NEW: Learn OnDemand in Arabic, French, Chinese & Spanish – Explore Courses or Book Free Consultation

header-bar
hamburger__close

Building an AI Governance Framework for Your PMO 

The regulatory era has arrived. Here is the five-layer structure that keeps your PMO on the right side of it.

Building an AI Governance Framework for Your PMO 
Back

Introduction

A consulting team lost a major government contract because their AI system hallucinated compliance documentation, fabricated citations, and invented references. The completed deliverable looked entirely legitimate until the client’s legal team took a closer look at the generated documents.1 

As a result of the errors, the firm was required to repay a portion of its fees, and the contract was completely lost. What struck me wasn’t just the error itself- it was how predictable it was.  

Nobody on that team had updated their Quality Assurance process to account for AI-generated outputs. Nobody had a protocol for reviewing what the tool produced before it went to the client. There was no governance structure because the governance question had never been asked. The tool was useful, so they used it.  

That’s how most PMOs are operating right now.  

Here’s what I keep seeing: organisations scrambling to implement AI, only to realise their existing governance frameworks don’t cover these new risks. More than 75% of PMOs are now using or piloting AI tools, scheduling engines, risk analysers, and generative assistants to write stakeholder reports.2

Almost none have a formal accountability structure in place for when something goes wrong. After working with several PMO teams, I developed a five-layer governance approach you can start building this quarter. These actionable steps align with current regulations and real-world project delivery.

PMO Illustration

The Compliance Minefield

Currently, regulations are moving faster than corporate policies can keep up with. The NIST AI Risk Management Framework is becoming the de facto standard in US federal procurement.3 More than 40 states have introduced AI legislation since 2023.4 The SEC’s Investor Advisory Committee voted in December 2025 to recommend that public companies formally disclose the material impact of AI on their operations and enforcement actions for AI-related misstatements.5 

That’s significant exposure for any PMO still running on a governance framework written before generative AI existed.  

Outside the US, the pressure is even more acute. The EU AI Act classifies several project-level AI as tools that evaluate contractor performance, and systems that influence resource allocation as high-risk. The penalties for non-compliance with the EU AI Act are up to 7% of global revenue.6 On March 9, 2026, RICS issued the world’s first mandatory professional AI standard, now enforceable globally across the built environment.7

Other professional bodies are watching closely. But here’s the thing most IT policies miss: AI governance isn’t just about compliance checkboxes. It needs to be baked into how projects get delivered, where the tools are running, where the outputs reach clients, and where accountability must be real and named.  

Compliance lives in legal, while governance lives in the PMO. 

AI Governance Framework for PMO - Infographic

8,9

The PMO AI Governance Stack

In Japanese martial arts, kata isn’t about following a rigid checklist; it’s about internalising a structure until it becomes instinct. I keep coming back to that idea when I work with PMO teams. This is the mindset that makes AI governance stick. Think of the PMO AI Governance Stack the way you’d think about a project charter: not bureaucracy, but the structure that makes everything else accountable. Five layers, each building on the last, each with a named owner and a single one-page output.  

You don’t need a new department. You need a new discipline, and most of the components already exist inside your PMO. 

Let’s build it. 

The Five Layers

Layer 1: Inventory and Classification 

Start by registering every AI tool active on your projects. This includes all licensed software, vendor-supplied platforms, or anything your team has adapted for project use. Record purpose, data inputs, and which live projects each tool touches. Apply a four-tier risk classification: Unacceptable, High, Limited, Minimal, drawn from the EU AI Act taxonomy, which maps cleanly onto NIST’s framework and works for US-based PMOs regardless of jurisdiction.  

The principle is simple: you cannot govern what you haven’t named.  

Output: An AI Tool Register. One page. Updated quarterly 

Layer 2: Risk Tiering 

Not all AI use carries the same consequence. A scheduling optimisation tool is a different beast from a generative system writing client deliverables, or a risk engine informing contractor evaluations. Tier each tool by four factors: data sensitivity, decision consequence (reversible or irreversible), available human oversight, and client or regulatory exposure.  

This isn’t about limiting what you use; it’s about knowing how carefully you need to watch it.  

Output: A Risk Tier Matrix for each active AI use case. 

Layer 3: Accountability and RACI 

Confucius called it the rectification of names: until the right name is attached to the right responsibility, nothing can be reliably governed. AI doesn’t have accountability. People do. For every tool in active use, assign: who runs it (Responsible), who owns the output (Accountable), who needs to be consulted on risk (legal, compliance, data privacy), and who stays informed (client, sponsor, PMO director).  

