The AI Governance Cycle: A practical approach for building AI designed for trust
AI governance isn't a final review step. It's the work that helps teams build, launch, and monitor AI with trust baked in from the start. At Dayforce, that means using a repeatable governance cycle to ask the hard questions early, keep risk proportional, and make sure every model stays explainable, defensible, and human-centered.

Table of Contents
Every organization I talk to wants the same two things from AI: results they can rely on, and a clear conscience about how those results were produced. The hard part is that you cannot bolt either one on at the end. Trust is not a disclaimer you add the week before launch; it is supported by dozens of small, deliberate decisions made long before a model ever meets a customer.
At Dayforce, we made those decisions early and visible. We built a single, repeatable governance cycle that carries an idea from the first sketch on a whiteboard all the way through release and into the years it spends running in production. It is the same discipline that earned us certification to ISO/IEC 42001 and alignment with the NIST AI Risk Management Framework — but more importantly, it is the discipline that helps us explain to a customer, plainly, the factors that inform how a feature is designed to behave.
The cycle has nine checkpoints, organized into three lenses — Review, Action, and Manage. Each lens has a clear owner, and each checkpoint asks a question that must be answered honestly before the work moves forward.
Here is the cycle itself, followed by a plain-language tour of why each question matters.
Read it as a loop, not a list. Review decides whether an idea deserves to be built. Action governs how it gets built. Manage helps keep it honest once it is live and feeds what it learns back to the top, where the next idea begins. Think of the arrow images as an on ramp or off ramp for the idea.
How our data and AI governance team is structured
Keeping in mind the size of Dayforce, we have a team including a Director of Data & AI Governance as well as two supporting individuals. This team currently reports into the Chief AI Officer (CAIO) but could as readily report into the Chief Privacy Officer (CPO). This team reviews inbound ideation from the process. Based on their experience, there may be requests that are similar to those which have been processed before and may be assessed as lower risk based on prior review patterns. In these cases, the team handles those ideas while still going through the process.
In instances where there is ambiguity or a specific level of expertise, the Director using JIRA includes others from an expertise perspective which can include the CPO, CAIO, or members of their teams with deep domain expertise as required in the data and application of AI. Notes and decisions are captured within JIRA, but any system that allows the capture of answers would suffice initially.
Dayforce also uses an external AI Ethics Council comprising individuals who have expertise in their field coming from government, not-for-profit, education, and commercial backgrounds. This independent council is used as a sounding board for ideas in general, the “can we” vs. “should we” types of questions. Given the exceptionally sensitive nature of employee data, having this external perspective steers us toward maintaining a strong view on AI Ethics and their application in the product.
The Review lens — deciding what deserves to be built
Owners: Data & AI Governance Team, Chief AI Officer, and Chief Privacy Officer. The job here is not to build anything. It is to protect everyone’s time and the customer’s trust by being willing to say “not like this” early, while it is still cheap (as nothing is being built yet).
1. AI Idea
Everything starts as an idea1 submitted through a formal front door rather than a hallway conversation. That single intake does three quiet but important things: 1) it creates awareness so two teams don’t unknowingly build the same thing, 2) it helps reduce the risk that data is touched before an idea has been validated, and 3) it routes the idea to the people best placed to review it2. An idea that is never written down can never be governed.
2. Is AI necessary?
This is the most useful question we ask, and the one most often skipped elsewhere. In our own experience, roughly three out of six ideas that arrive labelled “AI” turn out not to need it. In many cases, a set of rules or a decision tree would be more accurate, more explainable, and easier to defend. Asking whether the problem genuinely requires machine learning spares customers unnecessary complexity and keeps us focused on the problems where AI truly earns its place.
3. Is quality data available?
A model is only ever as good as the data beneath it; quality data is what helps support accuracy, fairness, and more dependable predictions in the first place. So before anyone uses our data lake to consider a model or writes code, we ask whether the right data exists, whether we have an appropriate legal basis or approved rights to use it, whether it is representative rather than a snapshot of one moment, and whether we are using the minimum needed for the task. When the honest answer is “not yet,” the idea is parked, not forced.
