June 18, 2024

ModelOp's AI Governance Score

Summary

In this episode of Good Decisions, host Jay Combs is joined by ModelOp's Dave Trier to explain the company's AI governance score and the accountability gap it was built to close. With enterprises running open-source models, generative AI, third-party vendor tools, and traditional statistical models side by side, governance officers have had no consistent way to tell whether any of it actually adheres to policy — and, by one industry estimate, only a small fraction of executives have real visibility into how AI is being used inside their own organizations. Dave describes the score as a configurable, apples-to-apples metric built on four inputs: required business and technical information, the implementation assets behind each use case, the evidence governance demands, and the controls that keep work inside policy. He explains how ModelOp implements it through technology-agnostic integrations and automation, why the software ships with templates based on frameworks like the NIST AI RMF and SR 11-7, and how the resulting score gives executives something they can take straight to the board.

Key Takeaways
  • Why inconsistent model types make policy adherence nearly impossible to measure without a common metric.
  • The AI accountability gap: how few executives actually have visibility into enterprise AI use and risk.
  • The four components that roll up into an AI governance score: information, assets, evidence, and controls.
  • Why the score has to be configurable to each enterprise's own governance policy.
  • How a single score gives non-technical executives and boards a usable view of AI risk.
  • Why out-of-the-box templates based on the NIST AI RMF and SR 11-7 get most enterprises 70-80% of the way there.
  • How technology-agnostic integrations and automation replace manual governance effort.
Timestamps

[00:03] – Introduction

[00:22] – Dave's path into AI governance

[01:22] – The AI accountability gap

[02:01] – What an AI governance score is

[03:19] – The four inputs behind the metric

[04:48] – Why executives need a single snapshot

[05:57] – Using the score to enforce policy

[06:24] – Where the idea came from

[07:13] – How enterprises implement it

[08:34] – Templates for NIST AI RMF and SR 11-7

[09:04] – Reporting AI risk to the board

[10:08] – Closing remarks

Transcript

Jay Combs: Hello, and welcome to the ModelOp Good Decisions podcast. I'm Jay Combs, the VP of marketing. And today, we're going to be talking about ModelOp's new AI governance score, what it is, why it's important. And to talk about it is our VP of product, Dave Trier.

Dave, welcome to the podcast. How are you?

Dave Trier: Doing well. Thanks for having me, Jay. Looking forward to this.

Jay Combs: Awesome. So before we get into, kind of the technicalities and concept of the AI governance score, can you just give us a quick, introduction of, like, who you are, how you got to ModelOp and into AI governance?

Dave Trier: Absolutely. So, my background, I've had a long history mainly with enterprises and helping to deliver data analytics, data science, ML, AI. And what was happening is I was helping these large organizations, these Fortune 500, to deliver on the promise of machine learning and AI. We routinely got into major bottlenecks.

Bottlenecks in actually using these types of analytics for production business purposes. And a lot of the time, it was actually came down to, operational and governance concerns. And so because of that, just really saw that this was a need in the market to be able to understand how do we properly use AIML with the appropriate oversight, governance, and operational procedures, both upfront and an ongoing perspective. So that's what led me to really having a focus in the AI and ML governance space over the last five to seven years.

Jay Combs: Got it. And so I think that's a good kind of summary of almost kind of why the AI governance score, is important. But, I guess, first things first, we know that, like, there's a larger AI accountability challenge. We've heard consulting firms like Accenture state that only about 2% of executives or CEOs have insight into how AI is being used, what it's doing, what the risks are within a company.

So I think there's a larger problem of understanding exactly what are those risks, what's the value, what's being done. So let's get into the details of what an AI governance score is with that in mind. So my first question is, you know, what is an AI governance score, and why is it important?

Dave Trier: Yeah. Absolutely. And just to set the context, around this is as the modern enterprise is starting to adopt a variety of different technologies, machine learning, traditional statistics, but now AI with neural nets, deep learning, generative AI. So you have this variety of different technologies and approaches that are being used.

