Responsible AI Policy Development - A GOVERNANCE PLAYBOOK
Responsible AI Policy Development - A GOVERNANCE PLAYBOOK
A GOVERNANCE
PLAYBOOK
September 2025
PRELUDE
AI is no longer a distant prospect; it is increasingly This is why AI governance must strike a careful
shaping industries, business models, and workforce balance between risk mitigation and enablement. The
expectations. Ignoring its impacts, therefore, is no objective is to create the conditions for responsible
longer an option. For organisations, the challenge is experimentation, measured adoption, and continuous
no longer whether to adopt AI but how to adopt it learning. Boards and governance professionals can
responsibly. As AI becomes embedded in core business support this by enabling safe “sandbox” pilots, setting
processes and decision-making, the need for a clear, clear oversight parameters, and scaling successful
well-governed AI policy has become pressing, which is use cases with appropriate controls. Overly rigid
the subject of this governance playbook. frameworks may protect the organisation from present
risks, while limiting its capacity to respond and adapt to
Organisations must first clarify ownership of their tomorrow’s opportunities and challenges.
AI policy. Oversight should sit at a sufficiently senior
level, typically the board or a delegated risk or Governance professionals are uniquely positioned to
technology committee, to ensure strategic alignment make this balance work in practice. They bridge the
and accountability for outcomes. The board’s role is board, management, and operational teams, translating
to approve the AI policy, set risk appetite, and monitor regulatory expectations into practical policies and
management’s progress in implementation. embedding accountability, transparency, and ethical
standards across the organisation. By ensuring that
Senior management should be responsible for drafting governance is both a guardrail and a catalyst, they
and maintaining the policy, drawing input from help organisations turn AI governance from a brake on
key stakeholders, including IT, cybersecurity, data progress into a driver of sustainable growth.
governance, legal, compliance, risk management, HR
(to address workforce impact), and business leaders
adopting AI solutions. Premature or poorly governed
adoption can create legal, ethical, and reputational
harms. Implementation should be operationalised
by cross-functional teams so that controls, ethical
standards, and regulatory requirements are embedded
into daily processes. Periodic review and regular board-
level reporting on AI risks, benefits, and incidents
should ensure that the policy remains current as
technology, regulations, and business priorities evolve.
01 Executive Summary
03 CHAPTER 1
AI Governance Matters
10 CHAPTER 2
Operationalising AI Governance
14 CHAPTER 3
Dynamic AI Governance:
Building Policies That Evolve
18 CHAPTER 4
Responsible AI Policy Framework
and Example
24 CHAPTER 5
Director Briefing Template
29 CHAPTER 6
Conclusion
EXECUTIVE
SUMMARY
Responsible AI Policy Development: A Governance Playbook
This playbook provides governance professionals, directors, and senior management with
practical tools to develop tailored AI governance frameworks that strike a balance between
innovation, ethical responsibility, and risk management.
Responsible AI Policy Development: A Governance Playbook | 2
- Build a Use Case Inventory - Maintain a central - Treat Policy Development as a Living Process
registry of all AI systems, capturing purpose, - Establish regular review cycles to keep
data sources, risk level, and ownership. You frameworks current as regulations evolve and
can't govern what you can't see. risks emerge. A static policy is a risk.
- Translate Principles into Practice - Link fairness - Equip Boards and Staff with the Right
to bias audits, transparency to explainability Questions - Provide tailored guidance through
standards, and accountability to escalation practical tools like risk checklists and oversight
protocols. Make values operational. questions to build a culture of accountability.
2: Operationalising AI Governance Use case inventories, risk assessments, lifecycle oversight tools
4. Key Takeaway
AI governance requires tailored approaches—not one-size-fits-all solutions. This playbook helps organizations build
frameworks aligned with their unique risk profiles, regulatory obligations, and values while maintaining flexibility to
evolve with technology and regulation.
3 | Responsible AI Policy Development: A Governance Playbook
CHAPTER 1
AI GOVERNANCE
MATTERS
privacy violations, and security breaches.3 These • Foster trust and open communication with
risks can, in turn, cause operational disruptions, internal and external stakeholders, promoting
damage stakeholder trust, and jeopardise stakeholder inclusive and socially grounded applications of
relationships with partners, regulators, and the public.4 AI.12
Effective application requires a clear understanding of • Mitigate downstream and systemic risks,
what AI systems can and cannot do, as well as ongoing particularly where these disproportionately
oversight to ensure they align with organisational impact vulnerable groups or the environment.13
goals, ethical standards, and regulatory requirements.5
Governance professionals play a vital leadership • Facilitate responsible innovation, enabling
role in bringing these governance issues to the fore, teams to deploy and scale AI solutions
ensuring that AI is not adopted as a purely technical confidently where appropriate - knowing that
or commercial tool but as a capability that demands clear guidelines, redress pathways and risk
proper oversight, alignment with purpose, and controls are in place.14
accountability across the organisation.