4. Regulatory / privacy issues?
AI law today is a fast-moving patchwork — AI-related legal requirements continue to evolve across jurisdictions, including the EU and several U.S. states (e.g., Colorado, California, Texas, Illinois, New York ). Our Global Privacy Office, specifically our Chief Privacy Officer, reviews ideas that have progressed against this landscape early, to help catch a compliance problem as a design choice to help reduce the risk of discovering it later as a liability. We map each system to a defined risk tier and design them to help keep a human in control of consequential decisions, because more explainable systems are easier to support with customers, regulators, and other stakeholders.
AI governance should be proportional to risk. A one-size-fits-all governance model does not scale effectively across the wide variety of AI use cases organizations encounter. Applying the highest level of review and oversight to every AI initiative can significantly slow innovation and reduce the ability to realize business value. Conversely, governance that is too limited can create legal, regulatory, reputational, and operational exposure. For this reason, Dayforce adopted a risk-tiered governance approach that is designed to align oversight activities with the potential impact of the AI system.
At the highest risk level are prohibited use cases. These are applications that involve practices such as manipulation, deception, social scoring, or certain forms of biometric and emotional surveillance that present unacceptable risks to individuals. For example, an AI system that analyzes employee emotions during virtual meetings and uses those scores to influence termination or layoff decisions would fall into this category. In these situations, the governance outcome is straightforward: the solution would not be approved for deployment.
The next category consists of high-risk systems. These are systems that can significantly affect an individual’s rights, opportunities, safety, or livelihood. Examples include AI systems used in hiring, promotion, lending, healthcare, or other consequential decision-making contexts. High-risk systems are not necessarily rejected from deployment, but they require the strongest governance controls and mitigation measures. Such controls may include human oversight, transparency, explainability, testing for bias, ongoing monitoring, and documented risk assessments. The objective is to help reduce the likelihood and impact of harm while supporting decisions that are accountable and defensible. This is where governance activities are most rigorous because the consequences of failure can be significant. Consistent with modern AI risk management approaches, governance should focus on managing impacts to individuals, organizations, and society while supporting systems that are designed to be trustworthy and accountable. 
Medium-risk systems represent the majority of AI deployments reviewed within many organizations. These systems may create privacy, reputational, or misinformation-related risks, but are not intended to directly determine major life outcomes. Examples include conversational assistants, chatbots, and productivity tools. For these systems, transparency becomes one of the most important governance controls. Users should understand when they are interacting with AI, recognize that outputs may not always be accurate, and apply appropriate human judgment when using AI-generated content. Additional controls may include monitoring, user guidance, and escalation paths when issues are identified.
Low-risk systems are generally more passive in nature and have limited potential to create meaningful harm. Examples include spam filtering, document classification, or similar background automation functions. Governance requirements for these systems are typically lighter and focus on basic oversight, monitoring, and transparency where users interact directly with AI-enabled functionality.
The key principle is that governance should scale proportionally to the potential impact on individuals, the level of regulatory exposure, and the degree of automation involved in decision-making. Once AI systems are classified according to risk, governance becomes operational rather than theoretical. This can help enable organizations to move quickly and innovate responsibly while maintaining appropriate safeguards, accountability, and defensibility.
The Action lens — building it well
Owners: Product, the Chief AI Officer’s team, and Data Science. Governance does not pause here; it becomes the quality bar the build has to clear.
5. Diverse team
Bias rarely arrives through bad intent; it can arise from many sources, including narrow perspectives, incomplete data, or design choices. One vital control is involving a team broad enough to notice what any one person may miss. Different backgrounds, disciplines, and lived experience reinforced with the right subject matter and data-science expertise, internal or external. A diverse group asking “who might this work badly for?” is worth more than any single checklist.
6. Model quality and limitations
Before a model is ready for use, its owners have to be able to say what “good enough” actually means and show the model meets it. We look hard at measured accuracy, whether results hold up consistently across similar cases, and the edge cases where the model is known to struggle. Knowing precisely where a model is weak is not a failure of the work; it is the work.
7. Model bias and transparency
A model you cannot explain is a model you cannot defend, especially to a customer or a regulator. We examine training and test data for bias, document how the system reaches its conclusions, and capture it in explainability factsheets written in language a non-specialist can follow. Transparency is what helps turn a black box into something more understandable, so a customer can reasonably make more informed decisions about how to use it.3
It is important to note that although the double arrows do not appear between the steps of the Action process, each step is still an on/off ramp for whether the idea should proceed. If the quality of the model is too low to meet the requirements, or there are signs of bias, then the work needs to be sunset.
