# A new AI feature is a governance decision, not just a technical one.

Introducing an AI feature, chatbot, or automated decision tool carries risks a standard IT change request does not capture — data exposure, unreliable output, and unclear accountability. XGRC® gives organisations a structured way to assess, approve, and monitor AI-related change.

**Frameworks:** ISO 42001, ISO 27001, POPIA, GDPR, AI Governance, Change Management

## A standard change form does not ask the questions AI risk requires.

Most change management processes were built for infrastructure and application changes. They do not prompt anyone to confirm what data an AI service sees, whether a vendor trains on it, or what happens when the model gets something wrong. Those gaps only surface after go-live.

- AI features are introduced through the standard change process, which does not ask about data flow, model training, or bias
- Nobody has confirmed whether the AI output is advisory or triggers automated actions
- Users are not warned against entering confidential or personal information into an AI tool
- There is no rollback plan if the AI feature produces unreliable or unsafe output

## A risk-based process for AI-related change.

- Classify the change by AI use case and risk rating before approval
- Assess data privacy, data flow, and cross-border transfer up front
- Review vendor terms, security controls, and access management
- Test for accuracy, bias, and unauthorised data exposure before go-live
- Brief users and support teams, with clear disclaimers on AI output
- Confirm a rollback plan and monitor the feature after launch

## How it works

- The AI change checklist raised and tracked as an auditable change record
- Approvals from business, technical, and security owners captured against the change
- Actions arising from the review tracked through to verified closure
- The same governance principles the checklist requires — audit trail, permission alignment, data boundary controls — built into MAIA®, XGRC®'s own AI capability

## On the platform

**Governance that keeps pace with AI adoption** — XGRC® links the AI change checklist to your existing change, risk, and action management processes, so an AI feature is approved, tested, and monitored with the same rigour as any other high-risk change — and MAIA®, XGRC®'s own AI capability, is built around those same governed-AI principles.

## The same AI rollout, without the blind spots.

| Manual approach | With XGRC® |
| --- | --- |
| AI features approved through a generic change form | A dedicated AI risk classification and review process |
| Data flow and vendor training use unconfirmed | Data flow, privacy, and vendor terms assessed before approval |
| No disclaimer or user guidance before go-live | User guidance and disclaimers issued with the change |
| No documented rollback plan | Rollback plan and post-launch monitoring tracked to closure |

## One process for every AI-related change.

- New AI features and tools
- Chatbots, copilots, and generative AI integrations
- Automated decision and recommendation systems
- Third-party AI vendor onboarding

## Frequently asked questions

### What is an AI change management checklist?

An AI change management checklist is a structured set of questions used to assess a new AI feature or tool before it goes live, covering data privacy, security, testing, and rollback — questions a standard IT change request does not ask.

### Why can't I just use my normal change management process for an AI feature?

A standard change process checks technical readiness but rarely asks what data an AI service processes, whether a vendor trains on it, or how the feature is disabled if it produces unreliable output — gaps this checklist is built to close.

### Does this checklist apply to third-party AI tools as well as custom-built ones?

Yes. The same questions apply whether the AI capability is a vendor product, an embedded copilot, or a custom integration, because the data flow and accountability risks are the same regardless of who built the model.

### How does XGRC® relate to AI governance?

XGRC® tracks the AI change checklist as an auditable change record with linked approvals and actions, and MAIA®, XGRC®'s own AI capability, is built around governed-AI principles including audit trails, permission alignment, and data boundary controls.

## Related solution

- [MAIA®](https://xgrcsoftware.com/maia)

---

Source: https://xgrcsoftware.com/use-cases/ai-change-management
