Governance Exception Detection · Enterprise

Governance failure begins when exceptions become invisible.

An obligation that drifts out of compliance, an evidence document that has not been reviewed since approval, a risk acceptance that expired six months ago — these are not sudden failures. They are governance conditions that went undetected. EAB detects them continuously.

Governance Exception Detection monitors AI system governance records for obligation drift, evidence staleness, overdue reviews, process deviations, and structural governance gaps. When a condition is detected, it surfaces as a signal — attributed, timestamped, and actionable. Detection creates a signal, not a final legal conclusion.

Enterprise only Continuous monitoring Signal, not verdict
Detection · Signal categories
Obligation drift — status changed without governed action
Evidence staleness — documents not reviewed since approval
Overdue risk acceptances — review date passed
Re-screening overdue — legal change not acted on
Governance gap — required step missing or incomplete
Exception register entries overdue for review
Detection model
Continuous
Governance records are monitored continuously — not at scheduled intervals.
Signal attribution
Full
Every signal carries the affected system, obligation, owner, and detection timestamp.
False conclusions
None
Detection creates a signal for human review — EAB does not make legal compliance determinations.
Undetected drift
Zero tolerance
No governance condition that EAB can observe should silently degrade without a signal.
The governance problem

“A compliance programme that was sound at approval can degrade quietly over months. Obligations drift, evidence becomes stale, accepted risks expire unreviewed. Governance Exception Detection is the continuous monitoring layer that ensures these conditions surface as signals — before they become findings.”

EAB Design Principle · Continuous Governance
What is detected

Six signal categories — each requiring governed response.

Governance Exception Detection monitors governance records across six categories of structural conditions. Each signal is specific to a system, an obligation, and an owner. Signals are not alerts in the general sense — they are governance conditions that require a response in the platform.

Signal: Obligation drift

Obligation status changed without governed action

An obligation that was previously complete, in progress, or approved has changed state without a corresponding governance action — no evidence update, no supervisor review, no re-screening. The drift is surfaced with the affected system, obligation reference, and the last attributed action.

Signal: Evidence staleness

Evidence document not reviewed since approval

An evidence document attached to an approved obligation has not been reviewed or updated within the defined review horizon. The system marks the attached evidence as potentially stale and surfaces the obligation for review. The signal does not invalidate the evidence — it requests review.

Signal: Overdue risk acceptance

Risk acceptance review date passed without action

A risk acceptance record in the Exception Register has passed its review date without a state transition. The named risk owner is signalled. The accepted risk is flagged in the register and in reporting as requiring reassessment under the Risk Acceptance Workflow.

Signal: Re-screening overdue

Legal change not acted on within the review window

A legal change re-screening was triggered for an AI system and has not been initiated within the review window. The system is flagged as operating under a screening result that may not reflect current legal obligations. The signal links to the specific legal change that triggered it.

Signal: Governance gap

Required governance step missing or incomplete

A governance step that is required given the system’s risk classification and obligation set has not been completed. This includes missing evidence for a specific article obligation, an incomplete technical documentation section, or a required assessment that was never initiated.

Signal: Exception overdue

Exception register entry past its review date

An entry in the Exception Register has passed its review date without a status transition. The exception owner is signalled and the entry surfaces as an overdue item in the register, in compliance reporting, and in the Executive Governance Cockpit governance health view.

How detection works

From condition to governed response.

Detection is not the end of the process — it is the beginning of a governed response. Every signal requires an acknowledged action in the platform. Signals that are ignored surface as escalation indicators in reporting and the executive cockpit.

1
Monitoring

Governance records monitored continuously

EAB monitors governance records across all AI systems in the organization — obligation statuses, evidence review dates, risk acceptance expiry dates, re-screening queue states, and exception register entries. Monitoring is continuous and covers all systems for which the organization has an active governance record.

2
Detection

Condition detected and signal created

When a governance condition is detected, EAB creates a signal. The signal is specific: it identifies the affected AI system, the obligation or record, the detection category, the responsible owner, and the date the condition was first observed. The signal is not a general notification — it is a structured record in the governance layer.

3
Routing

Signal routed to responsible owner and supervisor

The signal is surfaced in the responsible owner’s action inbox, in the Supervisor governance view, and in the Executive Governance Cockpit health indicators. Signals are not sent exclusively by email — they are live platform records that remain visible until a governed response is recorded.

4
Response

Owner responds within the platform

The responsible owner responds to the signal with a governed action: initiating re-screening, updating evidence, triggering the risk acceptance workflow, transitioning an exception state, or documenting a formal non-applicability decision. The response is attributed and timestamped. Acknowledging a signal without a governed action is not sufficient.

5
Escalation

Unresolved signals escalate in reporting

Signals that remain unresolved beyond a defined window escalate in governance reporting. They surface as elevated indicators in the Executive Governance Cockpit, as open items in Compliance Reporting, and as audit-visible conditions in the Auditor Workspace. Unresolved signals are not hidden.

Detection creates a signal. The organization decides what it means.

Governance Exception Detection identifies conditions that EAB can observe in the governance record: dates passed, statuses changed without governed action, documents not reviewed. It does not determine whether these conditions constitute a legal compliance failure. That determination requires human judgement, legal context, and organizational assessment.

A signal from Governance Exception Detection means: this governance record has a condition that requires your attention. It does not mean: your organization is non-compliant with Article X. The platform surfaces the condition — the responsible owner, supervisor, or compliance lead determines the appropriate governed response.

This constraint is intentional. AI governance is a human responsibility. EAB provides the structure, the monitoring, and the record of how the organization responded to every governance condition it was aware of. The response decisions belong to the organization.

What detection does
  • MonitorsAll governance records continuously across AI systems
  • DetectsSix categories of governance conditions
  • CreatesAttributed, timestamped signal in the governance layer
  • RoutesTo owner inbox, supervisor view, executive cockpit
  • EscalatesUnresolved signals in reporting over time
  • RecordsAll signals and responses in the audit trail
What detection does not do
  • NotDetermine legal compliance or non-compliance
  • NotAutomatically close or escalate without human action
  • NotReplace supervisor review or governance approval
  • NotModify governance records on detection

Surface governance conditions before they become audit findings.

Governance Exception Detection is available in the Enterprise plan. Continuous monitoring, attributed signals, and governed response paths — across all AI systems in the organization.

EU-hosted · Anchored to CELEX 32024R1689

Get in Touch
Request More Information

Tell us about your organization and what you’re looking to address. We’ll follow up with the relevant information.