Part III · The Control Layer

Governance as Infrastructure, Not Documentation

A PDF called “Our AI Policy” is not going to govern an environment containing autonomous agents, MCP connections, customer data and franchisee information.

Why documentation is no longer governance

As AI moves from answering questions to taking actions, traditional AI governance becomes insufficient. A PDF called “Our AI Policy” is not going to govern an environment containing autonomous agents, MCP connections, customer data, franchisee information, automated communications, financial systems and AI-generated advertising.

The company increasingly needs an AI governance infrastructure layer.

Agents should not merely know company policy. They should be required to obtain permission from a policy-enforcement layer before taking consequential actions.

Maintain an AI asset and risk register

The organization should have a current inventory of its AI models, applications, agents, MCP servers, data connections and automated workflows — each with an owner, approved uses, a risk classification and required controls.

Without such a registry, leadership may not even know which AI systems are touching company data.

Governance moves from an annual compliance exercise to continuous control.

Continuously detect drift

Approval should not be a one-time event. An agent reviewed six months ago may since have had its prompt changed, its model swapped, a new MCP server added, new data made accessible, or its permissions expanded.

The governance layer should automatically inspect important AI assets on a schedule and compare the current configuration with the approved one. A material change is drift — triggering notification, testing, human review or reapproval. Governance moves from an annual compliance exercise to continuous control.

Move governance into the agent workflow

The more important evolution is governing actions before they occur. An agent that wants to send an internal document to an external address should not interpret company policy itself; it should query the governance layer first — proposed action, data classification, requested permission — and receive back Approved, Denied, or Human authorization required. Only then does it proceed.

This is pre-execution governance, and it is fundamentally different from auditing AI after something has gone wrong.

Keep an audit journal

Every material AI action generates a record: which agent, what it intended, which policy applied, which data was involved, whether it was approved, and by whom.

Beyond making agentic systems auditable, this continuously accumulates the evidence that frameworks such as ISO 42001, ISO 27001 and SOC 2 require — rather than asking people to reconstruct it at audit time.

Apply it to distinctly franchise risks

For franchisors, this goes well beyond conventional IT governance. Before an agent sends a franchisee communication, the governance layer can check: does it create an unintended commitment? Is it inconsistent with the franchise agreement? Does it contain a prohibited financial performance representation?

Before an AI marketing agent publishes local advertising: required disclaimers, brand standards, permitted claims, territory restrictions.