Businesses deploying automated decision systems face obligations from several directions, and a governance structure addresses them together.

Inventory. Every system in use, what it decides or recommends, the data it uses, whether the output is reviewed by a person, and which business owns it. Most organisations cannot answer these questions, which is where governance begins.

Risk classification. Systems affecting employment, credit, housing, insurance, education and essential services carry the highest legal exposure, because existing discrimination and consumer protection law applies to them directly.

Assessment. Documented evaluation of purpose, data provenance, testing for disparate impact, accuracy, and the availability of a human review path. Increasingly required by statute for defined uses.

Vendor management. Contractual rights to audit, to obtain the vendor’s testing results, to be notified of material model changes, and indemnity.

Disclosure. Notice to affected individuals in a growing number of jurisdictions, and in some, an explanation of the factors used.

Intellectual property and confidentiality. Rules on what may be entered into external systems, since inputs may be retained and used.

Accuracy obligations. Existing law about the accuracy of representations applies regardless of how the statement was generated.