← IntelligenceMARKET INTELLIGENCE, DATA, AND CONTINUITY

Data governance for AI: foundations, responsibilities, and information quality

Luís Paravato

Article cover: Data governance for AI: foundations, responsibilities, and information quality

Data governance for AI is the set of responsibilities and practices that determines what information an application uses, who authorizes that use, and how its quality is monitored. The work covers data sources, updates, access, retention, and correction.

In a business, an AI-generated response supports specific activities: preparing a proposal, checking a sales policy, organizing customer information, or supporting customer service. The usefulness of that response depends on how well the available sources support the task.

A large knowledge base containing expired contracts, outdated prices, and documents without an assigned owner undermines that connection. Data needs to be organized around its intended use from the project design stage.

Start with the activity the application will support

Describe who will use the application, what information it will consult, and what will happen after it responds. An assistant that summarizes public documents has a different scope from an application that accesses customer data and changes CRM records.

The design documents authorized sources, permitted operations, and procedures for human review. It also establishes when the application should report missing data or stop an action.

This scope guides investment and controls. The team first organizes the data needed for the chosen activity, with a verifiable purpose and clearly identified owners.

Data governance and AI governance

Data governance addresses the information the business uses. AI governance also covers how the application operates: response evaluation, model behavior, permissions to act, failure monitoring, and version changes.

The two disciplines intersect in the use of sources. Even an accurate knowledge base requires testing to verify that the application retrieves the right document, understands its limitations, and presents the information faithfully.

A response that references the document consulted is easier to check. The reference must correspond to the content supporting the statement; a link alone does not establish the quality of a response.

How to prepare your data sources

An inventory records the documents, tables, and systems needed for the project. For each source, the team identifies an owner, purpose, validity period, and access restrictions.

DimensionPractical check
CurrencyDoes the source reflect the version currently used by the company?
CompletenessAre the fields needed for the task filled in?
ConsistencyDo values and definitions match across related sources?
OriginIs there a record of where the information came from?
AccessIs the user authorized to view this content?
RetentionIs there a rule for storing, reviewing, and deleting the information?

Duplicate documents are addressed, and older versions are kept separate from current content. Sensitive personal and business information is reviewed by the teams responsible for privacy, security, and contracts.

Responsibilities that need named owners

The business function's leadership defines the activity and expected result. The source owner validates the content and keeps it current. Technology teams maintain connections, authentication, and operational logs. Users check whether responses are suitable for the task.

Security and privacy teams help define access, processing, and sharing rules as appropriate to the context. Purchasing a tool also requires an understanding of storage, how submitted data is used, and deletion terms.

These responsibilities become part of routine project operations. A policy without someone responsible for correcting the knowledge base allows the same issue to recur in future queries.

Test before expanding use

Tests should reproduce real activities. The team prepares frequently asked questions, incomplete cases, conflicting documents, and out-of-scope requests. Responses are compared with reference material reviewed by the responsible business owners.

Beyond accuracy and response time, the evaluation examines improper disclosure of information, malicious instructions embedded in documents, and attempts to perform actions without authorization. Technical controls must work regardless of the text the user submits.

A new source, model version, or access rule requires retesting the affected cases. Test records allow the team to compare results and identify regressions.

Illustrative example: preparing sales proposals

A service business creates an assistant to prepare proposal drafts. Its knowledge base brings together current offerings, approved commercial terms, and descriptions of what will be delivered.

The team removes old pricing tables from operational queries, identifies the owners of each offering, and restricts access to customer contracts. The assistant uses only authorized sources and identifies the documents it consulted.

The design requires a sales review before a proposal is sent. Discounts, scope, and delivery timelines remain subject to approval by the responsible owners. Requests outside the documented terms are referred for review.

Monitoring records preparation time, required corrections, use of outdated sources, and instances of unauthorized access. These findings guide adjustments to the knowledge base and the application.

How to monitor quality after deployment

The operating team maintains a channel for reporting issues, including the question, response, source used, and observed impact. Records follow access controls and avoid unnecessarily reproducing sensitive data.

Each incident is assigned an owner and a category: incorrect content, inappropriate retrieval, interpretation, permission, or execution failure. This distinction directs corrective work to the relevant component.

The company also reviews which sources are still needed. Accumulating information without a purpose increases maintenance work and makes valid content harder to identify.

Frequently asked questions

Do all data sources need to be organized before starting?

The project organizes the data needed for the chosen activity. As the scope expands, new sources receive the same attention to quality, access, and accountability.

Can AI fix a disorganized knowledge base?

AI tools help classify information and identify inconsistencies. The company remains responsible for business rules, validation of corrections, and authorization to use the data.

Who approves a response?

The workflow depends on the activity's impact. Proposals, record changes, and sensitive communications receive levels of review defined in the application design.

How does Kronos Experience help organize this work?

Kronos connects business objectives, information sources, processes, and responsibilities. The work guides AI applications through scope definition, implementation, and results monitoring.

Sources consulted

NIST: AI Risk Management Framework. https://www.nist.gov/itl/ai-risk-management-framework

About Kronos Experience

Kronos Experience is a Brazilian business strategy and intelligence consultancy focused on market, customer, product, and revenue intelligence for digital and service businesses.

We work to increase your company's value to the market and to its customers, turning that value into competitive advantage. Our work connects market strategy, positioning, brand, acquisition, paid media, and sales with customer intelligence, experience, product, data, retention, and monetization.

Through assessment, strategic direction, implementation, and monitoring, we develop opportunities to increase returns on your brand, customer base, channels, products, and infrastructure, while developing new offerings and revenue streams.

Written by Luís Paravato