Governance Artifacts
Governance artifacts are the typed records you maintain so a sensitive activity can be defined, operated and checked. This section covers three kinds:
- Definitions — what good looks like: principles, guidance, threats, controls, risks and policy
- Sensitive Activity — the sensitive activity being governed
- Measures — evaluation, enforcement and audit records produced as the activity runs
Examples on these pages are drawn from a worked FOSS contribution programme Gemara example available on GitHub and from published catalogs such as the FINOS AI Governance Framework principles on the grc.store website.