Skip to main content

Governance Artifacts

Governance artifacts are the typed records you maintain so a sensitive activity can be defined, operated and checked. This section covers three kinds:

  • Definitions — what good looks like: principles, guidance, threats, controls, risks and policy
  • Sensitive Activity — the sensitive activity being governed
  • Measures — evaluation, enforcement and audit records produced as the activity runs

Examples on these pages are drawn from a worked FOSS contribution programme Gemara example available on GitHub and from published catalogs such as the FINOS AI Governance Framework principles on the grc.store website.