Governance of Emerging Technologies and AI
In the context of ISACA's CGEIT certification, Governance of Emerging Technologies and AI applies the core principles of Governance of Enterprise IT (GEIT) to innovations such as artificial intelligence, machine learning, blockchain, IoT, and cloud-native platforms. These are adopted so that they c… In the context of ISACA's CGEIT certification, Governance of Emerging Technologies and AI applies the core principles of Governance of Enterprise IT (GEIT) to innovations such as artificial intelligence, machine learning, blockchain, IoT, and cloud-native platforms. These are adopted so that they create stakeholder value while risks and resources stay under control. The focus remains on the governing body's responsibility to Evaluate, Direct, and Monitor (EDM), as described in COBIT 2019 and ISO/IEC 38500, rather than on technical implementation. The topic maps onto the four CGEIT domains. Governance Framework: Boards should extend existing policies, roles, and decision rights to cover emerging technologies. Typical measures include establishing AI ethics committees and defining accountability for algorithmic decisions. AI principles such as fairness, transparency, and human oversight should be embedded into the enterprise governance structure. Strategic Management: Emerging technology investments must align with enterprise strategy. Leaders should assess whether AI initiatives support business objectives and avoid adopting technology simply for hype. Innovation portfolios should balance experimentation with strategic fit. Benefits Realization: Business cases, value metrics, and portfolio management help ensure that AI and other emerging technologies deliver measurable outcomes. Pilots should progress through stage gates with clear success criteria. Risk Optimization: AI introduces new risks, including algorithmic bias, lack of explainability, data privacy breaches, model drift, intellectual property concerns, cybersecurity threats, and regulatory exposure, for example under the EU AI Act or GDPR. Governance requires defining a risk appetite, conducting impact assessments, maintaining model inventories, and ensuring continuous monitoring and auditability. Resource Optimization: Organizations need suitable skills, high-quality data, infrastructure, and trusted third-party vendors. Strong data governance is foundational because AI outcomes depend on data integrity. Effective governance treats emerging technology as an enterprise-wide responsibility, not just an IT issue. It promotes responsible innovation through clear policies, stakeholder engagement, performance measurement, and assurance mechanisms. Applied well, this approach lets organizations capture competitive advantage from AI while maintaining trust, compliance, ethical integrity, and alignment with stakeholder expectations.
Governance of Emerging Technologies and AI (CGEIT – Governance of Enterprise IT)
Introduction
Emerging technologies such as Artificial Intelligence (AI), machine learning, generative AI, robotic process automation (RPA), blockchain, Internet of Things (IoT), quantum computing and advanced cloud services are changing how enterprises create value. They bring large opportunities, but also new and often poorly understood risks.
For the ISACA CGEIT exam, Governance of Emerging Technologies and AI sits within Domain 1 (Governance of Enterprise IT). It also connects closely to Benefits Realization, Risk Optimization and Resource Optimization. The exam expects you to think like a board-level or senior governance advisor, not a technician. Your job is to make sure innovation is aligned with strategy, delivers value, stays within risk appetite and is properly overseen.
Why It Is Important
1. Strategic value and competitive advantage: Emerging technologies can transform business models, products and operations. Without governance, enterprises either miss opportunities or invest in hype-driven projects that never deliver value.
2. New and amplified risks: AI introduces several risks that traditional IT governance may not address, including:
- algorithmic bias and discrimination
- lack of transparency and explainability
- hallucinations and inaccurate outputs
- privacy breaches through training data
- intellectual property infringement
- model drift
- adversarial attacks
- shadow AI, where staff use public generative AI tools without approval
3. Regulatory pressure: Regulations and frameworks are evolving rapidly. Key examples include:
- the EU AI Act, with its risk-based classification of AI systems
- GDPR provisions on automated decision-making
- the NIST AI Risk Management Framework
- ISO/IEC 42001 (AI management systems)
- ISO/IEC 23894 (AI risk management)
- the OECD AI Principles
- sector-specific rules
Boards are accountable for compliance.