They have different types of implementations, different technical assets, and also different pieces of data that are actually used. So because of that, it's really challenging for governance officers and executives to really understand, well, are these particular models and use cases that are using AI actually adhering to our governance policy because they're so different? Introduce the AI governance score, which is meant to be a consistent metric to measure adherence to all of your AI and ML initiatives, regardless of whether it's a open source type model, whether it's a generative AI model, a third party vendor model, or a traditional statistic. I just want an apples to apples comparison to understand, Are all of my AI and ML models and capabilities actually adhering to the governance policy?

That's what the AI governance score is and it aims to solve overall.

Jay Combs: Got it. And being a metric, I imagine that there's a lot that rolls up into it into it that it captures and probably differs from industry to industry or even company to company. So can you go into a little more detail about what goes into that metric?

Dave Trier: Yeah. Absolutely. So first off, the metric from a model perspective is configurable. It's meant to be configurable to your specific policy, your governance policy.

And part of that policy and what rolls up into that metric are a variety of different factors that you want to check on. First, you want to make sure that you've collected all of the required, really, information, business information, technical information, metadata, et cetera, about your AI use case, making sure that you've captured everything that is required for your governance policy. Second, that you wanted to capture all the various assets that are related to how you're implementing this AI use case. Things for internally developed models like source code or binary artifacts, execution details, configurations of vendor models that you need to understand, whether they are provided as a service, where those endpoints are.

Third, you need to provide the various pieces of evidence that are required as part of governance. Typically, these are things like being able to, run tests, run those tests against thresholds to identify risks or where the benchmarks are, things such as documentation, approvals, and reports. And then finally, the fourth area is really around the controls. All governance policies have a set of controls just to make sure that we're actually operating within the bounds or the confines of the governance policy.

So some examples of controls could be things like attestations, change controls, process controls, data controls. All of those really factor into the that, again, control section, which is mainly the fourth part of the overall AI governance score. So I hope that I give you a little bit of a sense. There's obviously a lot that goes into it, as part of it, but those are really the four main categories that are typically included.

Jay Combs: Got it. That makes a lot of sense. Sounds like it's very good quick insight, say, for somebody who's maybe not into the day to day of all the details for a given model going through various stages of the model life cycle, maybe of hundreds of use cases. It can be really hard to understand where everything is at any given point in time.

And then AI governance score really helps that executive looking to get a snapshot of what are we doing, where are we at, what are the risks.

Dave Trier: Yeah. Exactly. Exactly. And that's really kind of hits on some of the, like I said, the first challenge is just having consistency, right?

All these enterprises are best to adopt a new generative AI technologies, whether they're in house or vendor or embedded AI. So you just need consistent way to understand, right, across all these different variety of technologies, what's it what are they actually adhering? Right? So this governance score just gives them, again, a consistent way to know that it's adhering.

The second one, which you alluded to, which is actually the visibility. Executives, I mean, it's not their day job to understand all the nuances of generative AI, of LLMs. But they need to know that they're that the enterprise is protected, right, that they're following the policy. So it gives the visibility for those that are not ingrained in generative AI or AI as a whole just a very easy way to understand how we're doing in terms of adherence.

And really the last thing I would just say just to kind of round that out, is it also helps to enforce the policy. Right? Most of these organizations before we come in, they have or either are developing a policy or have an AI governance policy, but there's not a consistent way to enforce that policy other than word-of-mouth and training and just hoping that employees do the right thing. So this is it helps to provide a way to enforce that policy, again, across all those different vectors that we mentioned earlier.

Jay Combs: Got it. So you mentioned, yeah, a couple of the challenges there. How did you, I guess, hear about those and kind of come up with the idea for the AI governance score? Were you talking to customers, the market?

What where did the genesis for this come from?

Dave Trier: Yeah. It's funny. So I think we've talked about this before, but I've had the pleasure our company had the pleasure of talking with hundreds of executive executives. And the first thing they say to us is that, you know what?

