In July this year the newly appointed AI Governance Officer at Aarti Capital Markets sat in my office with an open laptop and a frustrated expression. He had read the SEBI Advisory of 5 May 2026, the MeitY Guidelines, the DPDP Act Section 10 and the FREE-AI Report. He understood each. He had no idea how to start on Monday. "What do I actually do in Week 1?" he asked.
A ten-week AI governance build is not a mystery. It has four phases, each with one verb and one deliverable set, bracketed by four Board or Audit Committee checkpoints. The shape has worked for me on a BFSI broker, a healthtech, a fintech and a GCC. It will work for you. If you cannot answer the question "which phase are we in and what verb is this week," you are drifting.
Phase 1 Weeks 1-2 Appoint
The verb is Appoint. The deliverables are the AI Governance Officer appointment Board resolution [L5-C1], the stakeholder RACI naming Accountable, Responsible, Consulted and Informed roles for each strand, the AI inventory and model register populated with every AI system currently in use or planned for the next quarter, and the Function Allocation Worksheet from Lesson 3.
You will not have a policy yet. You will not have a DPIA yet. You will not have testing or monitoring yet. That is correct. If you try to draft an AI governance policy on Day 3 before you know what AI systems you are governing, the policy will be redrafted four times by Week 5.
Phase 1 ends with Checkpoint 1, a short Board or Audit Committee meeting at the end of Week 2 that formally receives the appointment, the RACI, the inventory and the Function Allocation. Minutes are signed. The AI Governance Officer now has the authority to proceed.
Phase 2 Weeks 3-5 Draft
The verb is Draft. The deliverables are the twelve-clause internal AI governance policy, the AI DPIA template aligned to DPDP Section 10(2)(c) proviso and Rule 13 [L5-C2], the pre-deployment risk assessment checklist (bias, robustness, security), the model card template, the datasheet-for-dataset template, the user-facing AI transparency notice template under Sutra 6 [L5-C3], the human-in-the-loop oversight SOP, and the AI incident response runbook.
Phase 2 is also the right time to pause new high-risk AI go-lives for three weeks while the policy is drafted. The business will object. The right response is that the pause is for three weeks only, that it applies to high-risk use cases, and that go-live will resume at Checkpoint 2 under the new policy.
Phase 2 ends with Checkpoint 2, a formal policy-approval Board meeting at the end of Week 5. The policy is approved by resolution. The DPIA template is approved by the Audit Committee. The AI incident response runbook is signed off by the AI Governance Officer and the CISO. The go-live pause lifts the next morning.
Phase 3 Weeks 6-8 Operate
The verb is Operate. The deliverables are a trained team (AI product owners, data engineers, legal, compliance), a running DPIA pipeline with three practice DPIAs on real systems in the inventory, pre-deployment testing executed on at least two production models, post-deployment monitoring stood up with drift detection on at least two production models, and the first AI incident report trial-run through the response runbook.
Phase 3 is where most programmes break. The DPIAs take longer than planned. The pre-deployment testing surfaces findings nobody wants to address. The drift detection produces false positives for the first two weeks. Treat each as expected. Build a weekly operations review in Week 6. Hold a mid-phase retrospective in the middle of Week 7. Expect to adjust the DPIA template and the testing scope at least once before Week 8.
Phase 3 ends with Checkpoint 3, an internal operations review at the end of Week 8 that measures DPIA completion rate, pre-deployment-testing coverage of production models, drift-detection coverage and training completion. The AI Governance Officer signs the review.
Phase 4 Weeks 9-10 Review
The verb is Review. The deliverables are a mock MeitY/sectoral-regulator review run by an external advisor or by internal audit, a Board briefing deck summarising programme health in six slides, a twelve-month operating calendar covering monthly, quarterly, half-yearly and annual tasks, and the written handover package the AI Governance Officer owes a successor.
The mock review is non-negotiable. It costs a day of your advisor\'s time and reveals policy gaps the drafter did not know existed. By the time the first SEBI, RBI or DPB inspection arrives, you will have closed them.
Phase 4 ends with Checkpoint 4, a full Board sign-off at the end of Week 10. The Board receives the six-slide health deck, the operating calendar and the risk register. The Audit Committee adopts the twelve-month calendar. The engagement is now programme, not project.
Three programme killers to disarm in Week 2
Unclear AI Governance Officer authority. If the appointment resolution is silent on the authority to pull a model out of production, Phase 2 drafting becomes a negotiation. Fix this in the resolution.
No AI inventory. If you cannot list every AI system in use in the organisation on one page by end of Week 2, the DPIA pipeline in Phase 3 has nothing to run on. Fix this at Checkpoint 1.
No go-live posture agreed. If the business and the AI governance function enter Phase 2 with different assumptions about whether high-risk new deployments continue, every policy decision becomes a fight. Fix this in Week 2 with a written three-week go-live posture.
Five failure modes on sequencing
Trying to run all four phases in parallel. The phases are sequential for a reason. Appointment unlocks authority. Authority unlocks drafting. Drafting unlocks operation. Operation unlocks review. Skip a step and the next step has no foundation.
Over-scoping the first programme. Keep the first ten weeks tight. Add deeper topics (GenAI red-teaming, formal fairness methods, international compliance alignment) in the next quarter.
Under-training product owners. The policy that lives only in the AI Governance Officer\'s laptop is theoretical. Phase 3 training is where it becomes working.
Letting drift detection produce noise. Scenario-tune twice. Agree a daily or weekly review window. Document the closed alerts for the due-diligence defence.
No calendar after Week 10. The programme must run forever. Checkpoint 4 is the start, not the end.
Your artifact from Lesson 5
Draw the ten-week engagement map for your organisation on one page. Four phases, four verbs, four checkpoints, with the deliverables and owners for each. Save it as Artifact 5 in your capstone workbook. We will revisit this map at the end of each module as a cross-check against drift.
The 2-click version
You have three honest routes to deliver the ten-week programme on your organisation. Route one is to run the course templates manually with your in-house team using the artifacts you build across Modules 1-12. The templates are complete and the engagement is doable with a two-person team. Route two is to run the programme inside the dcomply Compliance Suite, which pre-wires the capstone artifacts (policy, DPIA, model card, incident runbook, calendar) as live tools rather than Word documents. Route three is to engage Decipher done-for-you, where our team runs the Appoint-Draft-Operate-Review cycle on your organisation with you reviewing at each checkpoint. The certificate is the same on all three routes.