4. Ethics, trust and reputation: Stakeholders expect AI to be fair, accountable and transparent. A single harmful AI incident can damage brand trust significantly.
5. Accountability cannot be delegated to technology: The board and executive management remain accountable for outcomes produced by AI systems. Governance ensures clear ownership.
What It Is
Governance of emerging technologies and AI is the system of direction, oversight, accountability, policies, structures and processes. It ensures that the evaluation, adoption, use and retirement of new technologies:
- supports enterprise objectives
- optimizes risk
- uses resources responsibly
- meets legal and ethical obligations
- delivers measurable benefits
It applies the core governance principles of COBIT to new technology domains:
- Evaluate, Direct and Monitor (EDM): The board evaluates opportunities and risks, directs through strategy and policy, and monitors performance and compliance.
- Separation of governance from management: Governance sets direction and risk appetite. Management plans, builds, runs and monitors within that direction.
- Stakeholder value creation: Balancing benefits realization, risk optimization and resource optimization.
Key components include:
- An AI/emerging technology strategy aligned with business strategy
- Principles and policies, such as Responsible AI principles, acceptable use policies for generative AI, and data usage policies
- Organizational structures, such as an AI governance committee or ethics board, an innovation steering committee, and defined roles (AI owner, model owner, data steward, model risk management)
- Risk management integrated into enterprise risk management (ERM), with defined risk appetite and tolerance for AI
- Inventory and classification of AI systems and use cases by risk level
- Lifecycle controls covering use case approval, data sourcing, model development, validation, deployment, monitoring and decommissioning
- Third-party and vendor governance for AI embedded in purchased products and cloud services
- Performance and benefits measurement through KPIs, KRIs and value metrics
- Culture, skills and awareness, including AI literacy for the board and staff
How It Works
Step 1 – Establish direction and risk appetite: The board, supported by executive management, defines the enterprise position on emerging technology. This covers:
- where innovation is encouraged
- which uses are prohibited
- the level of risk the enterprise is willing to accept
Responsible AI principles are approved at this level. Typical principles are fairness, transparency, accountability, privacy, safety, security and human oversight.
Step 2 – Define accountability and structures: Assign clear ownership. The business owner of an AI use case is accountable for its outcomes, not IT alone. A cross-functional AI governance committee is often created. Members typically include business, IT, risk, legal, compliance, privacy, security, HR and ethics. Its role is to review high-risk use cases.
Step 3 – Evaluate opportunities through portfolio management: Emerging technology initiatives enter the investment portfolio. Each has a business case covering:
- expected benefits
- costs
- risks
- alignment with strategy
Proofs of concept and pilots, sometimes run in regulatory or innovation sandboxes, allow controlled experimentation before scaling. Stage-gate reviews stop or continue investments based on evidence.
Step 4 – Assess and treat risk: Each use case is classified by impact. For example, a customer-facing credit decision model is high risk, while an internal document summarizer is lower risk. Controls are proportional to risk. They may include:
- impact assessments (AI impact assessments, DPIAs)
- bias testing
- explainability requirements
- human-in-the-loop review
- security testing
- data quality checks
- contractual clauses with vendors
Step 5 – Implement policies and lifecycle controls: Management operationalizes governance through standards, procedures and tools, such as:
- an approved tools list
- data classification rules for prompts
- model documentation (model cards)
- version control
- change management
- incident response for AI failures
Step 6 – Monitor, measure and report: Ongoing monitoring covers model performance, drift, bias, incidents, compliance and benefits realized. Dashboards report KPIs and KRIs to the board. Independent assurance from internal audit or external reviewers provides objective confirmation.
Step 7 – Adapt and improve: Emerging technologies change quickly. Governance must be agile and periodically reviewed, updating policies as regulations, technology capabilities and the threat landscape evolve.
