How to Build an AI Governance Roadmap in 90 Days

RedHub AI Editorialupdated October 2, 20266 min read

A technician fits a padlock on one storage cage while the cages further down the row stand unlocked under red light.
Jump to a section8

Ninety days is enough to make the AI a business already runs visible and controlled, if an AI governance roadmap splits the quarter into three 30-day blocks. Days 1 to 30 find and rank every model, agent and tool. Days 31 to 60 put controls on the riskiest ones. Days 61 to 90 test those controls and pilot one or two agent workflows under them. You will not solve every future AI risk in a quarter. You need a baseline you can see and a process you can repeat.

TL;DR: Begin with what exists, not a committee. Month one: inventory and risk-tier every AI system, name an owner, and pause anything high-risk and uncontrolled. Month two: an approval path, per-agent identities, scoped permissions, logging, small test sets and one incident process. Month three: regression tests, a live kill-switch exercise and a measured pilot. You finish with six deliverables and a repeatable process. The AI Risk Register & Treatment-Tracking System ($99) grades whether each risk you record is actually governed. Start with the pillar: Enterprise AI Control Plane: When Agents Skip the Checkpoint.

Start with what already exists

A 90-day roadmap opens with one question: which AI models, agents, tools, data sources and workflows are already running?

Our example is a made-up home-services company with 150 people. Leadership believes it uses two AI tools. The first week of inventory finds eleven, including an AI writing feature switched on inside the CRM, a quoting assistant a sales rep built on a personal account, and an agent that reorders parts with a company card. The gap between two and eleven is the reason the roadmap starts here.

This roadmap assumes some AI already acts on its own. If your team mainly uses AI tools by hand, start with our 90-day AI governance setup for small business, which covers policy, training and proof. The two calendars can run side by side.

Days 1 to 30: inventory and triage

Create the inventory first. For each system, record the owner, provider, model, purpose, users, data access, tools, outside actions, customers affected and current controls. Our AI governance checklist explains why it comes first.

Then risk-tier each system. Put on top anything touching sensitive data, customer systems, outside communication, money, code repositories or production. Give every system an owner by name, not by team.

Last, pause what is clearly uncontrolled. In the home-services company, the parts-reorder agent can spend on a company card with no cap and no review. It stops until it has both, which can take a single conversation.

The tiers become your risk register: each risk, what you decided to do about it, who owns it, and the residual risk left after your controls.

Days 31 to 60: put controls on the top tier

Define a lightweight approval process for new AI systems, so the next quoting assistant gets reviewed before it goes live. Then give each high-priority workflow a unique agent identity (never a shared login), permissions scoped to the task, logging of what the agent saw and did, a tool allowlist (the short list of tools it may call) and an escalation path to a named person.

For the reorder agent, that could mean its own supplier login, a weekly cap of $2,000, and any order over $500 waiting for the purchasing lead. Those figures are illustrative; set yours from your real order history.

Build a small evaluation set for each critical use case: twenty or thirty real past tasks with the right answers written down. Define what triggers a review, a rollback or a shutdown. Adopt one shared incident process, so nobody invents a response under pressure.

Days 61 to 90: test, pilot and measure

Run regression tests, re-running the evaluation set to confirm nothing got worse. Then run a kill-switch exercise: stop an agent mid-task, and time how long it takes and who had to be involved. Review access and evidence trails. Then pilot one or two high-value agent workflows under the new controls.

Measure the pilot on task success, cost per accepted outcome, latency, human-review time, policy violations, tool errors and user feedback. Cost per accepted outcome puts the model bill and review time in one number.

Illustrative example: a quoting pilot runs for a month. Model and tool fees come to $180, and people spend 6 hours reviewing drafts at $40 an hour, which is $240. Of the drafts, 120 quotes are accepted as written or with light edits. Total cost is $180 + $240 = $420, so each accepted quote costs $420 / 120 = $3.50. These numbers are made up to show the arithmetic.

