← AI Transformation Suite Governance Foundation

AI Governance & JAD Session Charter

Download Word

This charter establishes the AI Governance & Center of Excellence (CoE) mandate — what it does, who leads it, and what authority it holds — and defines the JAD (Joint Application Design) session structure used to develop requirements for each BRD. It is approved at the Phase 0 gate and referenced throughout the program by the Governance Model, PMP, and all three BRD specifications. Any change to the CoE mandate or JAD structure requires AI Governance Board approval.

Table of Contents

  1. Charter Purpose & Authority
  2. AI Governance & CoE Mandate
  3. CoE Organization & Reporting
  4. CoE Relationship to Independent Model Validation
  5. Shadow AI Prevention Authority
  6. JAD Session Governance
  7. JAD Mandatory Roles & Responsibilities
  8. JAD Session Structure & Agenda
  9. JAD Output, Sign-Off & Exception Handling
  10. AI Model Design Review at JAD
  11. Escalation Path
  12. Charter Governance & Document Control

1. Charter Purpose & Authority

This charter serves two distinct but interconnected purposes:

  1. Establish the AI Governance & CoE as a permanent governance function within the program — not an advisory committee, not a working group, but a team with enterprise-wide authority over AI development standards, model lifecycle governance, and responsible AI practices. The CoE's authority is granted by the Program Charter and enforced through the Program Governance Model.
  2. Define the JAD session structure that produces the requirements for each BRD. JAD sessions are not informal brainstorming — they are governed requirements-development processes with mandatory participants, structured agendas, formal sign-off, and documented exception handling. The quality of requirements directly determines the quality of the AI models built from them; governance at the requirements stage prevents problems that are far more expensive to fix during development or validation.

2. AI Governance & CoE Mandate

The AI Governance & Center of Excellence is the enterprise-wide first line of defense for AI model risk. It operates across four domains:

2.1 Standards & Policy

2.2 Model Lifecycle Governance

2.3 Regulatory Tracking

3. CoE Organization & Reporting

3.1 Team Composition

The AI Governance & CoE consists of 12 people, led by S. Khurana (AI Governance Director, Pulaski Advisory). Full roster in Resource Plan, Team 5. Key roles:

RoleNameOrgPrimary Responsibility
AI Governance DirectorS. KhuranaPulaskiLeads the CoE; chairs the AI Governance Board; sets enterprise AI strategy
AI Governance Sr. ManagerA. ReyesPulaskiDay-to-day operations; interim model reviews; CoE coordination
AI Standards & Policy LeadJ. FerraroPulaskiEnterprise AI Standards Guide; model documentation requirements
NIST AI RMF SpecialistM. DelacroixPulaskiNIST AI RMF alignment; four-function mapping; compliance verification
ISO 42001 SpecialistP. SinghPulaskiISO/IEC 42001 management system alignment; certification readiness
Model Documentation SpecialistC. AlvarezPulaskiModel cards, data lineage records, training methodology documents
3 AI Governance Analysts (offshore)T. Nakamura, R. Osei, V. CastellanoPulaskiRegulatory tracking, risk taxonomy maintenance, governance reporting
Governance Program CoordinatorL. WhitfieldACMEMeeting coordination, documentation management, governance admin
Governance Reporting AnalystK. NovakACMEGovernance metrics, compliance dashboards, board reporting
Governance Documentation (offshore)D. IbrahimPulaskiStandards documentation, process guides, training materials

3.2 Reporting Structure

4. CoE Relationship to Independent Model Validation

The distinction between the CoE (first line) and Independent Model Validation (second line) is structural and deliberate:

DimensionAI Governance & CoE (First Line)Independent Model Validation (Second Line)
RoleAdvisory, standards-setting, embedded in deliveryTesting, verification, independent from delivery
When activeThroughout model lifecycle (design through production monitoring)At formal validation gate (Phase 3) and re-validation
AuthoritySets standards; recommends; flags concerns; does NOT approve or reject modelsTests against standards; approves or rejects models for production (blocking authority)
Reports toAI Governance Board + Program DirectorAI Governance Board only (NOT to BRD leads or Program Director)
TeamS. Khurana, 12 peopleP. Okafor, 6 people
AnalogyInternal quality assurance embedded in engineeringExternal auditor who tests the final product independently
Why this matters: If the same team that helps design a model also validates it, there is an inherent conflict of interest — they have a psychological and organizational incentive to pass models they helped create. The two-line separation ensures that the validation team has no stake in the model's success and no schedule pressure to approve it. This structure is modeled on OCC SR 11-7 (financial services model risk guidance) and adapted for healthcare AI.