Relevant Frameworks to Know
- COBIT 2019: governance system, design factors including emerging technology adoption strategy (first mover, follower, slow adopter), EDM objectives, and APO04 Managed Innovation
- NIST AI RMF: Govern, Map, Measure, Manage functions
- ISO/IEC 42001: AI management system standard
- ISO/IEC 38500: corporate governance of IT principles
- EU AI Act: unacceptable, high, limited and minimal risk categories
- OECD AI Principles
Common Exam Scenarios
- Business units are adopting generative AI tools without approval (shadow AI). What should governance do first?
- The board wants to invest in AI quickly to keep pace with competitors. What is the most important first step?
- An AI model shows bias after deployment. Who is accountable, and what is the best response?
- A vendor offers an AI-enabled solution. What is the primary governance concern?
- How should the enterprise measure value from an emerging technology pilot?
- What is the best way to ensure AI initiatives remain aligned with strategy?
Exam Tips: Answering Questions on Governance of Emerging Technologies and AI
1. Think governance, not technology. CGEIT rewards answers about strategy, accountability, policy, risk appetite and oversight. Avoid answers that jump straight to technical fixes, such as retraining a model or buying a tool, unless the question is clearly at management level.
2. Alignment with business strategy comes first. When asked about adopting a new technology, the best answer usually ties the initiative to enterprise objectives and a business case. Answers driven by technology hype or competitor imitation are usually wrong.
3. Establish a framework and policy before scaling. For shadow AI or uncontrolled adoption, the preferred answer is usually to develop and communicate a policy or governance framework, such as an acceptable use policy or AI governance structure. Blocking everything stifles innovation and is rarely the best choice.
4. Accountability rests with the business and the board. The business owner is accountable for AI outcomes, and the board is ultimately accountable for governance. IT is typically responsible for implementation, not accountable for business outcomes.
5. Risk appetite drives decisions. Look for answers that reference defining or applying risk appetite and tolerance. Risk treatment should be proportional to the risk level of the use case.
6. Integrate, do not isolate. Prefer answers that integrate AI risk into existing ERM, portfolio management and compliance processes. Creating disconnected silos is usually a weaker choice.
7. Use pilots and stage gates for uncertainty. Where benefits are uncertain, controlled pilots or proofs of concept with defined success criteria and go/no-go decisions are usually best.
8. Stakeholder value is the goal. Balance benefits, risk and resources. Answers that maximize only one dimension, such as the fastest deployment or zero risk, are usually distractors.
9. Watch keywords. Words such as FIRST, BEST, MOST important and PRIMARY matter.
- FIRST often points to understanding the current state, strategy alignment or establishing governance structures.
- PRIMARY concern often relates to value, accountability or alignment to risk appetite.
10. Third-party AI still needs governance. Outsourcing a technology does not outsource accountability. Look for answers covering due diligence, contractual rights (audit, transparency, data use) and ongoing monitoring.
11. Ethics and transparency matter. When choices involve customer impact, prefer answers ensuring human oversight, explainability, fairness and regulatory compliance.
12. Monitoring is continuous. AI models degrade and environments change. Answers involving ongoing monitoring and periodic review beat one-time assessments.
13. Eliminate operational distractors. If two answers seem correct, choose the one at the higher governance level, the one addressing root cause, or the one enabling a sustainable enterprise-wide approach.
Quick Example
Question: Several departments are using public generative AI tools to process customer data. What should the IT governance function do FIRST?
Options might include:
- block all AI sites
- train users
- develop an enterprise AI acceptable use policy aligned with risk appetite and data protection requirements
- conduct a technical audit
The best answer is usually to establish the policy and governance direction. Training, controls and monitoring then follow from that policy.
Summary
Governance of emerging technologies and AI applies proven governance principles to fast-moving, high-impact innovations:
- Evaluate, direct and monitor
- Define clear accountability, strategic alignment and risk appetite
- Apply proportional controls and continuous oversight
For the CGEIT exam, consistently choose answers that enable responsible innovation. That means delivering business value while keeping risk within acceptable limits, with accountability clearly owned by business leadership and the board.
Unlock Premium Access
Certified in the Governance of Enterprise IT
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2995 Superior-grade Certified in the Governance of Enterprise IT practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CGEIT: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!