5 | Responsible AI Policy Development: A Governance Playbook
This section offers a generalised picture of the regulatory landscape in Hong Kong, and should be read alongside
emerging regulatory developments in jurisdictions of operation:
Hong Kong has adopted a context‑specific, sector‑led approach to AI governance,15 rather than introducing
a single, overarching law like the EU AI Act. Instead, the government has relied on existing laws and sectoral
guidelines, supplemented by voluntary frameworks, to manage AI‑related risks.16 Across industries, two Hong Kong
government bodies have taken the lead in promulgating AI standards:
While compliance with these frameworks is voluntary, the underlying Personal Data and Privacy Ordinance (PDPO)
obligations are not. As of February 2025, the PCPD have launched a new round of AI security compliance checks for
organisations across various sectors, including telecommunications, banking and finance, insurance, beauty services,
retail, transportation, education, medical services, public utilities, social services and government departments.21
Moreover, a range of sector-specific circulars have been published by industry bodies - most notably in banking and
finance,22 healthcare,23 and insurance.24 So while the regulatory landscape remains fragmented, AI governance in
Hong Kong is already enforceable through existing laws and sectoral guidance in the absence of specific legislation.
Consequently, the above standards increasingly reflect what regulators expect to see during investigations, reviews, or
licensing. Governance professionals should therefore treat voluntary frameworks as practical compliance imperatives,
as these quickly become de facto expectations in boardrooms and compliance reviews.
Responsible AI Policy Development: A Governance Playbook | 6
❶ OECD AI Principles;
25
Fairness.
Reliability & Safety.
Privacy & Security.
Inclusiveness.
Transparency.
Accountability.
The chart below distils the six core principles and their implications, illustrating how each principle might show up
in governance. As a starting framework, the issues outlined are not a complete catalogue. But for each principle,
we flag representative risk categories to show the path from value statement to operational exposure. Governance
professionals should therefore expand or revise this mapping to reflect their own sector, jurisdictions, impact profile
and emerging external standards, then design controls in proportion to the level of risk identified:
1. Fairness
Fairness asks whether an AI system treats individuals without discrimination and avoids unjustified
disparate impact across protected or vulnerable groups. In practice, this covers training data
representativeness, model design choices, and outcome monitoring.
4. Inclusiveness
Inclusiveness asks whether AI systems are accessible, usable and beneficial across demographic,
linguistic, cultural and disability dimensions, and whether they avoid creating new digital divides.
5. Transparency
Transparency covers both model explainability (stakeholders can understand how outputs were
produced), and organisational disclosure (being open about AI usage, limitations and governance).
This includes internal traceability, user-facing explanations, documentation of design choices, and
openness about limitations and risks.44
6. Accountability
Accountability ensures that clear ownership, oversight, and redress mechanisms are in place for
the design, deployment, and impact of AI systems. In other words, that identifiable humans, and
ultimately the board, remain answerable for AI-generated outcomes, with clear mechanisms to
trace responsibilities, remedy harms, and learn from incidents. It includes assigning responsibility
across functions, tracking decisions, and ensuring consequences for misuse or failure.
The AI Policy must reflect whole-of-organisation • Draft a Policy Charter and Gap Assessment.
participation, not only from governance, legal, and IT, Map existing policies (e.g., cybersecurity,
but also from business heads, operations, marketing, procurement, data protection) to identify
HR, and internal audit. Senior management ownership overlaps and blind spots.
or buy-in is critical for sustained adoption and
effectiveness. • Define Oversight and Review Mechanisms.
Integrate AI governance into existing board risk
• Initiate Leadership Engagement. Secure board or ethics committees, with regular reporting
support and appoint a cross-functional lead and oversight to ensure effective management.
group reporting to senior management.
CHAPTER 2
OPERATIONALISING
AI GOVERNANCE
2.1 Introduction: Governance as AI Use This means moving beyond reactive measures to embed
Matures ethical considerations and accountability across the
organisation. Governance professionals should take the
As organisations deploy more sophisticated AI systems, lead in:
such as large language models, predictive analytics,
and automated decision-making tools, additional • Interpreting each principle from an internal
governance challenges emerge. Legal exposure, governance lens.
stakeholder scrutiny, and operational complexity tend
to rise sharply. • Translating abstract values into policy elements.
At this stage, the governance professional should play • Embedding policy elements into an end-to-end
a critical role in translating principles into practice. accountability framework.
Acting as a facilitator, the governance professional
connects technical, legal, and business functions, • Ensuring the board and senior management
ensuring that responsible AI practices are integrated understand their oversight responsibilities.
into daily operations, risk frameworks, and compliance
structures. They also connect and align with external • Engaging operational teams to design and
stakeholders, such as regulatory bodies, and assume implement meaningful processes.
the roles of horizon scanning and liaison.
