Chapter 08
Governance, Risk & Responsible Use
4 sawal, 3 mumkin jawab — AI ka kaam safe rakhne wala ek habit jo actually chalta hai
Ye chapter CCAO-F ke Governance, Risk, and Responsible Use domain ke liye foundation hai
Core Idea
Ek logistics company ka AI ke sath acha saal chal raha hai. Phir ek project manager, ek director ka sawal lunch se pehle answer karne ki koshish mein, customer names aur account numbers wali spreadsheet AI chat mein upload kar deti hai. Wo koi rule todne ki koshish nahi kar rahi. Company investigate hone tak AI use freeze kar deti hai, aur wo teams bhi apna workflow kho dete hain jinhone kuch galat nahi kiya, kyunke ek routine decision ne aisa risk bana diya jise organisation ignore nahi kar sakti. Ye ek dramatic failure nahi hai, ek ordinary decision hai jise kisi ne decision ki tarah frame hi nahi kiya.
Poora Course, 30 Seconds Mein
AI se koi meaningful kaam karwane se pehle 4 sawal poocho:
The Case
The Data
The Capability
The People
Kab Ye Chalana Hai
Part 1 · The Case: Kya AI Ye Kaam Kar Sakta Hai?
Ye sawal pehle aata hai, kyunke agar AI ko ye kaam karna hi nahi chahiye, baad ke data aur tool wale sawal matter hi nahi karte. 4 screens use karo (AI Fluency Framework mein inhe Delegation criteria kehte hain):
| Screen | Sawal |
|---|---|
| Reversibility | Agar output galat hai, kya nuksan hone se pehle catch aur undo kar saktay hain? |
| Consequence of error | Agar galat hui, kya hota hai? Cost trivial hai, mehngi hai, harmful, regulated, ya irreversible? |
| Human judgment ya empathy | Kya task relationship, care, ya original judgment maangta hai jo insaan ko khud karni chahiye? |
| Accountability | Iska jawab kaun deta hai, aur kya wo AI ka output meaningfully review aur own kar sakta hai? |
| Answer | Matlab |
|---|---|
| Fully appropriate | Low consequence, reversible, normal work mein review hona aasan, koi special gate nahi chahiye |
| Appropriate with human review | AI useful hai, lekin use hone/send/publish hone se pehle ek specific human check chahiye |
| Inappropriate | Consequence, irreversibility, ya human responsibility itni bhari hai ke review se bhi repair nahi hoti |
Deciding Factor Dhoondo
Human In The Loop Ek Gate Nahi Hai
“Insaan review karega” responsible lagta hai aur aksar kuch matlab nahi rakhta:
Defined Gate
- Who: wo role jo actually responsibility rakhta hai
- What: wo specific risk jo review pakadne ke liye hai
- When: output hard-to-undo hone se pehle
Gate Nahi Hai
- “Human loop mein rahega”
- “Koi check kar lega”
- “Review hoti hai”
- “Appropriate oversight ke sath”
| Use Case | Classification | Kyun | Gate |
|---|---|---|---|
| Approved policy docs se internal FAQ draft karna | Appropriate | Reversible, low consequence, authoritative sources maujood hain | Normal editorial review |
| Billing complaint ka customer response draft karna | Appropriate with review | Company customer ke account facts ke liye accountable hai | Support agent facts aur tone verify kare, bhejne se pehle |
| Final professional determination banana | Inappropriate | Professional accountability aur consequence transfer nahi ho sakti | Human professional khud decide aur own karta hai |
| Candidate applications summarize kar ke organise karna | Appropriate with strong review | Applicants ke liye consequential, unfair filtering ka risk | Hiring owner inclusion AND exclusion dono review kare |
Part 2 · The Data: Kya Ye Information Andar Ja Sakti Hai?
