top of page

BrightBridge Learning International

is a fictional international nonprofit created to demonstrate how enterprise AI governance can be designed for an organization serving children across multiple countries.

The engagement examines AI used across education, safeguarding, program delivery, communications, workforce operations, and third-party platforms. The objective is to establish a governance structure that allows the organization to identify AI use, classify risk, assess impacts on children, assign accountability, implement controls, govern vendors, and continuously monitor higher-risk systems.

Focus: Enterprise AI Governance | Child Impact | AI Risk Management | Human Oversight | Controls & Evidence | Vendor Governance

'

The Governance Challenge

AI adoption can happen across an organization long before a formal governance program exists.

For a child-serving international nonprofit, this creates additional concerns around:

Child safety and safeguarding

Sensitive and cross-border data

Bias and unequal outcomesHuman oversight of child-affecting decisions

Accessibility and inclusionThird-party AI vendors

Model transparency and documentation

Accountability across countries and programs

This engagement develops a governance model designed to move BrightBridge from fragmented AI use toward a documented, risk-based and accountable AI governance program.

The Engagement

Governance lifecycle.png

The work is organized into eight client-ready governance artifacts.

Governance Artifacts 01

AI Governance Charter & Operating Model

Defines how AI governance operates across the organization, including governance structure, committee responsibilities, named roles, decision rights, escalation pathways, exceptions, and review cadence.

Demonstrates: Governance Operating Model | Accountability | Decision Rights | Executive Oversight

02 | Enterprise AI System Inventory

Creates an authoritative register of known AI systems and AI-enabled vendor features, documenting business purpose, owners, affected stakeholders, data use, automation, lifecycle status, and risk classification.

Demonstrates: AI Discovery | System Inventory | Ownership | Risk Visibility

03 | AI Risk Classification Standard

Establishes a repeatable method for classifying AI systems as low, moderate, high, or prohibited based on factors such as child interaction, sensitive data, decision impact, safeguarding, automation, accessibility, and vendor transparency.

Demonstrates: Risk Tiering | Governance Intake | Proportional Controls

04 | Child Impact Assessment

A detailed assessment of the Student Dropout Risk Predictor, examining intended use, affected children, privacy, bias, safeguarding, accessibility, explainability, human oversight, foreseeable misuse, mitigation, and residual risk

Demonstrates: AI Impact Assessment | Child Safety | Stakeholder Analysis | Human Oversight.

05 | AI Risk Register

Translates identified concerns into specific, actionable risks with likelihood, impact, safeguards, accountable owners, residual risk, treatment decisions, evidence, review dates, and escalation status.

Demonstrates: AI Risk Management | Risk Ownership | Residual Risk | Remediation

06 | Control & Evidence MatrixMaps AI risks to specific governance controls and defines who owns each control, what evidence demonstrates implementation, how effectiveness is tested, and how gaps are remediated.

Demonstrates: Control Design | Assurance | Evidence | Control Testing

07 | AI Use, Procurement & Vendor Due-Diligence Standard

Establishes requirements for adopting third-party AI systems and embedded AI capabilities before procurement or deployment, including vendor disclosure, data handling, child-data restrictions, audit rights, model changes, incidents, subcontractors, retention, and exit planning.

Demonstrates: Third-Party AI Risk | Procurement Governance | Vendor Due Diligence

08 | Governance Roadmap & Monitoring Pla

nConverts assessment findings into a phased implementation plan covering the first 90 days, six months, and twelve months, supported by KRIs, monitoring, incident escalation, reassessment, and executive reporting.

Demonstrates: Governance Implementation | Monitoring | KRIs | Executive Reporting

bottom of page