I've invested in tens, hundreds of millions of dollars into AI. And I just want visibility into where AI is being used. And then second, what are the risks around it? And so that's really been the genesis, from the start for ModelOp as, with our overall releases is to provide that visibility and then provide the visibility into the risks around it, which ultimately led to this governance score, which is giving executives, again, that don't have the day to day knowledge of AI, that visibility into the risk across all the variety of different technologies.

Jay Combs: Got it. And so conceptually, this sounds great, makes a lot of sense, but how do you actually implement it? Sometimes implementations can be, like, with just enterprise tech in general, it can be very challenging. How do you get off the ground with this?

Dave Trier: Yeah. Absolutely. So off this is where ModelOp's is invested very heavily in a couple factors. First is being agnostic.

Right? Being agnostic to technology, but providing a consistent way to collect everything about the model, all those factors that I mentioned, the metadata, the assets, the documentation, approvals. So first, because we're agnostic, we can easily tie into those variety of different technologies. Second is we have a very powerful suite of integrations, which allows you to get off the ground quickly saying, okay.

I've got some internally developed models that's tying to your source code management. I've got some cloud based models that's tying to the APIs around those, et cetera. So we start with, again, the agnosticity, the integrations, and then automation, right, behind our software overall. It's powered by automation through and through.

So in that way, it turns it from a very manual effort to something that is automated, helping to import existing models, existing use cases, but ultimately helping to streamline the overall adherence to the governance policies.

Jay Combs: Got it. And if I was a chief AI officer or CIO or CDAO and I said, hey. Really, I would love to get this kind of visibility in comparison to my different model types. I want to start using ModelOp.

How what are what are the steps that I would need to do to get that AI AI governance score? Does this take weeks, days, years to get set up? How does that function?

Dave Trier: No. Great question. Luckily, we ship ModelOp center with some examples, some templates out of the box for around governance score. And these are based on generally regulations, things like the NIST AI RMF, in the financial world, SR 11-7 from the OCC, et cetera.

So we actually ship ModelOp with some configured out of the box governance score, criteria as we call it, so that you can get up to speed very quickly. And again, it's configurable as every enterprise has some nuances, but we ultimately ship out of the box, which gets you around 70% to 80% of the way there.

Jay Combs: Cool. Awesome. So easy to get started with and it the AI governance score, ModelOp's AI governance score is a standardized metric for, measuring compliance adherence and being able to compare apples to apples, different types of models regardless of the technology that's behind it, in a very, easy to understand way, gives you visibility and accountability across the enterprise. So with that summary, anything else you want, listeners to know about the AI governance score?

Dave Trier: Yeah. I think it's just what you alluded to earlier is that, the board, board of directors are all saying, okay, well, how are we using AI and how are we protecting ourselves? So if you think about the that executive visibility back to the board who's asking the question how we protected ourselves. That governance score is incredibly powerful to provide them that visibility and consistent way to say, like, here's all the AI systems.

Look. Here's the governance score across all those different AI use cases that we're actually using. Very easy to understand even at the board of director level. So I would just say to those that are in charge of AI and AI governance as a whole, it's a I strongly consider looking at how we do the AI governance score and using ModelOp Center to help to enforce that and provide that visibility.

Jay Combs: Awesome. Thank you, Dave, so much. I think we're going to hold it there. And this was a great episode.

Thank you for sharing your thoughts and the ideas behind the AI governance score. That's it for this episode of Good Decisions. Thanks for joining us. And, everybody listening, please subscribe to the podcast.

We'll be recording new episodes about on a weekly basis. So, if you have any thoughts too for new content or questions, we're trying to answer frequently asked questions on the podcast. Don't hesitate to reach out to us, with some ideas. And if you want to talk more AI governance, connect with Dave, or some of the rest of our experts here.

Don't hesitate to reach out. There's a contact form and a demo form on our website. We'd love to show you more. Thanks so much.

Bye.

Show Full Transcript
Stay Connected

🔗 Follow Dave Trier: LinkedIn

🔗 Follow : LinkedIn

Follow ModelOp
Get the Latest News in Your Inbox
Share this post
Good Decisions Podcast