ensuring AI systems are transparent, auditable, and compliant with regulatory expectations. Logs provide the evidence needed to demonstrate accountability, while retention policies ensure that data is stored only as long as necessary and deleted when no longer required.…

  • Model Card template

    Model Card & Change Log Template FairByDesign | 2025 Introduction Model cards and change logs provide transparency into how AI systems are designed, deployed, and updated. A model card describes the system’s purpose, data, and performance, while the change log tracks updates over time. Together, these artifacts demonstrate lifecycle accountability, which is emphasized in…

  • Evidence Journal Template

    Evidence Journal Template FairByDesign | 2025 Introduction An evidence journal provides a structured way to record findings during AI audits. It captures what was tested, what evidence was observed, and whether the result met expectations. Maintaining such a journal demonstrates defensible governance and supports repeatable audit cycles (NIST, 2023; ISO, 2023). How to Use…

  • Incident & Escalation Playbook

    This is a governance artifact to share with clients or regulators to demonstrate how AI-related incidents will be managed. Incident & Escalation Playbook for AI Systems FairByDesign | 2025 Introduction AI incidents—such as unsafe outputs, system failures, or compliance breaches—require structured response processes. Without predefined playbooks, organizations risk delayed responses, unclear accountability, and increased…

  • Framework Crosswalk Brief

    Framework Crosswalk Brief (PDF-style Word draft) Title: Aligning AI Governance Frameworks: A Practical CrosswalkFairByDesign | 2025 Introduction Organizations face overlapping requirements when deploying AI systems. The EU AI Act, NIST AI Risk Management Framework, GDPR, and ISO/IEC 42001 all prescribe governance obligations, but in different language. Without a crosswalk, teams duplicate effort or miss…

  • Building a Comprehensive Security Policy

    Building a Comprehensive Security Policy

    Crafting a holistic security policy that integrates these tools can feel overwhelming. However, understanding the key components and their roles can simplify the process, allowing organizations to build effective security without the complexity.