At Dayforce, we utilize a standard industry platform for the development of models starting from determining the appropriate type of model to be used as a basis for the AI, then being able to generate the analysis and reporting for bias and transparency. We also use the same platform to deploy and run the model as well as monitor the models for changes.
It is important to recognize that risk classification is not a one-time activity. The initial risk assessment is performed when the idea is first proposed, but AI systems often evolve as they move through design, development, testing, and implementation. New data sources may be introduced, additional functionality may be added, levels of automation may change, or the intended use case may expand beyond the original scope. Any of these changes can alter the overall risk profile of the system.
A final AI Impact Assessment is conducted prior to deployment to help confirm that identified relevant risks, controls, and governance requirements have been evaluated. The depth and scope of the assessment are determined by the system’s risk classification, with higher-risk systems requiring more comprehensive analysis, documentation, and evidence of mitigation. The completed assessment serves as the authoritative record of the system’s intended purpose, stakeholders, data, controls, and potential impacts. Once approved, the AI system is registered within our AI governance platform and mapped against applicable regulatory requirements, industry standards, and voluntary frameworks. This creates a centralized inventory designed to support ongoing governance, compliance monitoring, audit readiness, and alignment with evolving AI obligations and best practices.
The Manage lens — keeping it trustworthy
Owners: the Data & AI Governance Team, engineering (IT), cloud organization, and trusted third parties. A model is not “done” at launch4; in many ways, that is when the ongoing responsibility begins.
8. Deploy and monitor
Unlike ordinary software, a model can drift — its behavior can change as the data flowing through it changes, without a single line of code being touched. So once a feature is live, we monitor it on an ongoing basis for drift, apply the relevant compliance controls across the regions it serves, and keep a human in the loop. If anything material changes, the feature is designed to come back through the cycle rather than quietly carrying on.
9. Third-party audit
For our higher-risk AI models, our own confidence is not the final word. We commission independent bias and fairness audits so an outside expert can check our work against evolving legal and ethical expectations. The goal here is to help identify, assess, and reduce the risk of “adverse” or “disparate” impactv. What those audits surface flows straight back to the top of the cycle — which is exactly why the blueprint is drawn as a circle, not a line.
Why the cycle earns trust
None of these nine steps or questions is exotic. Their power comes from being asked consistently, through a repeatable process, by people who are accountable for the answer. Together they turn our seven AI ethics principles; social good, privacy and security, transparency, inclusion, reliability, accountability, and sustainability from a poster on the wall into a process with real outcomes.
It is also why every AI-enhanced feature in Dayforce is AI by Choice: you can turn it on or off, our AI insights are designed to support the human in the loop who makes the final call, and each feature that ships has gone through a documented process to promote explainability. Governance done this way is designed not to slow innovation down. Built properly, it is the very thing that can help you speed up — because you have a documented basis for understanding the decisions, risks, and controls behind what was shipped.
If you would like to talk through how this cycle could shape your own AI program, your Dayforce representative can connect you with our AI Governance team.
Disclaimer: The information provided in this post is provided for informational purposes only and should not be relied upon or construed as legal advice and does not create an attorney-client relationship. You should review with your legal advisors how the laws identified in this post may apply to your specific situation.
Endnotes:
1. At Dayforce, we capture all initial ideas through a simple JIRA form with 6 business questions as the starting point. This allows for tracking of ideas and reporting on the status, SLA, and acceptance, rejection or ongoing discussion.
2. An important aspect of the initial ideation process is that our governance team does not decide whether the idea has merit; they are assessing the idea against the first 3 questions in the review process.
3. It is important to note that not all AI models are effectively transparent. A discriminative model is likely to be far more transparent than a generative one depending on use. A discriminative model is producing a prediction based on data (such as predicting the price of a home based on square footage) while a generative model is actually creating new content. Given the vast training data within a Large Language Model (LLM) and the way in which they generate a token from the prompt, they do not support full human interpretability, as the process is simply too complex.
4. It’s important to realize that models within AI can become somewhat “organic”. Specifically, if they are models that continue to learn on new data, then the behavior of the models (more specifically discriminative models) may change their predictions over time. Generative models can also change each time they go through a training cycle (usually a new model is produced due to time and cost).
You may also like:
Ready to get started?