Order yaad rakho:
3 Practical Tiers
Green · Generally Permitted
Public material, genuinely anonymised/aggregated data, internal material jo broad use ke liye approved hai
Yellow · Pehle Check Karo
Internal-only documents, personal contact info, customer/employee identifiers, unannounced deal ya product information
Red · Unapproved Route Se Nahi
Credentials, secrets, highly regulated ya specially protected data, privileged ya third-party confidential material
Sabse Zyada Useful Data Sawal
“Kya task ko actually identifiers chahiye, ya sirf pattern?”
Agar spending trends analyse kar rahe ho, shayad customer names ki zaroorat nahi. Agar ek specific account reconcile kar rahe ho, identifier zaroori hai.
Redaction Magic Nahi Hai
Route Utna Hi Matter Karta Hai Jitna Tool Ka Naam
Sawal ye nahi hai “kya ye AI product approved hai?”, sawal ye hai: “kya ye specific route, is data, aur is purpose ke liye approved hai?”. Data apne collect hone ki wajah ke sath aati hai, ek gym members ka phone number class reminders ke liye rakhta hai, wahi numbers supplements bechne ke liye use karna ek alag purpose hai. Naya AI workflow chalane se pehle poocho ke jis purpose ke liye data collect hua tha, kya wo is use ko cover karta hai.
Controls Narrower Sawal Answer Karte Hain
Part 3 · The Capability: Kya Main Ye On Kar Sakta Hoon?
Sawal ab sirf “kya main model pe trust karta hoon” nahi hai, ye hai: “is session ya agent mein main kya authority add kar raha hoon?”
Sabse Zaroori Fact
5 checks chalao:
- Source: kisne banaya ya publish kiya?
- Reach: jis environment mein ye chalti hai, kya data, files, systems, tools, ya credentials touch kar sakti hai?
- Fit: kya ye reach us kaam ke proportionate hai jo aapko chahiye?
- Outside content: kya ye web pages, incoming email, customer files, shared documents parhegi?
- Actions: kya ye send, pay, delete, publish, edit, ya kisi hard-to-reverse change ka sabab ban sakti hai?
Enable
Source pata hai, reach proportionate hai, task fit karta hai, actions controlled hain
Escalate
Kuch important establish nahi ho pa raha: source uncertain, reach broad, ya security implications role se bahar
Decline
Reach clearly disproportionate, ya trust establish nahi ho sakta
Ehtiyat
Trusted Tool, Untrusted Content
Ek capability trusted publisher se aa sakti hai aur phir bhi wo content parh sakti hai jo kisi na-trusted ne likha ho. Isay prompt injection kehte hain.
“Tool kisne likha aur content kisne likha, ye 2 alag trust sawal hain.”
Risk sabse zyada tab barhta hai jab ek AI workflow untrusted content parhta bhi hai aur consequential actions le sakta hai. Ordinary knowledge work ke liye default: AI ko sirf wahi parhne do jo zaroori hai, read-only access ko prefer karo jab kaafi ho, aur send/publish/pay/ delete/approve ko ek defined human gate ke peeche rakho jab tak workflow ne higher autonomy earn na ki ho.
Agent Builders Ke Liye
Part 4 · The People: Kya Ye Kisi Ko Unfairly Affect Karega?
Pehle 3 sawal mostly organisation aur uski information ko protect karte hain. Ye sawal bahar dekhta hai:
- Kaun affect ho raha hai, un logon samet jo output kabhi dekhte hi nahi?
- Unke liye kya galat ho sakta hai?
- Kya wo notice ya challenge kar payenge?
- Ek fair process kaisa dikhega?
- Kya disclosure zaroori hai, ya AI involvement unke liye reasonably matter karti hai?
Jo Exclude Hua Wo Dekho
Disclosure: Pehle Rules, Phir Judgment
- 1
Pehle: Kya Disclosure Required Hai?