This is where “the AI produced this” stops being an acceptable answer in a client meeting, in a contract dispute, or in front of a regulator.  

Output: An AI Accountability Matrix. One owner per tool, on a single page.  

Layer 4: Audit and Traceability 

If an AI-generated output gets challenged in a contract dispute, a regulatory audit, or a client review, can you reconstruct what happened? That requires three things: prompt logs or audit trails where tools allow; version control and clear ‘AI-assisted’ labelling on all deliverables; and a decision record for any AI recommendation that directly informed a project decision. The EU AI Act mandates this for high-risk systems. [6] RICS requires it for professional practice globally. [7] US federal contractors are increasingly facing the same expectation, and enterprise clients are starting to ask for it as a contract condition 

Output: An AI Decision Log and labelling protocol. 

Layer 5: Continuous Review 

The Zen concept of Shoshin, beginner’s mind, is the discipline of approaching each recurrence without the complacency of assumed familiarity. Last quarter’s risk profile isn’t this quarter’s. New tools get added, regulations shift, project contexts change.  

Embed a 30-minute AI governance review into your standard quarterly PMO cycle: refresh the Tool Register, re-tier any new deployments, check for regulatory changes in your jurisdictions, update the accountability matrix. The PMOs treating this as a consistent discipline are the ones presenting boards with evidence of control rather than scrambling after an incident.10

Output: A Quarterly AI Governance Review Checklist. Thirty minutes, four times a year. 

Start This Week 

Not in a strategy deck. Not in a steering committee. Start right where you’re standing.  

Start this week with a single question: What AI tools are active on your projects right now?  

Not what IT has licensed, but what’s actually running on live work. Build that list. Assign a provisional risk tier to each tool. That’s your AI Tool Register, Layer 1 of the stack, and it takes less time than most PMO leaders expect. Whether you’re operating under US federal requirements, the EU AI Act, or RICS standards, the structure is the same.  

Build the foundation now, before a client, a regulator, or a legal team asks to see it.  


References

  1. Risk & Insurance. (2026).“AI Governance Failures Expose Organizations to Professional Liability Risks.”   ↩︎
  2. Gold Standard Certifications. (2026) “Future of Project Management in 2026: AI, Remote Teams & PMP® Skills.”   ↩︎
  3. National Institute of Standards and Technology. (2023) “Artificial Intelligence Risk Management Framework (AI RMF 1.0).”  ↩︎
  4. National Conference of State Legislatures. (2025) “Artificial Intelligence 2024 Legislation.”   ↩︎
  5. Crowell & Moring LLP. (2025) “Investor Advisory Committee Recommends SEC Disclosure Guidelines for Artificial Intelligence.”   ↩︎
  6. European Parliament and Council. (2024) “Regulation (EU) 2024/1689 — Artificial Intelligence Act.” Official Journal of the European Union. See Article 99 for penalty structure; Annex III for high-risk classification.   ↩︎
  7. Royal Institution of Chartered Surveyors. (2026) “Responsible Use of Artificial Intelligence in Surveying Practice.”   ↩︎
  8. Infosys Knowledge Institute. (2025) “Responsible Enterprise AI in the Agentic Era.” Survey of 1,500 senior executives across North America, Western Europe, and ANZ.   ↩︎
  9. Deloitte Insights. (2025) “Tech Trends 2026: Agentic AI Strategy.” Based on Deloitte 2025 Emerging Technology Trends Survey of 500 US technology leaders.  ↩︎
  10. PMI. (2025) “Pulse of the Profession® 2025: Boosting Business Acumen.” Project Management Institute ↩︎

Additional References

  1. PMI. (2024) “Pulse of the Profession® 2024: The Future of Project Work.” Project Management Institute
  2. PMI. (2024) “AI Essentials for Project Professionals.” Project Management Institute

Further Reading EU

  1. AI Act High-Level Summary: artificialintelligenceact.eu/high-level-summary  
  2. NIST AI RMF Playbook: nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook 
  3. Deloitte Tech Trends 2026 (full report): deloitte.com/us/en/insights/topics/technology-management/tech-trends  
  4. PMI AI Essentials for Project Professionals: pmi.org/standards/ai-essentials-for-project-professionals