The governance professional should coordinate
2.2 Translating Risks into Governance: risk-mapping workshops across functions, adapting
Promoting End-to-End Accountability oversight structures to reflect the nature and purpose
of AI applications. The table below provides a non-
For chartered governance professionals, the imperative exhaustive list of governance actions that teams can
is clear: establish robust internal governance structures consider:
that proactively manage AI risks across its lifecycle.
11 | Responsible AI Policy Development: A Governance Playbook
Fairness ✔ Require fairness audits before and after deployment to detect harms and address bias
over time.
✔ Ensure human-in-the-loop oversight in critical decisions, particularly to catch edge cases
not handled well by automation.
✔ Use diverse, representative and up-to-date datasets, documenting provenance, gaps and
limitations.
✔ Define and approve fairness metrics, drawing from broad stakeholder input.
✔ Secure board approval of chosen fairness trade-offs through a metric-justification memo.
✔ Establish clear escalation and remediation processes if unfair outcomes are detected.
Reliability ✔ Introduce red-teaming protocols, stress testing and scenario planning, simulating
& Safety technical and/or organisational failures.
✔ Maintain fallback procedures and post-launch safety checks.
✔ Conduct robust testing and validation, redundancy, and fail-safes.
✔ Establish model performance benchmarks to validate outputs under expected, edge-case
and adversarial conditions.
✔ Monitor for hallucination and model drift.
✔ Utilise intrusion detection, data encryption, and secure channels, and perform regular
data audits.
Privacy ✔ Map data flows and perform thorough legal/privacy compliance reviews of all AI systems.
& Security ✔ Employ adversarial testing: Test for inversion attacks, membership inference attacks,
prompt injection and data leakage.
✔ Ensure board-level visibility over AI incident response readiness.
✔ Extend privacy and security requirements to third‑party vendors through contracts,
audits, and monitoring.
Inclusiveness ✔ Conduct inclusive user testing and solicit feedback from diverse communities during
design and post-deployment.
✔ Use diverse and representative datasets, inclusive design principles, and social impact
assessments to mitigate and monitor exclusionary outcomes.
✔ Integrate inclusiveness KPIs into internal risk reporting.
Accountability ✔ Establish a governance structure that identifies responsible individuals and outlines clear
escalation paths for addressing issues.
✔ Require vendor accountability clauses covering risk disclosures, remediation obligations,
and audit rights.
✔ Develop clear internal guidelines for employees on using AI responsibly.
✔ Support board committees in reviewing AI risk reporting and approving deployments.
✔ Foster a culture of ownership, where AI accountability is not outsourced to vendors or
technical teams.
Responsible AI Policy Development: A Governance Playbook | 12
To embed AI oversight into everyday processes, the governance professional should help develop and promote
internal governance instruments tailored to the organisation's AI maturity and risk profile.
Establish a central inventory of all AI systems in use. This registry enables internal visibility and facilitates board-
level oversight. Suggested inputs are:
✔ Business owner and system purpose
✔ Model type and data sources
✔ Risk classification (e.g. customer impact, regulatory sensitivity)
✔ Explainability level and lifecycle stage
Additional documents:
✔ Product requirements document (PRD)
✔ Stakeholder mapping (clarifying who is affected and who should be consulted)
✔ System mapping (flow of inputs into model to outputs to downstream impacts)
Integrate AI-specific questions into existing enterprise risk assessments or product development checklists to
enhance their effectiveness and accuracy.
A failure modes and effects analysis (FMEA) and "what-if" anticipatory scenario worksheet can facilitate the
early identification of downstream impacts, promoting proactive risk mitigation.48
13 | Responsible AI Policy Development: A Governance Playbook
The governance professional should require all teams deploying AI to complete standardised documentation,
addressing:
✔ Intended use and limitations
✔ Data used for training and validation
✔ Bias mitigation techniques
✔ Explainability, performance, and safety metrics
For high-risk or novel use cases, the governance professional should convene an oversight forum—either an
existing committee or a new review board—drawing on legal, compliance, technical, and risk functions.
The forum should conduct and review social impact assessments to make "go / no-go / revise" decisions.52 It should
be empowered to delay or reject deployments until mitigations, risk thresholds and critical stakeholder concerns
are addressed.
As AI systems become integrated and scaled in workflows over time, the governance professional must
continuously oversee their impacts. Oversight tools include:
✔ Real‑time dashboards for performance drift, bias drift, hallucination rates and security anomalies;
✔ Using audit checklists to ensure document completeness;
✔ Scheduled re‑audits and red‑team tests after material changes or system updates;
✔ Regular reviews of remediation and risk mitigation plans
CHAPTER 3
DYNAMIC AI GOVERNANCE:
BUILDING POLICIES THAT
EVOLVE
15 | Responsible AI Policy Development: A Governance Playbook
AI governance must adapt to rapid changes in use cases, • Construct "user stories" to understand an AI's
stakeholder expectations, and regulatory requirements. functionality from a particular user's view.54
A well-structured review process ensures that AI
policies remain relevant and effective. • Delivering targeted training for business
functions on the AI policy's practical
Recommended actions: implications.