Law, policy, contract, professional rules, client commitments check karo. Agar koi require karta hai, decision ho chuka
- 2
Doosra: Agar Koi Rule Nahi
Kya AI involvement is insaan ki work ya relationship ki understanding badal degi? Consequential ya relational work zyada transparency deserve karti hai
2 disclosure cases baar baar aati hain: Authorship (jo kaam aapke naam se jata hai wo aapka hai use stand karne ke liye, chahe AI ne kitna bhi draft kiya ho) aur meeting notetaker (chaaron sawal ek sath touch karti hai, sabko announce karo shuru mein, kuch jurisdictions mein har participant ki consent chahiye).
Sawal Escalate Karo, Verdict Nahi
3 signals mein se koi ek kaafi hai:
- Affected population bada hai
- Potential harm significant hai
- Sawal aisi area ko touch karta hai jahan aapki team ko standing hi nahi (law, contract, employment)
Weak Vs Strong Escalation
Part 5 · Sab Kuch Sath, Aur Incident
Ek Ordinary Workflow, Shuru Se Aakhir Tak
Ayesha ek logistics company mein operations lead hai. Weekly service-exception report AI se draft karwana chahti hai, phir account manager bhejta hai.
| Sawal | Answer |
|---|---|
| The Case | Appropriate with human review, deciding factor accountability. Gate: account manager delivery facts dispatch record se check kare, tone disputed accounts pe dekhe, bhejne se pehle |
| The Data | Yellow tier (customer names, shipment info), task ko identifiers chahiye (customer report), isliye specific workspace aur route confirm kiya |
| The Capability | Dispatch system connector, source internal platform team, reach sirf reporting tables, actions mein sending shamil nahi, read-only enable, sending account manager ke paas rehti hai |
| The People | Customers aur drivers/staff dono affected (free-text notes mein), fairness check: attribution dispatch record se match kare, disclosure contract/policy se check karo |
The Evidence (5th part): success measure (account managers check karte hain bhejne se pehle), failure threshold (koi bhi material factual error customer tak pahunche), monitor (Ayesha monthly sample review karti hai), residual risk (consistent wording bias sab reports mein individual checks se bach sakta hai, isliye sample review customers ke across bhi compare karta hai).
Governance Record: Ek Page Jo Meeting Se Bach Jaye
4 sawal aapke sar mein useful hain. Likh diye jayein to organisationally useful ban jate hain. Ek blank field ek guess kiye hue field se behtar hai, agar owner ya route pata nahi, OPEN QUESTION likho aur sahi banda dhoondo.
Jab Kuch Galat Ho Jaye
Governance ye promise nahi hai ke koi galti kabhi nahi hogi. Ye galtiyon ko itna jaldi surface karne ki ability hai ke contain ho sakein.
- 1
1. Spread Roko
Forward, repost, ya unnecessary new copies mat banao
- 2
2. Facts Record Karo
Kya hua, kaunsa data/output/action shamil tha, kaunsa route, kab, aur kya kahin aage gaya
- 3
3. Foran Report Karo
Apni organisation ke incident path se, sensitive cases mein timing legally matter karti hai
- 4
4. Facts Plainly Batao
Speculation aur self-defence avoid karo
- 5
5. Incident Owner Ki Instructions Follow Karo
Deletion, notification, disclosure jaise sawal khud decide mat karo
Ehtiyat
Part 6 · Habit Ko Zinda Rakho
Governance Kyun Drift Karti Hai
High-stakes decisions attention paate hain kyunke sab jante hain ye important hain. Routine decisions governance ke liye zyada khatarnak hain kyunke har ek itna chhota lagta hai ke count na ho. Ek insaan thodi aasan tool use karta hai. Ek human review ek glance ban jata hai. Ek connector project badalne ke baad bhi permission rakhta hai.
“Policy aur asal mein log jo karte hain, uske darmiyan jo faasla hai, wahin risk rehta hai. Isay Diligence gap kehte hain.”
Usage Audit Chalao
- Kaunse AI workflows actually use ho rahe hain?
- Unse actually kaunsa data guzarta hai?
