NEW: Learn OnDemand in Arabic, French, Chinese & Spanish – Explore Courses or Book Free Consultation
Speak to an advisor
The regulatory era has arrived. Here is the five-layer structure that keeps your PMO on the right side of it.
A consulting team lost a major government contract because their AI system hallucinated compliance documentation, fabricated citations, and invented references. The completed deliverable looked entirely legitimate until the client’s legal team took a closer look at the generated documents.1
As a result of the errors, the firm was required to repay a portion of its fees, and the contract was completely lost. What struck me wasn’t just the error itself- it was how predictable it was.
Nobody on that team had updated their Quality Assurance process to account for AI-generated outputs. Nobody had a protocol for reviewing what the tool produced before it went to the client. There was no governance structure because the governance question had never been asked. The tool was useful, so they used it.
That’s how most PMOs are operating right now.
Here’s what I keep seeing: organisations scrambling to implement AI, only to realise their existing governance frameworks don’t cover these new risks. More than 75% of PMOs are now using or piloting AI tools, scheduling engines, risk analysers, and generative assistants to write stakeholder reports.2
Almost none have a formal accountability structure in place for when something goes wrong. After working with several PMO teams, I developed a five-layer governance approach you can start building this quarter. These actionable steps align with current regulations and real-world project delivery.
Currently, regulations are moving faster than corporate policies can keep up with. The NIST AI Risk Management Framework is becoming the de facto standard in US federal procurement.3 More than 40 states have introduced AI legislation since 2023.4 The SEC’s Investor Advisory Committee voted in December 2025 to recommend that public companies formally disclose the material impact of AI on their operations and enforcement actions for AI-related misstatements.5
That’s significant exposure for any PMO still running on a governance framework written before generative AI existed.
Outside the US, the pressure is even more acute. The EU AI Act classifies several project-level AI as tools that evaluate contractor performance, and systems that influence resource allocation as high-risk. The penalties for non-compliance with the EU AI Act are up to 7% of global revenue.6 On March 9, 2026, RICS issued the world’s first mandatory professional AI standard, now enforceable globally across the built environment.7
Other professional bodies are watching closely. But here’s the thing most IT policies miss: AI governance isn’t just about compliance checkboxes. It needs to be baked into how projects get delivered, where the tools are running, where the outputs reach clients, and where accountability must be real and named.
Compliance lives in legal, while governance lives in the PMO.
In Japanese martial arts, kata isn’t about following a rigid checklist; it’s about internalising a structure until it becomes instinct. I keep coming back to that idea when I work with PMO teams. This is the mindset that makes AI governance stick. Think of the PMO AI Governance Stack the way you’d think about a project charter: not bureaucracy, but the structure that makes everything else accountable. Five layers, each building on the last, each with a named owner and a single one-page output.
You don’t need a new department. You need a new discipline, and most of the components already exist inside your PMO.
Let’s build it.
Start by registering every AI tool active on your projects. This includes all licensed software, vendor-supplied platforms, or anything your team has adapted for project use. Record purpose, data inputs, and which live projects each tool touches. Apply a four-tier risk classification: Unacceptable, High, Limited, Minimal, drawn from the EU AI Act taxonomy, which maps cleanly onto NIST’s framework and works for US-based PMOs regardless of jurisdiction.
The principle is simple: you cannot govern what you haven’t named.
Output: An AI Tool Register. One page. Updated quarterly
Not all AI use carries the same consequence. A scheduling optimisation tool is a different beast from a generative system writing client deliverables, or a risk engine informing contractor evaluations. Tier each tool by four factors: data sensitivity, decision consequence (reversible or irreversible), available human oversight, and client or regulatory exposure.
This isn’t about limiting what you use; it’s about knowing how carefully you need to watch it.
Output: A Risk Tier Matrix for each active AI use case.
Confucius called it the rectification of names: until the right name is attached to the right responsibility, nothing can be reliably governed. AI doesn’t have accountability. People do. For every tool in active use, assign: who runs it (Responsible), who owns the output (Accountable), who needs to be consulted on risk (legal, compliance, data privacy), and who stays informed (client, sponsor, PMO director).
This is where “the AI produced this” stops being an acceptable answer in a client meeting, in a contract dispute, or in front of a regulator.
Output: An AI Accountability Matrix. One owner per tool, on a single page.
If an AI-generated output gets challenged in a contract dispute, a regulatory audit, or a client review, can you reconstruct what happened? That requires three things: prompt logs or audit trails where tools allow; version control and clear ‘AI-assisted’ labelling on all deliverables; and a decision record for any AI recommendation that directly informed a project decision. The EU AI Act mandates this for high-risk systems. [6] RICS requires it for professional practice globally. [7] US federal contractors are increasingly facing the same expectation, and enterprise clients are starting to ask for it as a contract condition
Output: An AI Decision Log and labelling protocol.
The Zen concept of Shoshin, beginner’s mind, is the discipline of approaching each recurrence without the complacency of assumed familiarity. Last quarter’s risk profile isn’t this quarter’s. New tools get added, regulations shift, project contexts change.
Embed a 30-minute AI governance review into your standard quarterly PMO cycle: refresh the Tool Register, re-tier any new deployments, check for regulatory changes in your jurisdictions, update the accountability matrix. The PMOs treating this as a consistent discipline are the ones presenting boards with evidence of control rather than scrambling after an incident.10
Output: A Quarterly AI Governance Review Checklist. Thirty minutes, four times a year.
Not in a strategy deck. Not in a steering committee. Start right where you’re standing.
Start this week with a single question: What AI tools are active on your projects right now?
Not what IT has licensed, but what’s actually running on live work. Build that list. Assign a provisional risk tier to each tool. That’s your AI Tool Register, Layer 1 of the stack, and it takes less time than most PMO leaders expect. Whether you’re operating under US federal requirements, the EU AI Act, or RICS standards, the structure is the same.
Build the foundation now, before a client, a regulator, or a legal team asks to see it.
Highly in-demand across roles, industries, and experience levels
Book Your Free Consultation
One-time offer, don’t miss out. Your next career milestone starts here.
Enter your email to receive your code instantly. By signing up, you agree to receive our emails. Unsubscribe anytime.
IPMXPUPDE59R
Don’t forget to copy and save this one-time code. It is valid until 31 October 2026.
We use cookies to ensure you get the best experience of our website. By clicking “Accept”, you consent to our use of cookies.