• Establish a regular review cycle (e.g. every 6–12 • Record and integrate lessons learned into
months), embedded into board and committee future risk assessments, policy updates,
agendas (with a focus on fairness, safety, training, and design standards. Ensure cross-
reliability and risk). functional input (legal, compliance, IT, user
teams) to generate comprehensive insights.
• Trigger ad hoc reviews in response to, for
example, material AI-related incidents or • Actively track AI-related developments
near misses; high-impact or experimental (regulatory, technological, best practices), and
deployments; and significant regulatory how peers are operationalising their AI policies.
changes (e.g. EU AI Act, China's AI regulations,
updates in data protection laws). The governance professional's role is to ensure this
reflection is formal and part of the governance culture.
• Ensure inclusive review participation, involving
legal, risk, IT, operations, compliance, and
frontline units.
Responsible AI Policy Development: A Governance Playbook | 16
• Benchmark and gather external intelligence, • Conduct scenario planning and reputational
regularly scanning the environment to see how risk assessments for novel or high-profile AI
other organisations and sectors are governing initiatives.
AI and integrating lessons learned and best
practices. By reinforcing escalation pathways and promoting
open dialogue, governance professionals create a
• Prepare emergency fallback mechanisms pre- culture of early issue resolution, strategic foresight, and
deployment. responsible innovation.
• Ensure retired models are decommissioned 3.6 Building Trust and Delivering Value
with no unintended residual influence.
In today's fast-moving AI environment, a static policy
These help reduce blind spots, support transparency, is a risk. AI governance must be treated as an ongoing,
and enable effective institutional learning. organisation-wide effort—one that evolves in step with
operational realities, stakeholder expectations, and
3.5 Strategic Enablement: Supporting AI regulatory shifts.
Innovation with Confidence
Governance professionals play a crucial role in this
Governance professionals must help organisations journey. By leading review cycles, promoting learning,
strike a balance between control and enablement, fostering coordination, and supporting innovation,
ensuring that responsible governance does not stifle they help transform AI governance from a compliance
innovation but builds the foundation for sustainable obligation into a source of strategic advantage.
adoption. A restrictive framework can inadvertently With the right structure and mindset, governance
slow innovation and erode competitiveness. Strategic professionals can ensure their organisations govern
enablement involves assessing both risk and AI with confidence, responsibly, resiliently, and in the
opportunity, ensuring that high-potential use cases public interest.
receive appropriate support and guardrails rather than
blanket rejection. Some organisations deploy 'sandbox'
environments, allowing safe experimentation under
controlled conditions, followed by scaled deployment
once risks are addressed.
Recommended actions:
CHAPTER 4
RESPONSIBLE AI POLICY
FRAMEWORK AND EXAMPLE
19 | Responsible AI Policy Development: A Governance Playbook
This chapter offers a sample AI Policy template for This sample policy is non-exhaustive and illustrative,
organisations seeking to formally codify their AI and should be adapted and expanded in consultation
governance practices. This template is designed to help with legal, risk, compliance, and technical teams to
governance professionals facilitate the development of reflect the organisation's specific risk profile, business
a policy that is: model, internal structure, decision-making culture,
applicable laws and regulations, and the types of AI
• Aligned with international best practices and technologies used, as these technologies bring their
evolving regulatory frameworks; own nuances:
• Rooted in organisational values and risk • Tier 1: Minimum Viable AI Policy - Covers
priorities; essential elements such as core principles, key
requirements, basic governance structure, and
• Practical and enforceable across operational prohibited uses.
settings;
• Tier 2: Comprehensive Policy Additional
• Adaptive to technological and legal Elements – For mature or technology-forward
developments over time. organisations to consider adopting in addition
to Tier 1 elements, with the caveat that there is
Governance professionals are not expected to act as AI no one-size-fits-all.
developers or technologists. Their role is to coordinate
across functions, ensure appropriate oversight
structures, and help tailor policies that support
responsible, risk-informed innovation.
1. Policy Objective and Scope (please align to your numbering and formatting)
This AI Policy outlines the principles, governance roles, and operational controls that guide the development,
acquisition, deployment, and use of AI systems within [Organisation Name].
The purpose of this Policy is to ensure that AI is used safely, ethically, lawfully, and in alignment with our
organisational values, including privacy protection and responsible innovation.
2. Definitions
Term Definition
Artificial Intelligence (AI) A system that simulates human intelligence processes and performs
tasks normally requiring human intelligence, such as learning, reasoning,
problem-solving, and language understanding.
