The three dimensions of dependency governance
Dimension 1: Diversification and portability
The first defence against dependency is diversification. An organisation must not concentrate too many critical functions on a single AI system or supplier. Moreover, it must retain the capacity to migrate to other solutions or suppliers.
- Identify critical functions and ensure coverage by at least two possible sources.
- Retain the code, the data and the intellectual property needed to switch supplier.
- Regularly test portability: can we really migrate to another solution?
- Explicitly document the dependencies on external suppliers.
Dimension 2: Transparency and understanding
An organisation cannot govern effectively govern a dependency unless it understands it. This requires complete transparency on how AI systems work, their limits, their risks and their decisional impacts.
- Require that every AI system be auditable and explainable, not a black box.
- Conduct regular audits to verify that AI does what we think it does.
- Train teams to understand AI systems, not to worship them.
- Put in place alerts to detect when AI starts to determine business decisions rather than support them.
Dimension 3: Resilience and fallback plans
A resilient organisation must be able to operate without its AI systems. This requires keeping manual or alternative processes, even if they are less efficient, and regularly testing the capacity to operate in degraded mode.
- Retain the alternative manual processes for every critical function.
- Regularly test the shift to degraded mode: can the organisation continue without AI?
- Explicitly document the switch-over thresholds: at what point of dysfunction do we stop the AI?
- Plan business continuity exercises that include the loss of AI systems.