How to Build an AI Governance Roadmap in 90 Days
RedHub AI Editorialupdated October 2, 20266 min read

Jump to a section8
Ninety days is enough to make the AI a business already runs visible and controlled, if an AI governance roadmap splits the quarter into three 30-day blocks. Days 1 to 30 find and rank every model, agent and tool. Days 31 to 60 put controls on the riskiest ones. Days 61 to 90 test those controls and pilot one or two agent workflows under them. You will not solve every future AI risk in a quarter. You need a baseline you can see and a process you can repeat.
TL;DR: Begin with what exists, not a committee. Month one: inventory and risk-tier every AI system, name an owner, and pause anything high-risk and uncontrolled. Month two: an approval path, per-agent identities, scoped permissions, logging, small test sets and one incident process. Month three: regression tests, a live kill-switch exercise and a measured pilot. You finish with six deliverables and a repeatable process. The AI Risk Register & Treatment-Tracking System ($99) grades whether each risk you record is actually governed. Start with the pillar: Enterprise AI Control Plane: When Agents Skip the Checkpoint.
Start with what already exists
A 90-day roadmap opens with one question: which AI models, agents, tools, data sources and workflows are already running?
Our example is a made-up home-services company with 150 people. Leadership believes it uses two AI tools. The first week of inventory finds eleven, including an AI writing feature switched on inside the CRM, a quoting assistant a sales rep built on a personal account, and an agent that reorders parts with a company card. The gap between two and eleven is the reason the roadmap starts here.
This roadmap assumes some AI already acts on its own. If your team mainly uses AI tools by hand, start with our 90-day AI governance setup for small business, which covers policy, training and proof. The two calendars can run side by side.
Days 1 to 30: inventory and triage
Create the inventory first. For each system, record the owner, provider, model, purpose, users, data access, tools, outside actions, customers affected and current controls. Our AI governance checklist explains why it comes first.
Then risk-tier each system. Put on top anything touching sensitive data, customer systems, outside communication, money, code repositories or production. Give every system an owner by name, not by team.
Last, pause what is clearly uncontrolled. In the home-services company, the parts-reorder agent can spend on a company card with no cap and no review. It stops until it has both, which can take a single conversation.
The tiers become your risk register: each risk, what you decided to do about it, who owns it, and the residual risk left after your controls.
Days 31 to 60: put controls on the top tier
Define a lightweight approval process for new AI systems, so the next quoting assistant gets reviewed before it goes live. Then give each high-priority workflow a unique agent identity (never a shared login), permissions scoped to the task, logging of what the agent saw and did, a tool allowlist (the short list of tools it may call) and an escalation path to a named person.
For the reorder agent, that could mean its own supplier login, a weekly cap of $2,000, and any order over $500 waiting for the purchasing lead. Those figures are illustrative; set yours from your real order history.
Build a small evaluation set for each critical use case: twenty or thirty real past tasks with the right answers written down. Define what triggers a review, a rollback or a shutdown. Adopt one shared incident process, so nobody invents a response under pressure.
Days 61 to 90: test, pilot and measure
Run regression tests, re-running the evaluation set to confirm nothing got worse. Then run a kill-switch exercise: stop an agent mid-task, and time how long it takes and who had to be involved. Review access and evidence trails. Then pilot one or two high-value agent workflows under the new controls.
Measure the pilot on task success, cost per accepted outcome, latency, human-review time, policy violations, tool errors and user feedback. Cost per accepted outcome puts the model bill and review time in one number.
Review time is more than half that bill. Our guide to AI cost per task walks through the full calculation.
What you hold on day 90
| Deliverable | Outcome |
|---|---|
| AI inventory | Visibility into models, agents, owners, data, tools and dependencies |
| Risk-tiering framework | A clear control level for each workflow |
| Governance standard | Shared requirements for approval, identity, access, logging, testing and response |
| Evaluation suite | Evidence that model and prompt changes improve critical workflows |
| Incident playbook | A defined process to stop, contain, investigate, communicate and recover |
| Pilot results | Measured business and risk outcomes for controlled autonomy |
That is a minimum operating system, not a finished program. Our post on the AI governance operating system covers what keeps it running after day 90.
Where 90 days runs short
The kill-switch exercise is the step most likely to break the calendar. If stopping the reorder agent takes 40 minutes because only one engineer knows how, fixing that can eat the pilot's time. Let it. A pilot under a stop control nobody can use is autonomy without a brake.
The pilot has its own limit: a month at low volume may not give enough runs to trust a success rate. Twenty runs with two failures is a 90% success rate. Three failures in the same twenty runs is 85%. Treat month-three numbers as a first reading, and say so when you report them. If the inventory turns up thirty systems instead of eleven, the calendar stretches. Decide on day 30, once you have the count, whether to plan a second quarter.
Check whether your risk register would hold up
The AI Risk Register & Treatment-Tracking System marks six governance fields for each risk, among them a named owner and a current review, and returns GOVERNED, GAP or UNGOVERNED per entry and DEFENSIBLE AS DESCRIBED, GAPS TO CLOSE or EVIDENCE GAPS PRESENT AS DESCRIBED for the register. A risk accepted at high residual severity with no named owner or an overdue review reads UNGOVERNED however well it scores: the shipped sample's R-03 scores 78 and still does. It grades whether each entry is governed, not whether a risk is acceptable. Not legal advice.
Get the AI Risk Register — $99Pairs well with
The Stop-Authority Assay ($109) grades what each stop control has been shown to do rather than what it claims, returning STOPS, SLOWS or NAMED ONLY. The Prompt Regression Lab ($89) snapshots a baseline, diffs every prompt change and fails your build pipeline on any regression: ship, hold or regressed. The AI Agent Quiet-Failure & Drift Monitor Kit ($49) computes the expected end-to-end success rate of multi-step agents: an 8-step agent at 85% per step succeeds all the way through 27.2% of the time (0.85 to the eighth power, treating the steps as independent).
More in this guide
What should an AI governance roadmap include?
An inventory of every AI system, a risk tier and named owner for each, controls for the riskiest systems, small evaluation sets, an incident process and a measured pilot. In 90 days that yields six deliverables: inventory, risk tiers, a governance standard, an evaluation suite, an incident playbook and pilot results.
Can a company build AI governance in 90 days?
It can build a working first version: its AI made visible, the riskiest systems under control, and a process it can repeat. A complete program takes longer.
What is the first step in an AI governance roadmap?
An inventory: each AI system's owner, provider, model, purpose, users, data access, tools, outside actions and current controls. You cannot control systems you have not found, and in this post's example the inventory found eleven tools where leadership expected two.
What is a kill-switch exercise?
It is a planned test where you stop a running AI agent mid-task and time how long that takes and who had to be involved. It shows whether your stop control works in practice.
What should a 90-day AI pilot measure?
Task success, cost per accepted outcome, latency, human-review time, policy violations, tool errors and user feedback. Count review time in the cost.
How is this different from a 90-day AI policy rollout?
A policy rollout covers rules, training and records for people who use AI tools. This roadmap adds controls for AI that acts on its own: agent identities, scoped permissions, tool allowlists, regression tests and a tested way to stop an agent. The two can run in parallel.


The gate this post refers to, drawn from the tool’s own logic. See the tool.