High-Risk AI An AI system that poses serious risks to health, safety or the fundamental
rights of protected groups
Generative AI AI that creates content (e.g. text, images, audio, video), including LLMs, by
learning patterns from existing data and generating original outputs.
3. Policy Principles
All AI systems used by [Organisation Name] must adhere to six Responsible AI principles:
✔ Fairness – Prevent discriminatory or biased outcomes. Conduct fairness audits where appropriate.
✔ Reliability & Safety – Ensure systems are stress-tested and robust, with fallback mechanisms.
✔ Privacy & Security – Comply with applicable data protection laws. Conduct privacy impact assessments
(PIAs), ensure lawful processing, and respect data subject rights.
✔ Inclusiveness – Design for accessibility and consider diverse user needs and impacts.
✔ Transparency – Inform users when AI is used. Ensure outputs are explainable where feasible.
✔ Accountability – Assign responsibility for AI decisions and outcomes. Maintain human oversight.
These principles reflect both legal and ethical imperatives, supporting long-term trust with customers, staff, and
regulators.
5. Operational Controls
✔ Risk Assessment: Assess AI systems for: ✔ Risk Assessment: Assess AI systems for:
• Ethical risks, bias, and explainability. • Data protection impact assessment
• Data privacy. (DPIA) outcomes.
• Cross-functional review for high-risk use
cases.
✔ Transparency and Notification: Notify users ✔ Transparency and Notification: Notify users
when AI is involved in decisions. when AI is involved in decisions. Disclose:
• The logic and potential impact of AI
tools.
• Rights to explanation, appeal, and human
review.
• Public performance metrics.
✔ Human Oversight
• Staff must retain responsibility and
intervene as needed.
• AI must not make unreviewed decisions
in critical contexts.
Responsible AI Policy Development: A Governance Playbook | 22
✔ Acceptable Use
• AI may enhance productivity, research, and customer service.
• Avoid inputting sensitive data into public AI platforms.
• AI-generated content must be human-validated before external use.
• Disclose AI involvement in communications and decisions.
✔ Prohibited Use
• Fabricated, defamatory, discriminatory, or misleading content.
• Unauthorised impersonation.
• Circumventing compliance or security controls.
• Unreviewed automated decisions affecting rights.
CHAPTER 5
DIRECTOR BRIEFING
TEMPLATE
25 | Responsible AI Policy Development: A Governance Playbook
Developing credible AI policies is not just a compliance exercise: it is a strategic act of governance. The governance
professional should anticipate the risks, frame the issues, and guide the process, but outcomes must be endorsed
by the board and co-owned by senior management. We now turn to how the governance professional can facilitate
directors in asking the right questions about AI implementation, interrogate key risks, and assess organisational
readiness.
What Every Director Needs to Know About AI: A Practical Governance Briefing
Prepared by: [Company Secretary/Governance Professional]
A reasonable director is not expected to understand how an algorithm works in code, but they are expected to
ensure the organisation is equipped to use AI responsibly and in accordance with the law. That includes:
✔ Understanding purpose.
✔ Clarifying risk.
✔ Setting expectations.
✔ Monitoring accountability.
✔ Supporting transparency.
By asking the right questions and relying on governance professionals to facilitate sound oversight, the board can
ensure that AI becomes an asset—not a liability—to the organisation's future.
1. Start With the Right Question: What Is the AI Being Deployed For?
As a director, you need to know where AI is being used in your organisation and what it's being used for. This is
the foundation for effective board oversight.
Ask:
✔ What decisions or processes are being influenced, supported, or made by AI?
✔ Who owns each AI system or use case?
✔ What business problem is it trying to solve — and why use AI to solve it?
These questions help determine whether the deployment is routine (e.g., email sorting), sensitive (e.g., recruitment
filtering), or high-risk (e.g., credit assessments or predictive policing).
AI is not inherently safe or neutral. Risks arise depending on how AI is trained, applied, and governed. Directors
should understand and probe the following (note: this is not an exhaustive list of risks):
✔ Bias and unfairness – Does the AI treat certain individuals or groups unfairly?
✔ Lack of transparency – Can we explain how the AI arrives at its decisions?
✔ Data misuse – Is personal or sensitive data being used lawfully and ethically?
✔ System failure – What happens if the AI fails or produces harmful outputs?
✔ Lack of accountability – Who is ultimately responsible for decisions made using AI?
These risks can lead to public backlash, regulatory fines, loss of stakeholder trust, or strategic damage, depending
on the location of the business operations and the applicable laws and regulations.
Responsible AI Policy Development: A Governance Playbook | 26
Your organisation should have a formally adopted AI Policy. It should not be just an IT policy, but a governance
framework shaped around the following six principles:
✔ Fairness – Avoid discrimination or bias.