Review time is more than half that bill. Our guide to AI cost per task walks through the full calculation.

What you hold on day 90

DeliverableOutcome
AI inventoryVisibility into models, agents, owners, data, tools and dependencies
Risk-tiering frameworkA clear control level for each workflow
Governance standardShared requirements for approval, identity, access, logging, testing and response
Evaluation suiteEvidence that model and prompt changes improve critical workflows
Incident playbookA defined process to stop, contain, investigate, communicate and recover
Pilot resultsMeasured business and risk outcomes for controlled autonomy

That is a minimum operating system, not a finished program. Our post on the AI governance operating system covers what keeps it running after day 90.

Where 90 days runs short

The kill-switch exercise is the step most likely to break the calendar. If stopping the reorder agent takes 40 minutes because only one engineer knows how, fixing that can eat the pilot's time. Let it. A pilot under a stop control nobody can use is autonomy without a brake.

The pilot has its own limit: a month at low volume may not give enough runs to trust a success rate. Twenty runs with two failures is a 90% success rate. Three failures in the same twenty runs is 85%. Treat month-three numbers as a first reading, and say so when you report them. If the inventory turns up thirty systems instead of eleven, the calendar stretches. Decide on day 30, once you have the count, whether to plan a second quarter.

Check whether your risk register would hold up

The AI Risk Register & Treatment-Tracking System marks six governance fields for each risk, among them a named owner and a current review, and returns GOVERNED, GAP or UNGOVERNED per entry and DEFENSIBLE AS DESCRIBED, GAPS TO CLOSE or EVIDENCE GAPS PRESENT AS DESCRIBED for the register. A risk accepted at high residual severity with no named owner or an overdue review reads UNGOVERNED however well it scores: the shipped sample's R-03 scores 78 and still does. It grades whether each entry is governed, not whether a risk is acceptable. Not legal advice.

Get the AI Risk Register — $99

Pairs well with

The Stop-Authority Assay ($109) grades what each stop control has been shown to do rather than what it claims, returning STOPS, SLOWS or NAMED ONLY. The Prompt Regression Lab ($89) snapshots a baseline, diffs every prompt change and fails your build pipeline on any regression: ship, hold or regressed. The AI Agent Quiet-Failure & Drift Monitor Kit ($49) computes the expected end-to-end success rate of multi-step agents: an 8-step agent at 85% per step succeeds all the way through 27.2% of the time (0.85 to the eighth power, treating the steps as independent).

More in this guide

What should an AI governance roadmap include?

An inventory of every AI system, a risk tier and named owner for each, controls for the riskiest systems, small evaluation sets, an incident process and a measured pilot. In 90 days that yields six deliverables: inventory, risk tiers, a governance standard, an evaluation suite, an incident playbook and pilot results.

Can a company build AI governance in 90 days?

It can build a working first version: its AI made visible, the riskiest systems under control, and a process it can repeat. A complete program takes longer.

What is the first step in an AI governance roadmap?

An inventory: each AI system's owner, provider, model, purpose, users, data access, tools, outside actions and current controls. You cannot control systems you have not found, and in this post's example the inventory found eleven tools where leadership expected two.

What is a kill-switch exercise?

It is a planned test where you stop a running AI agent mid-task and time how long that takes and who had to be involved. It shows whether your stop control works in practice.

What should a 90-day AI pilot measure?

Task success, cost per accepted outcome, latency, human-review time, policy violations, tool errors and user feedback. Count review time in the cost.

How is this different from a 90-day AI policy rollout?

A policy rollout covers rules, training and records for people who use AI tools. This roadmap adds controls for AI that acts on its own: agent identities, scoped permissions, tool allowlists, regression tests and a tested way to stop an agent. The two can run in parallel.

How it decides
Diagram of the AI Risk Register: six weighted governance fields, an accepted-high-residual gate, and entry R-03 scoring 78 that still reads UNGOVERNED.

The gate this post refers to, drawn from the tool’s own logic. See the tool.