- Kya defined human gates actually chali?
- Kaunse naye tools, Skills, connectors, ya permissions add huay?
- Model, feature, route, data, ya audience mein kya badla?
Process Audit Karo, Insaan Nahi
Friction Ka Rule
Agar approved path 10 steps leta hai aur unapproved path 1 step, log deadline ke neeche 1-step wala route dhoondh lenge. Isay shadow AI kehte hain, work data jo un tools/accounts se guzarta hai jo organisation ne kabhi approve nahi kiye. Jab bar bar workarounds dikhein, poocho: “approved way ko unsafe way se harder kya bana raha hai?” Ye ek fix, doosri reminder email se zyada risk kam kar sakta hai.
Agar Koi AI Policy Nahi Hai
Apni khud ki policy invent kar ke official ki tarah present mat karo. Sahi owner ke liye ek interim proposal banao:
- Approved AI products aur work data ke liye specific routes
- Ek chhoti list un data types ki jinhe use se pehle confirmation chahiye
- External ya consequential outputs ke liye human-gate rule
- Naye Skills, connectors, high-authority tools ke liye review rule
- Sawalon aur incidents ke liye ek named role ya channel
Workflow Badle To Dobara Check Karo
Model ya model family, feature ya retention behaviour, connector/Skill/permission/action, data type, outside content ka source, audience, error ki consequence, law/ policy/contract/vendor terms, in mein se koi badle to Governance Record dobara check karo. “Pichle saal approved tha” review skip karne ki wajah nahi hai agar jo approve hua tha wo ab wahi cheez nahi rehi.
One-Minute Checklist
| Sawal | Quick Check | Middle Answer Ke Liye |
|---|---|---|
| Case | Kya AI ye task responsibly kar sakta hai? | Defined human gate: who/what/when |
| Data | Kya ye information is route se ja sakti hai? | Ek control, data minimisation, ya confirmed approved route |
| Capability | Kya ye tool ya authority enable honi chahiye? | Ek specific security/admin review sawal |
| People | Kya ye logon ko affect kar sakti hai ya disclosure maangti hai? | Fairness check, disclosure, ya escalation |
Aakhri Sawal
Poora Course, Compressed
“Act karne se pehle classify karo. Agar answer beech mein hai, commitment ka naam lo. Phir likho ke kyun.”
- 4 sawal: The Case (kya AI kar sakta hai), The Data (kya andar ja sakti hai), The Capability (kya on karna hai), The People (kya kisi ko unfairly affect karega)
- Har sawal ke 3 jawab hain, middle wala hamesha ek commitment maangta hai: reviewer, control, ya route ka naam
- Ek defined gate who/what/when form mein likha jata hai, "human review karega" ek gate nahi hai
- Data ke liye: pehle classify karo, phir poocho identifiers chahiye ya sirf pattern, phir route confirm karo
- Ek Skill ki apni permission list nahi hoti, wo session ki poori reach ke sath chalti hai, isliye source/reach/fit check karo
- Prompt injection tab sabse khatarnak hai jab AI untrusted content parhta bhi hai aur consequential action bhi le sakta hai
- Jo exclude hua wo bhi sample karo, sirf jo bacha wo nahi, warna unfair filtering kabhi pakdi hi nahi jati
- Governance Record ek page hai: Case, Data, Capability, People, Evidence, owner, aur re-check triggers
- Incident ho to: spread roko, facts record karo, foran report karo, incident owner follow karo, evidence chupao mat
- Diligence gap wahan banti hai jahan policy aur asal practice mein faasla hota hai, fix friction hai, extra reminder nahi
Ab Khud Try Karo: Apna Governance Record Banao
Ek real workflow chuno jo aap own ya influence karte ho, jahan AI already help karta hai ya jald karega. Fictional ya already-approved example use karo, koi confidential material is exercise ke liye paste mat karo.
- 1
Block 1 · The Case
AI kya karta hai, human kya karta hai, classification, deciding factor, gate (who/what/when).
