AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

← News
Research2026-07-23

DDMI's Two-Step AI Approval Model Shows How Enterprises Can Operationalize Use-Case and Product Review as Separate Gates

What happened

DDMI, a data-driven enterprise, has shared a detailed case study via Dataversity describing how it operationalized AI governance through a structured two-step approval process in an article titled AI Governance in Action: Practical Insights from a Data-Driven Enterprise. In the first step, reviewers assess whether the proposed use case is appropriate and permissible before any specific tool or product is considered. Only after use-case approval does the second step evaluate the particular AI product or service under consideration, including legal and regulatory checks, security assessments, and data-location guardrails. The separation of these two gates prevents organizations from anchoring approval decisions to a specific vendor or product before the underlying use has been validated, a sequencing error that is common in ad hoc AI adoption. DDMI also describes continuous monitoring obligations that persist after deployment, framing governance as an ongoing function rather than a one-time approval event. The practical controls outlined in the case study are directly transferable to enterprise AI review workflows and complement widely discussed models such as the Mastercard pre-build risk scorecard and the gated governance approach covered in a recent enterprise case study.

Why it matters

  • ·Regulators and auditors increasingly expect documented, structured AI intake processes: a two-step model that separates use-case approval from product approval creates a clear audit trail and reduces the risk of approvals being driven by vendor preference rather than risk analysis.
  • ·Data-location guardrails embedded at the approval stage address a persistent compliance exposure -- many organizations discover cross-border data transfer or residency violations only after deployment, at which point remediation is costly and may trigger notification obligations under applicable privacy regimes.
  • ·Continuous monitoring requirements in the DDMI model reflect the direction of emerging AI governance frameworks globally, meaning organizations that treat approval as a terminal event rather than the start of an ongoing oversight obligation are building programs that are already misaligned with regulatory expectations.

Governance controls affected

What to do now

  • Audit your current AI intake process to determine whether use-case approval and product or vendor approval are distinct gates, and restructure the workflow if they are conflated into a single step.
  • Add data-location and cross-border transfer checks as explicit criteria in your product-level approval gate, not as a post-deployment review.
  • Define the continuous monitoring obligations that attach to each approved AI deployment, including who is responsible, at what cadence, and what thresholds trigger escalation or re-review.
  • Document the rationale for both the use-case and product approval decisions separately so that each gate produces an independently retrievable audit record.
  • Map the DDMI legal and regulatory check criteria against your existing vendor assessment questionnaire and update the questionnaire where gaps exist.

What to watch next

Compliance teams should monitor whether other named enterprises publish similarly granular case studies, as regulators in multiple jurisdictions are signaling that documented intake processes will be an early focus of AI governance audits. The ISO/IEC 42001:2023 – Information Technology – Artificial Intelligence – Management System certification process is increasingly being used as a benchmark against which enterprise intake workflows are evaluated, and auditors are beginning to ask for evidence of structured pre-deployment gates specifically. Teams should also track whether forthcoming guidance from US state regulators -- particularly those implementing provisions of laws like the Colorado AI Act SB205 -- incorporates explicit sequencing requirements for use-case versus product approval, which would elevate the DDMI model from best practice to legal obligation in those jurisdictions.

Stay ahead of stories like this

Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-07-31

Fortune 500 Bank Case Study Maps a Repeatable AI Intake and Approval Operating Model

ValidMind published a case study detailing how a Fortune 500 bank structured its AI governance workflow to accelerate use-case review and approval without relaxing legal, security, or monitoring controls. The bank separated intake, review, and ongoing oversight into distinct stages, creating a repeatable operating model. The case study offers financial services compliance teams a concrete reference architecture for scaling AI governance without creating bottlenecks.

Research2026-07-30

Kriv AI Case Study Shows Quarterly Review Cadence and Risk Register as Baseline for Financial Services AI Governance

Kriv AI published a case study documenting how it built a centralized AI governance framework for a regional US financial services firm that lacked structured AI oversight. The engagement produced a formal risk register, a quarterly review cadence, and a continuous compliance monitoring function. Financial services compliance teams can use the documented approach as a template for model inventory, periodic assurance, and regulator-ready governance programs.

Corporate Policy2026-07-24

Static AI Governance Models Are Inadequate for Agentic Systems, Info-Tech Research Group Warns in New Blueprint

Info-Tech Research Group has published a governance blueprint arguing that one-time approval processes and static control models cannot manage the risks of agentic AI systems that act autonomously across tools and workflows. The blueprint calls for adaptive programs covering governance, risk, compliance, assurance, and full lifecycle integration. Enterprise compliance teams are advised to move toward continuous control monitoring rather than point-in-time review.