This is a ready-to-use periodic report for the AI governance program as a whole, not for one model. A per-model monitoring record proves one system still performs; this report answers the question a board and senior management actually need answered on a cadence: across every AI system the company runs, is the portfolio under control. Replace every <<FILL: ...>> placeholder with your own specifics, set your document numbers and dates, and route it through your normal document control. A worked filled specimen follows the template. This content is educational reference, not legal or regulatory advice.
Document control header
| Field | Entry |
|---|---|
| Document title | AI Governance Program Periodic Review |
| Document number | <<FILL: RPT-ID, e.g. RPT-AIGB-2026-Q3>> |
| Review period | <<FILL: from>> to <<FILL: to>> |
| Author | <<FILL: role, e.g. AI Governance Board chair or secretary>> |
| Register version reviewed | <<FILL: register version / date pulled>> |
1. Purpose and period summary
State plainly, in two to four sentences, what changed in the AI portfolio this period: new systems registered, systems that changed tier, retrains and changes executed, monitoring triggers that fired, and any decommissioning completed. <<FILL>>
2. Portfolio snapshot
| Metric | This period | Prior period | Trend |
|---|---|---|---|
| Total AI systems on the register | <<FILL>> | <<FILL>> | <<FILL>> |
| Systems by tier: low / medium / high | <<FILL: counts>> | <<FILL>> | <<FILL>> |
| Systems by lifecycle state: proposed / development / validated / live / monitored / retiring / retired | <<FILL: counts>> | <<FILL>> | <<FILL>> |
| Vendor-hosted or API-delivered systems | <<FILL>> | <<FILL>> | <<FILL>> |
| Systems with no named business owner | <<FILL: should be zero>> | <<FILL>> | <<FILL>> |
| Systems overdue for their defined monitoring or periodic-review cadence | <<FILL: should be zero>> | <<FILL>> | <<FILL>> |
3. Register reconciliation
| Question | Answer |
|---|---|
| Reconciliation performed against project intake and change-control records for the period | Yes / No |
| New AI capability found operating with no prior register entry (shadow AI) | <<FILL: count and each reference>> |
| Each shadow-AI finding: routed to a register entry and risk-tiered | <<FILL: Yes/No per finding, with date>> |
| Vendor platform version upgrades reviewed for newly enabled AI features this period | <<FILL: Yes/No, and findings>> |
4. Changes, retrains, and predetermined change control plan activity
| System | Change type | Executed per approved plan (Y/N) | Confirmatory result | Reference |
|---|---|---|---|---|
<<FILL>> | <<FILL: routine retrain / threshold change / new feature / architecture change / vendor base-model change>> | <<FILL>> | <<FILL: met spec Y/N>> | <<FILL>> |
<<FILL: add a row per change executed this period>> |
| Field | Entry |
|---|---|
| Changes executed outside an approved predetermined plan this period | <<FILL: count, should be zero or each escalated to the board>> |
| Vendor-driven model changes discovered rather than announced | <<FILL: count and each disposition>> |
5. Monitoring trigger breaches across the portfolio
| System | Trigger | Fired (Y/N) | Response taken | Disposition | Reference |
|---|---|---|---|---|---|
<<FILL>> | <<FILL: performance below spec / override-rate anomaly / input-distribution drift>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL: add a row per breach this period>> |
6. Human oversight and acceptance-rate signal
| Field | Entry |
|---|---|
| Systems with an override or acceptance rate outside its expected range this period | <<FILL: count and each reference>> |
| Automation-bias investigations opened | <<FILL>> |
| Outcome of each investigation | <<FILL>> |
7. Board decisions and exceptions this period
| Date | Decision | System(s) | Rationale | Reference |
|---|---|---|---|---|
<<FILL>> | <<FILL: tier adjudication / exception granted / policy change / escalation>> | <<FILL>> | <<FILL>> | <<FILL: board minutes reference>> |
<<FILL: add a row per decision>> |
8. Decommissioning activity this period
| System | Decommission date | Rationale | Records/model versions retained (Y/N) | Access and endpoints removed (Y/N) | Vendor-hosted data return/deletion confirmed (Y/N, if applicable) |
|---|---|---|---|---|---|
<<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL: add a row per system retired this period, or state "none this period">> |
9. Open items and actions carried forward
| Item | Owner | Due date | Status |
|---|---|---|---|
<<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
10. Overall conclusion and escalation to management review
- The AI portfolio is under control for the period: the register is current, changes and retrains followed approved plans, monitoring triggers were responded to, and no open item requires management-review escalation beyond routine reporting.
- The portfolio shows a pattern requiring management-review attention (state the pattern and the recommended action below).
- A material gap was found this period requiring immediate escalation outside the normal review cycle (state what, and confirm it was already escalated).
| Field | Entry |
|---|---|
| Conclusion narrative | <<FILL>> |
| Items escalated to management review this cycle | <<FILL: reference to the management review record>> |
| Author (name, signature, date) | <<FILL>> |
| AI Governance Board endorsement (name, signature, date) | <<FILL>> |
Acceptance criteria
- Every section is completed for the period from the register and the underlying per-system records, not reconstructed from memory at report time.
- Section 3’s reconciliation is evidenced, not assumed: it names the intake and change-control sources checked, and any shadow AI found is traced to a register entry.
- Every monitoring trigger breach in section 5 has a recorded response and disposition; a breach with no response is not an acceptable line item.
- The conclusion in section 10 is a genuine judgment on the portfolio, not a restatement of section 2’s counts, and any material gap is shown as already escalated, not pending.
- The report is retained as a GxP record and referenced in the management review record it feeds.