- 2
Block 2 · The Data
Kya data andar jata hai, uski tier, kya task ko identifiers chahiye, agar sensitive fields rahen to approved route.
- 3
Block 3 · The Capability
Har Skill/connector/tool ke liye: source, reach, fit, outside content, consequential actions, outcome (enable/escalate/decline).
- 4
Block 4 · The People
Kaun affected hai, kya harm plausible hai (exclusions samet), disclosure decision, kya escalate hona chahiye.
- 5
Block 5 · The Evidence
Success measure, failure threshold, monitoring owner/cadence, residual risk.
Ehtiyat
Governance Record: Copy Karo
GOVERNANCE RECORD Workflow: Owner: Date: THE CASE Classification: appropriate / appropriate with review / inappropriate Deciding factor: Gate: who what they verify when THE DATA Tier: green / yellow / red Does the task need the identifiers? yes / no Fields removed: Approved route: THE CAPABILITY Tools, Skills, connectors enabled: Source: Reach: Outside content it reads: Actions it must not take without review: THE PEOPLE Who is affected: Fairness check (including exclusions): Disclosure decision: Required by / judgment Open question or escalation: THE EVIDENCE Success measure: Failure threshold: Monitored by: How often: Residual risk: RE-CHECK IF: model, feature, data, audience, permission, policy, vendor term, or business consequence changes.
Aakhri Kadam
Is Chapter Ke Naye Terms
Exam ke liye ye poori glossary yaad rakho, koi bhi term skip mat karo:
| Term | Matlab |
|---|---|
| Delegation criteria | 4 screens jo decide karte hain AI ye kaam kare ya nahi: reversibility, consequence of error, human judgment/empathy, accountability |
| Appropriate with review | AI kaam kar sakta hai, lekin use hone se pehle ek specific human gate chalni chahiye |
| Defined gate | Ek review jo who, what, aur when naam leta hai |
| Deciding factor / load-bearing criterion | Wo factor jo classification ko actually carry kar raha hai |
| Accountability | Jawab kaun deta hai, ye kabhi tool ko transfer nahi hoti |
| Diligence | AI Fluency Framework ki competency, AI use ke liye responsibility lena, team scale pe iska matlab audit karna ke log actually kya kar rahe hain |
| Diligence gap | Policy jo maangti hai aur log actually jo karte hain, uske darmiyan ka faasla, yahin risk rehta hai |
| Data tier | Information handle karne ki simple classification (green/yellow/red) |
| Entry point / route | Specific tareeqa jis se data AI system tak pahunchti hai |
| Purpose | Wo wajah jiske liye data collect hui thi, naya use usi purpose se cover hona chahiye |
| Redaction | Wo fields hatana jo task ko nahi chahiye, AI tak pahunchne se pehle |
| Pseudonymisation | Identifiers ko labels se replace karna jabke reconnect karne ka tareeqa abhi bhi maujood ho |
| Anonymisation | Data ko is tarah transform karna ke wo organisation ke standard ke hisab se identify nahi ho sakta |
| The five checks | Source, reach, fit, outside content, actions, Skill/connector/tool trust check karne ke liye |
| Prompt injection | Malicious ya misleading instructions jo content ke andar hon (webpage, email, document) aur AI ko steer karne ki koshish karein |
| Least privilege | Ek insaan, service, ya agent ko sirf utni access dena jitni task ke liye chahiye |
| Shadow AI | Work data jo un AI tools/accounts se guzarta hai jo organisation ne kabhi approve nahi kiye |
| Residual risk | Jo abhi bhi galat ho sakta hai jab planned controls apni design ke hisab se kaam karein |
| Governance Record | Ek workflow ke Case, Data, Capability, People, evidence, owner, aur re-check triggers ka one-page summary |
Source Note
Self-Test
Khud Se Poocho
Pehle khud answer do, phir sawal pe click kar ke answer check karo.