✔ Reliability and Safety – Ensure the system performs as intended, even under pressure.
✔ Privacy and Security – Comply with laws, protect personal data.
✔ Inclusiveness – Serve all user groups appropriately.
✔ Transparency – Make systems explainable to users and regulators.
✔ Accountability – Ensure human responsibility is never outsourced to a machine.
Directors should be familiar with these principles and ensure that they are reflected in their policies, risk
management practices, and organisational culture.
A reasonable director should ask: "Can you show me where AI is currently used in our business?"
This is the modern equivalent of knowing your organisation's financial systems or major contracts — it is about
visibility and control.
As a board member, you should not assume technical teams are "handling it". Ask:
✔ Is there clear ownership for each AI system?
✔ Who reports to the board on AI risk and performance?
✔ What happens when things go wrong?
✔ Are there examples of AI issues/risks that have emerged so far and if so, how have they been handled?
27 | Responsible AI Policy Development: A Governance Playbook
6. Board's Role: Ask the Right Questions and Expect the Right Information
55
✔ Inclusion & User Impact:
• Are AI systems tested across diverse user groups before deployment, particularly those at risk of
exclusion?
• Are model performance metrics (e.g. precision, recall) disaggregated by protected characteristics
such as race, gender, language, and disability?
• What benchmarks or frameworks guide our approach to inclusive AI design and deployment?
• Are accessibility and cultural considerations integrated into product development and model
evaluation?
• How are inclusive practices embedded into hiring, team composition, and vendor selection for AI
projects?
• Are exclusionary impacts monitored post-deployment, and how are findings acted upon?
✔ Incident Management:
• Are incident response and recovery plans in place for AI system failures, including clear roles and
cross-functional coordination?
• How are findings from model audits, complaints, near-misses, or observed harms integrated into
system redesign, oversight, and board reporting?
• When exclusionary or harmful outcomes are detected, what remediation pathways and escalation
processes are followed?
• How are breach detection, response, and notification protocols adapted for AI-specific risks?
Company secretaries, general counsels and governance professionals are not AI developers — but they are the
facilitators of responsible governance. They support the board by:
✔ Developing and maintaining the AI Policy.
✔ Coordinating the cross-functional AI use case inventory.
✔ Tracking regulatory developments and industry benchmarks.
✔ Facilitating training and awareness across functions.
✔ Ensuring board visibility of incidents, exceptions, and lessons learned.
You can expect your governance team to help translate complex technical risks into governance language — and
frame the right issues for board review.
CHAPTER 6
CONCLUSION
Thank you for taking the time to engage with HKCGI's Responsible AI
Governance Playbook. We encourage you to apply the tools, frameworks,
and engage in the activities described to embed responsible AI practices
into your governance processes.
REFERENCES AND
FURTHER READING
[1] See Collina, Luca, et al. "Critical Issues about A.I. Accountability [18] Privacy Commissioner's Office (Hong Kong). "Privacy Commissioner's
Answered." California Management Review Insights, 6 Nov. 2023, Office Publishes "Artificial Intelligence: Model Personal Data Protection
[Link]/2023/11/critical-issues-about-a-i-accountability- Framework."" [Link], 11 June 2024, [Link]/english/
answered/. news_events/media_statements/press_20240611.html.
[2] See Bender, Emily, et al. “On the Dangers of Stochastic Parrots: Can [19] Digital Policy Office. "Ethical Artificial Intelligence Framework | Digital
Language Models Be Too Big?” FAcc’21: Proceedings of the 2021 ACM Policy Office." [Link], 25 July 2024, [Link]/
Conference on Fairness, Accountability, and Transparency, 1 Mar. 2021, pp. en/our_work/data_governance/policies_standards/ethical_ai_framework/.
610–623, [Link]/ebender/papers/Stochastic_Parrots.
pdf, [Link] [20] Han, Sirui, et al. "Hong Kong Generative Artificial Intelligence Technical
and Application Guideline." SSRN Electronic Journal, 2025, www.
[3] See Schneider, Johannes, et al. "Governance of Generative Artificial [Link]/en/our_work/data_governance/policies_standards/
Intelligence for Companies." [Link], 5 Feb. 2024, ethical_ai_framework/doc/HK_Generative_AI_Technical_and_
[Link]/abs/2403.08802. Application_Guideline_en.pdf, [Link]
[4] See Bird & Bird. "AI Governance: Essential Insights for Organisations: [21] Privacy Commissioner's Office (Hong Kong). "PCPD Has Completed
Part I – Understanding Meaning, Challenges, Trends, and Best Practices Compliance Checks on 60 Organisations to Ensure AI Security." Pcpd.
in AI Governance." [Link], 2025, [Link]/en/ [Link], 8 May 2025, [Link]/english/news_events/media_
insights/2025/ai-governance-essential-insights-for-organisations-part-i- statements/press_20250508.html.
