ITIL AI Governance (Version 5): categorizing and assessing AI, and deploying appropriate controls
Paul Burby, Global Service Management Lead – Mars
In a previous era, we were told “not to believe everything you read in the newspapers”, despite people placing their faith in such external authorities.
Later, that approach extended to being skeptical about information online, then social media and – today – the same goes for AI. But the added risk with AI is how human it can seem, leading to trust that’s not always justified.
For professionals developing and working with AI solutions in organizations, this means they must be thinking about appropriate controls and governance.
In my role as a global process owner with governance responsibility for IT change and request management, I’m not directly creating AI tools. However, studying ITIL AI Governance (Version 5) has helped me frame my thinking and move the governance needle within our own function.
That involves highlighting where the governance gaps are, what’s required and bridging the gaps with specific controls within our processes.
Recognizing the need for AI governance and practical approaches
Our company already takes a mature approach to AI governance, with policies and policing of, for example, shadow AI use. Where it’s required, the right level of governance is in place.
For organizations and practitioners that may be less mature, the ITIL AI Governance (Version 5) module would help identify the general appetite for risk and governance while assessing AI use cases and the required level of governance for them.
The guidance provides a roadmap for how to assess the different levels of governance that might be needed and how that contrasts with governance at an organizational level. This helps by outlining what can be done, rather than allowing implementation of AI to just happen.
Bearing in mind the principles that AI should a) do no harm and b) benefit people, the knowledge in the module helps you assess each AI use case for its risk level and enable the right controls. So, if there is an AI use case which could have a wider impact on the organization and its employees, there needs to be human oversight and the option to have an “off” button for the AI in question, when necessary.
And this is also about having the knowledge to reassure stakeholders that an AI solution will help people work better while not posing a problem. Again, this is about identifying the right controls dependent on the use case.
Valuable elements from the ITIL AI Governance (Version 5) guidance
Within the new module, the ITIL AI Capability Model, which sets out six capabilities influencing how organizations adopt and use AI, is especially valuable.
It provides the ability to categorize AI use cases and the capabilities they would create; helping to determine which controls a team would need to put in place and what the business outcomes would be. After all, it’s not about implementing AI for the sake of it.
This is where putting AI governance in the context of ITIL’s focus on business value is so important. For my team, co-creation of value is fundamental: preventing downtime to business services that can affect revenue and reputation. Therefore, if and when AI comes into the picture, having the ITIL AI Capability Model knowledge ensures I can categorize what we’re doing and understand the potential risks it might pose to change enablement.
Of course, we’re always interested in how to make things more efficient, which could include AI delivering more in less time. For example, in the change enablement practice – with activities including assessment of risk level and providing approval – a change can become pre-approved with less governance when it has happened several times and can be considered low risk.
AI might help that and, at some stage, guardrails could be reduced if deemed safe. However, this won’t replace the role of people and human accountability.
Appropriate guardrails for AI
In tandem with the ITIL AI Capability Model is the ITIL AI Governance Improvement Model. This provides the wrap-around of governance and the policies and controls to implement.
For example, when making a change, this could involve selecting a configuration item and checking the relationship database to see what it’s connected to. AI could be deployed to ensure the relationship is correct and identify previous incidents – and could then suggest to the change owner the potential for a particular change to have a wider impact. Ensuring the change owner has final approval means that appropriate guardrails are in place.
Governing AI enterprise-wide
In every role and department exploring the use of AI, there’s a reason to apply the learnings from ITIL AI Governance (Version 5).
Professionals across an organization can apply the guidance to their own AI use cases; using the Capability Model to categorize and assess risk in a more structured way and to identify and implement the necessary controls appropriately.