5. Shadow AI Prevention Authority

Shadow AI — AI or ML initiatives deployed outside the program's governance perimeter — is one of the program's highest-rated risks (RAIDD R-10, score 8/9). The CoE's authority to address shadow AI is defined here:

5.1 Detection Mechanisms

5.2 Disposition Authority

Identified shadow AI initiatives are evaluated by the CoE within 10 business days. The CoE recommends one of three dispositions to the AI Governance Board:

5.3 Enforcement

The CoE has authority to recommend suspension of non-compliant AI initiatives to the Executive Sponsor. Persistent non-compliance after notification and escalation is treated as a governance violation and reported to the Executive Steering Board. The program's governance authority over enterprise AI is defined in the Program Charter §9 and cannot be circumvented by individual department heads without Executive Steering Board override.

6. JAD Session Governance

Requirements for each BRD are developed through Joint Application Design (JAD) sessions — structured, facilitated workshops that bring together business, clinical, legal, compliance, security, architecture, AI governance, and delivery perspectives to define what the AI system must do, under what constraints, and to what standards.

JAD sessions are governed, not informal. They have mandatory participants (Section 7), a structured agenda (Section 8), formal sign-off requirements (Section 9), and explicit exception handling. This governance exists because requirements quality directly determines model quality — a model trained on poorly specified requirements will fail validation regardless of how well it is engineered.

6.1 JAD Series Cadence

BRDSession CountSession DurationWindowRequirements Sign-Off Target
BRD-01 (Claims & Prior Auth AI)8 sessions2–3 hours eachOct – Dec 202618 Dec 2026
BRD-02 (Member & Provider UX AI)7 sessions2–3 hours eachJan – Mar 2028 (Year 2)Set at Phase 1 Y2 gate
BRD-03 (Underwriting & Risk AI)6 sessions2–3 hours eachFeb – Apr 2028 (Year 2)Set at Phase 1 Y2 gate

Session count is a guideline, not a constraint. If requirements are not sufficiently developed after the planned sessions, additional sessions are scheduled. Rushing to meet a session count at the expense of requirements quality is explicitly prohibited — it creates technical debt that compounds through development and validation.

7. JAD Mandatory Roles & Responsibilities

Non-Negotiable: No JAD session proceeds without all 8 mandatory roles present (in person or via qualified proxy). If a mandatory attendee is unavailable and no qualified proxy is available, the session is rescheduled. This is non-negotiable because the governance value of JAD sessions comes from having all perspectives in the room simultaneously — a session missing Legal or Compliance is requirements development without governance.
1. Business Sponsor
Dr. N. Patel (BRD-01 · CMO)
Owns scope and priority. Validates clinical appropriateness. Cannot be delegated to a subordinate without AI Governance Board approval — the sponsor's judgment is not replaceable by a delegate's.
2. Legal Counsel
R. Thorne (General Counsel)
Flags liability exposure, regulatory risk, and legal constraints. Signs off that requirements do not create unacceptable legal risk. Specifically reviews: AI output liability (Moffatt precedent), adverse-determination protocols, data-use permissions.
3. Compliance Officer
J. Martinez (VP Compliance)
Ensures CMS/state regulatory alignment. Validates audit trail requirements. Reviews PA decision-timeline compliance (CMS-0057-F). Signs off that requirements meet all applicable regulatory obligations.
4. Chief Architect
D. Chen (Enterprise Architecture)
Validates technical feasibility. Reviews data mapping and integration requirements. Confirms architecture fit with existing enterprise systems. Signs off that requirements are implementable within the approved architecture.
5. Cybersecurity / CISO
M. Hassan (CISO)
Security threat modeling for the proposed AI capability. Reviews data residency, access control, and adversarial-input requirements. Signs off that requirements do not create unacceptable security risk.
6. Program Director (Facilitator)
C. Tyrrell
Facilitates the session — manages agenda, time, and cross-functional discussion. Assesses timeline and resource feasibility. Does NOT sign off on requirements (facilitator role preserves neutrality).
7. AI Governance Director
S. Khurana (CoE)
NIST AI RMF alignment. Model risk assumptions. Fairness criteria definition. Human-override protocol review. Signs off that AI governance standards are embedded in requirements from the start — not bolted on later.
8. BRD Lead
F. Bennett (BRD-01 · Pulaski)
Technical feasibility assessment. Model architecture concepts. Data availability and quality assessment. Signs off that requirements are technically achievable within the approved timeline and budget.

7.1 Proxy Rules

8. JAD Session Structure & Agenda

8.1 Session Progression

The 6–8 sessions per BRD follow a deliberate progression from broad scope to detailed specifications:

Session #FocusExpected OutputDuration
1Scope & Business Context — Why this BRD exists, what business problem it solves, who is affected, what success looks like. Regulatory anchors identified.Business case summary; high-level scope boundaries; success criteria draft3 hours
2Current State & Data Mapping — How the process works today, what data exists, where it lives, what condition it's in. Pain points documented.Current-state workflow map; data inventory; gap assessment3 hours
3Target State & AI Capability Design — What the AI system will do, how it fits into the workflow, what model types are proposed, what the user experience looks like.Target-state architecture (conceptual); model type proposals; UX concepts3 hours
4AI Model Design Review — Detailed model specifications reviewed by AI Governance (Section 10). Fairness criteria, explainability requirements, and human-override protocols defined.Model design approvals; fairness thresholds set; human-in-the-loop requirements defined3 hours
5Security, Compliance & Regulatory Review — Cybersecurity threat model, data residency validation, regulatory traceability, compliance sign-off.Security requirements; compliance requirements; regulatory traceability matrix draft2.5 hours
6Functional Requirements Consolidation — All requirements consolidated, prioritized (MoSCoW), and reviewed for consistency. Gaps identified.Draft BRD requirements document; MoSCoW prioritization complete3 hours
7Non-Functional Requirements & Integration — Performance targets, availability, scalability, integration requirements, testing approach.Non-functional requirements; integration matrix; testing strategy outline2.5 hours
8Final Review & Sign-Off — Complete BRD requirements document reviewed end-to-end. Exceptions discussed. Sign-off or exception documentation.Signed BRD requirements document OR documented exceptions with resolution plan3 hours

8.2 Session Facilitation Rules

9. JAD Output, Sign-Off & Exception Handling

9.1 Requirements Document

Each JAD series produces a BRD requirements document that becomes the authoritative specification for what the delivery team builds. The document uses a standard template:

9.2 Sign-Off Process

  1. At Session 8 (Final Review), each mandatory attendee (except the Program Director, who facilitates) reviews the complete requirements document.
  2. Each attendee provides one of two responses: Sign Off ("I have reviewed these requirements and confirm they are acceptable from my governance perspective") or Submit Exception (written statement identifying specific requirements they cannot approve, with explanation and recommended resolution).
  3. Sign-off is collected in a formal sign-off record, documented with name, role, date, and response. The record is archived in the project portal as part of the Phase 1 gate package.

9.3 Exception Handling

Exceptions are not failures — they are the governance system working correctly. A mandatory attendee who has a legitimate concern should raise it, not suppress it to avoid delaying the timeline.

10. AI Model Design Review at JAD

Session 4 of each JAD series is dedicated to AI model design review — the point where the CoE evaluates whether the proposed model approach is governable, fair, explainable, and safe. This is not a technical deep-dive into algorithm selection; it is a governance review of the model's design assumptions and risk profile.

10.1 What the CoE Reviews

Review AreaKey QuestionsReviewed By
Model Type SelectionIs the proposed model type appropriate for this use case? Is explainability achievable? Are there simpler alternatives that would meet the business need with less risk?S. Khurana + BRD Lead
Training Data AssumptionsIs the training data representative? Is it sufficient in volume? Are there known biases in the data? Is de-identification adequate?S. Khurana + E. Sato (CPO)
Fairness CriteriaWhat demographic groups are relevant? What disparate-impact threshold will be applied? How will proxy variables be handled?S. Khurana + Dr. N. Patel + R. Thorne
Explainability StandardCan the model produce human-readable explanations of its decisions? Are the explanations faithful to the model's actual reasoning?S. Khurana + BRD Lead
Human-Override ProtocolUnder what conditions must a human review the model's output? Can the human override the model? Is the override logged?S. Khurana + Business Sponsor + Legal
Retraining TriggersWhat metrics will be monitored in production? At what thresholds will retraining be triggered? Who decides to retrain?S. Khurana + BRD Lead

10.2 Model Design Approval

The AI Governance Director (S. Khurana) provides a formal recommendation on each model design: Approved (proceed to development), Approved with Conditions (proceed with specified adjustments), or Not Approved (redesign required). The recommendation is documented in the JAD Session 4 minutes and reported to the AI Governance Board at its next meeting. The AI Governance Board ratifies or overrides the recommendation.

11. Escalation Path

Used when a JAD session cannot reach consensus on a requirement, a model design question, or a governance exception:

  1. Within the session (immediate): Program Director (facilitator) attempts resolution by clarifying the positions, proposing a compromise, or reframing the question. Most disagreements resolve at this level.
  2. Action item with deadline (24–48 hours): Unresolved item parked as a formal action item with a named owner, a clear statement of the disagreement, and a resolution deadline (typically next JAD session or within 10 business days).
  3. Board review (5 business days): If the action item cannot be resolved bilaterally, escalated to the relevant board: AI Governance Board (model-risk or fairness questions), EARB (technical feasibility questions), or Executive Steering Board (scope, budget, or regulatory-risk questions).
  4. Executive Sponsor (if board cannot resolve): Material disagreements that deadlock at board level are escalated to M. Kavanagh per the standard escalation framework in the Governance Model §6.

12. Charter Governance & Document Control

FieldValue
Document TitleAI Governance & JAD Session Charter
Version1.0
Date17 August 2026
OwnerS. Khurana (AI Governance Director)
Approved ByAI Governance Board (10 Aug 2026); Executive Steering Board (acknowledged 17 Aug 2026)