-understanding-meaning-challenges-trends-a.
[22] HK Monetary Authority. "HKMA Banking Regulatory Document
[5] See Hickman, Eleanore, and Martin Petrin. "Trustworthy AI and Repository." [Link], 2024, [Link]/eng/doc-ldg/
Corporate Governance: The EU's Ethics Guidelines for Trustworthy docId/20241122-3-EN.
Artificial Intelligence from a Company Law Perspective." European
Business Organization Law Review, vol. 22, no. 4, 6 Oct. 2021. [23] HK Department of Health. Medical Device Administrative Control System
(MDACS) Artificial Intelligence Medical Devices (AI-MD). 3 Jan. 2024.
[6] See Mökander, Jakob, et al. "Challenges and Best Practices in Corporate
AI Governance: Lessons from the Biopharmaceutical Industry." Frontiers [24] HK Insurance Authority. Conduct in Focus. 7 May 2023, [Link]/en/
in Computer Science, vol. 4, 10 Nov. 2022, [Link] legislative_framework/files/Eng_Conduct_in_Focus_7_May_23.pdf
fcomp.2022.1068361.
[8] See [3] [26] Infocomm Media Development Authority. "Singapore Model AI Governance
Framework." Infocomm Media Development Authority, 16 Jan. 2024,
[9] See Olteanu, Alexandra, et al. "Rigor in AI: Doing Rigorous AI Work [Link]/resources/press-releases-factsheets-and-speeches/
Requires a Broader, Responsible AI-Informed Conception of Rigor." ArXiv. press-releases/2024/public-consult-model-ai-governance-framework-
org, 2025, [Link]/abs/2506.14652. genai
[10] See [4] [27] European Parliament. "EU AI Act: First Regulation on Artificial
Intelligence." European Parliament, 8 June 2023, [Link].
[11] See Camilleri, Mark Anthony. "Artificial Intelligence Governance: Ethical eu/topics/en/article/20230601STO93804/eu-ai-act-first-regulation-on-
Considerations and Implications for Social Responsibility." Expert Systems, artificial-intelligence.
vol. 41, no. 7, 18 July 2023, [Link]
[28] European Parliament. "The General-Purpose AI Code of Practice." Shaping
[12] Ibid. Europe's Digital Future, 2025, [Link]/en/policies/
contents-code-gpai.
[13] See [2]
[29] National Institute of Standards and Technology. "AI Risk Management
Framework." NIST, 12 July 2023, [Link]/itl/ai-risk-management-
[14] See Raji, Inioluwa Deborah, et al. "Closing the AI Accountability Gap:
framework.
Defining an End-To-End Framework for Internal Algorithmic Auditing."
ArXiv:2001.00973 [Cs], 3 Jan. 2020, [Link]/abs/2001.00973.
[30] International Organisation for Standardisation. "ISO/IEC 42001:2023."
ISO, 2023, [Link]/standard/42001.
[15] See White & Case. "AI Watch: Global Regulatory Tracker - Hong Kong |
White & Case LLP." [Link], 6 June 2025, [Link]/
insight-our-thinking/ai-watch-global-regulatory-tracker-hong-kong [31] International Organisation for Standardisation. "ISO/IEC 23894:2023."
ISO, Feb. 2023, [Link]/standard/[Link].
[16] Ibid.
[32] Ashurst. "New Generative AI Measures in China." Ashurst, 26 Sept. 2023,
[Link]/en/insights/new-generative-ai-measures-in-china/.
[17] Privacy Commissioner's Office (Hong Kong). "Publishes Guidance on
Ethical Development and Use of AI and Inspection Report on Customers'
Personal Data Systems of Two Public Utility Companies." [Link], 18 [33] Microsoft. "Responsible AI Principles and Approach | Microsoft AI."
Aug. 2021, [Link]/english/news_events/media_statements/ [Link], 2024, [Link]/en-us/ai/principles-and-
press_20210818.html. approach.
31 | Responsible AI Policy Development: A Governance Playbook
[34] Ibid. [46] See Weidinger, Laura, et al. “Sociotechnical Safety Evaluation of
Generative AI Systems.” ArXiv (Cornell University), 18 Oct. 2023,
[35] See [3]. [Link]
[36] See [11]. [47] See Gesser, Avi. “Good AI Vendor Risk Management Is Hard, but Doable –
Debevoise Data Blog.” [Link], 26 Sept. 2024,
[Link]/2024/09/26/good-ai-vendor-risk-
[37] See [5]. management-is-hard-but-doable/. Accessed 1 Aug. 2025.
[38] See Huang, Lei, et al. “A Survey on Hallucination in Large Language [48] See [14]
Models: Principles, Taxonomy, Challenges, and Open Questions.”