References
ICH Q10, Pharmaceutical Quality System, for management review and the escalation of aggregate risk to senior management. ICH Q9(R1), Quality Risk Management, for the risk basis behind tier distribution and trigger thresholds. 21 CFR Part 11 and EU GMP Annex 11, for this report as a controlled electronic GxP record. FDA and EMA, “Guiding Principles of Good AI Practice in Drug Development” (published jointly 14 January 2026), for the life cycle management principle, scheduled monitoring and periodic re-evaluation, that this report exists to evidence at the portfolio level. GAMP 5, Second Edition (ISPE, 2022), for the computerized system lifecycle each register entry traces back to.
Confirm the current version and status of each reference before issue.
Revision history
| Version | Date | Author | Summary of change |
|---|---|---|---|
<<FILL: 1.0>> | <<FILL: date>> | <<FILL: author>> | Initial issue. |
Approvals
| Role | Name | Signature | Date |
|---|---|---|---|
| Author | <<FILL>> | ||
| AI Governance Board chair | <<FILL>> |
Filled specimen
The following shows a completed quarterly report for an illustrative mid-size biologics company with nine AI systems on its register, so you can see the level of detail expected. The company, systems, and numbers are illustrative; replace them with your own.
| Field | Entry |
|---|---|
| Document number | RPT-AIGB-2026-Q3 |
| Review period | 01 July 2026 to 30 September 2026 |
| Author | Associate Director, Digital Quality (AI Governance Board chair) |
| Register version reviewed | AI Register v14, pulled 01 October 2026 |
Period summary: Nine systems on the register (three advisory, four automated classification, two process-adjacent), unchanged in count from Q2. One quarterly retrain executed and passed confirmatory testing. One monitoring trigger fired on the deviation-triage model’s override rate and was investigated. No system was decommissioned this quarter. The vendor-platform sweep found one previously unregistered AI feature, now registered and tiered.
Portfolio snapshot: 9 systems (Q2: 9). Tier: 4 low, 4 medium, 1 high (unchanged). Lifecycle: 7 live/monitored, 1 in validation, 1 retiring. Vendor-hosted or API-delivered: 3 of 9. Systems with no named owner: 0. Systems overdue for monitoring cadence: 0.
Register reconciliation: Performed against Q3 project intake and change-control logs. One shadow-AI finding: a document-management platform’s “suggested classification” feature was enabled in a June version upgrade with no register entry. Registered 14 July 2026 (AI-014), tiered Advisory, assessed low risk, unscripted verification completed.
Changes and retrains: Deviation-triage model (AI-003) quarterly retrain executed per PCCP-AI-003, confirmatory test on the locked set returned recall 0.93 (spec 0.90), passed, VAL-2026-0341. No changes executed outside an approved plan this quarter. No undisclosed vendor model changes detected.
Monitoring trigger breaches: AI-003’s override rate rose from a baseline of 4 percent to 9 percent over three weeks in August. Investigated under DEV-2026-0512; root cause traced to a new complaint category the training data underrepresented. Response: full specialist review reinstated for that category pending the Q4 retrain, which will include the new category in the training set. Disposition: model remains in its validated state for all other categories; the affected category is under enhanced review.
Human oversight: One automation-bias investigation opened (the AI-003 finding above); no other systems flagged.
Board decisions: 12 August 2026, board confirmed AI-014’s Advisory tier and low-risk assessment (minutes ref AIGB-2026-08-12, item 2). 09 September 2026, board reviewed the AI-003 override-rate investigation and approved the enhanced-review interim measure pending Q4 retrain (minutes ref AIGB-2026-09-09, item 1).
Decommissioning: None this quarter.
Open items: AI-003 Q4 retrain to include the underrepresented complaint category, owner Data Science lead, due 15 December 2026, in progress.
Conclusion: The portfolio is under control for the period. One shadow-AI finding was closed within the quarter it was found, and one monitoring trigger was caught, investigated, and given an interim control before it produced a quality event. Both are reported to management review as evidence the monitoring and reconciliation controls are functioning, not as unresolved gaps. Author signed 03 October 2026; AI Governance Board chair endorsement 06 October 2026. Escalated to Q3 management review, item 4.
Reading it: the report does not show a perfect quarter, it shows a governed one. A shadow-AI feature slipped through a vendor upgrade and a model’s override rate drifted, and both were caught by the controls this report exists to evidence, closed within the period, and reported upward rather than buried in a per-system dashboard nobody rolled up.
Common inspection findings this report prevents
- Individual AI systems each have monitoring records, but no one can produce a single document showing the state of the whole AI portfolio.
- A shadow-AI finding gets fixed locally but never appears in any record that shows the reconciliation process actually caught it.
- AI risk is discussed informally at leadership level with no retained record connecting it to the register or to management review.
- A monitoring trigger fired and was handled at the system level, but the pattern was never surfaced to the body with the authority to see it alongside other systems’ patterns.
- The AI Governance Board meets and minutes decisions, but nothing periodically summarizes those decisions against the register they are supposed to govern.
How to adapt this report
- Set the cadence to match your board’s meeting schedule and your management-review cycle; quarterly is a reasonable default while a portfolio is still small, more frequent while it is growing quickly.
- Pull sections 2 through 8 from your actual register and per-system monitoring, change, and board records; do not draft this report from memory.
- If your organization tracks EU AI Act provider/deployer classification separately, add a row to section 2 cross-referencing the AI system inventory and EU AI Act classification register rather than duplicating that register’s fields here.
- Keep section 10’s conclusion a genuine judgment call, written by a person who read the sections above, not a template sentence restating the counts.
- File each completed report with the AI Governance Board’s records and reference it explicitly in the management review record it feeds.