Getting started with Governance

Learn how the Governance module helps you assess and manage privacy, vendor and AI risk, and get set up in a few steps.

Governance is where you evaluate and manage risk across your organization. It brings privacy assessments, vendor risk management and AI governance into one place, built on top of your data map, so every assessment and risk is connected to the real systems, vendors and data behind it.

What you can do with Governance

Governance supports three main programs. Most organizations run more than one, and they share the same assessments, risks and workflows.

ProgramWhat it coversTypical work
PrivacyHow your organization collects and uses personal dataPrivacy impact assessments, data protection assessments, legitimate interest and transfer assessments
Vendor riskThe privacy, security and AI risk introduced by third partiesVendor onboarding, security reviews, cyber posture monitoring, periodic reassessment
AI governanceHow AI systems and agents are used across your organizationAI assessments, AI risk tracking, governance of discovered AI tools and agents

These programs help you meet requirements across privacy, security and AI frameworks worldwide, from US state privacy laws and the EU and UK GDPR to Brazil's LGPD, the EU AI Act, NIST AI RMF, ISO standards and DORA.

How Governance is organized

In the left navigation, Governance includes Assessments, Risks and AI posture. These are the main capabilities behind them:

CapabilityWhat it doesLearn more
AssessmentsEvaluate privacy, vendor, security and AI risk using templates, with help from Mira AIIntroduction to Assessments
Workflows and privacy by designTrigger the right reviews automatically when a new vendor, product or AI tool is requestedWorkflows / Privacy by design
Risk registryTrack every risk identified across your assessments through to mitigationManaging the risk registry
Vendor onboardingAdd new vendors, run their risk assessments and record approval decisionsOnboarding and assessing vendors
Policies and alertsMonitor your data map for governance issues and notify the right peopleCreating and managing policies and alerts
AI postureDiscover and govern AI tools and agents used across your organizationAISPM overview

How Governance connects to your data map

Governance works best when your inventory is up to date. Assessments pull data sources, data types and processing activities directly from your data map, risks link back to the systems they affect, and Mira AI uses your inventory to draft answers. The more complete your data map, the less you'll need to enter by hand. See Data mapping overview and quickstart.

Quickstart

  1. Check your inventory. Make sure the systems and vendors you want to assess are in your inventory, with owners and key details filled in. See Navigate Your Inventory.
  2. Set up your business profile. Give Mira AI context about your company and upload key policies, so its drafts reflect how you actually work. See Get started with Mira AI agents.
  3. Choose your templates. Start from the MineOS template catalog or build your own. See Building Templates.
  4. Create your first assessment. Pick a system, vendor or project, assign an owner and let Mira draft the first answers. See Creating Assessments.
  5. Review and track risks. Add the risks your assessment identifies to the risk registry, and mitigate them. See Managing the risk registry.
  6. Automate. Once your process is working, set up workflows so new vendors and projects are reviewed automatically. See Workflows / Privacy by design.

Did this page help you?