ArXiv (Cornell University), 9 Nov. 2023, [Link]
arxiv.2311.05232. [49] Mitchell, Margaret, et al. "Model Cards for Model Reporting." Proceedings
of the Conference on Fairness, Accountability, and Transparency - FAT* '19,
2019, pp. 220–229, [Link]
[39] See [4]
[42] See Centre for Emerging Technology and Security. (2023). Adversarial AI: [53] Burns, Mary, et al. “Imagining Failure to Attain Success: The Art and
Coming of age or overhyped? [online] Available at: [Link] Science of Pre-Mortems.” Brookings, 6 Feb. 2025, [Link]/
[Link]/publications/adversarial-ai-coming-age-or-overhyped. articles/the-art-and-science-of-pre-mortems/.
[43] HK Stock Exchange. "Exchange Publishes Consultation Paper on [54] Halme, Erika, et al. “How to Write Ethical User Stories? Impacts of the
Corporate Governance Code Enhancements." [Link], 2024, www. ECCOLA Method.” Lecture Notes in Business Information Processing, 2021,
[Link]/News/Regulatory-Announcements/2024/240614news?sc_ pp. 36–52, [Link] Accessed 12
lang=en. Aug. 2021.
[44] See [14]. [55] Mitchell, Margaret, et al. "Diversity and Inclusion Metrics in Subset
Selection." Proceedings of the AAAI/ACM Conference on AI, Ethics, and
Society, 4 Feb. 2020, [Link]
[45] See [27].
The Hong Kong Chartered Governance Institute 香港公司治理公會
(Incorporated in Hong Kong with limited liability by guarantee)
The Hong Kong Chartered Governance Institute (HKCGI) is the sole accrediting body in Hong Kong and the
Chinese mainland for the globally recognised Chartered Secretary and Chartered Governance Professional
qualifications. Formerly known as The Hong Kong Institute of Chartered Secretaries (HKICS), HKCGI is the
Hong Kong/China Division of The Chartered Governance Institute (CGI).
With a legacy of over 76 years, HKCGI has established itself as a trusted and reputable professional body in
the region. Its influence extends to CGI’s global network of around 40,000 members and students, making it
one of its fastest-growing divisions. HKCGI’s community comprises about 10,000 members, graduates, and
students, with significant representation in listed companies and diverse governance roles across various
industries.
Guided by the belief that governance leads to better decision-making and a better world, HKCGI is
committed to advancing governance in commerce, industry, and public affairs. It achieves this through
education, thought leadership, advocacy, and active engagement with its members and the broader
community. As a recognised thought leader, HKCGI promotes the highest standards of governance while
advocating for an inclusive approach that considers the interests of all stakeholders, and ensures that every
voice is heard and valued.
關於香港公司治理公會
( 於香港成立的有限擔保公司 )
香港公司治理公會(前稱「香港特許秘書公會」)(公會)是特許公司治理公會(國際總會)的中國香港
屬會,同時亦是中國內地和香港地區唯一頒授獲國際廣泛認可的「特許秘書」和「公司治理師」專業資格
的機構。
公會成立迄今已有逾 76 年的歷史,其專業地位於中國內地及香港地區備受信賴及尊崇。公會的影響力擴
展至國際總會的所有屬會,涵蓋全球約 40,000 名會員和學員,亦成為增長最快的屬會之一。公會現擁有
約 10,000 名會員、畢業學員及學員,他們在上市公司和各行各業中擔任重要的治理角色。
作為治理領域的思想領導者,公會始終秉承「卓越治理帶來更佳決策,從而創造更美好世界」的理念,致
力於通過教育、思維領導、倡導工作,以及與會員和廣泛社會層面的互動交流,提升工商業以及公共事務
的治理水平,並促進最高治理標準。同時,公會提倡考慮所有持份者的利益,確保各種寶貴意見及建議都
被聽取和重視。
卓越治理 更佳未來
如欲了解更多資訊,請瀏覽:[Link]。
CONTACT US
The Hong Kong Chartered Governance Institute 香港公司治理公會
(Incorporated in Hong Kong with limited liability by guarantee)
Disclaimer and copyright. Notwithstanding the contents, this paper is not intended to constitute legal advice or to derogate from the responsibility of any person to comply with
the relevant rules and regulations. Readers should be aware that this paper is for reference only and should form their own opinions on each case. In case of doubt, they should
consult their own legal or professional advisers as they deem appropriate. The views expressed herein do not necessarily represent those of the Institute. It is also not intended to
be exhaustive but to guide in understanding the topic. The Institute shall not be responsible to any person or organisation because of reliance upon any information or viewpoint
set forth under this paper, including any losses or adverse consequences. The Institute owns the copyright of this paper. This paper is intended for public dissemination, and any
reference to it or reproduction in whole or part thereof should be suitably acknowledged.