Getting started with Governance
Learn how the Governance module helps you assess and manage privacy, vendor and AI risk, and get set up in a few steps.
Governance is where you evaluate and manage risk across your organization. It brings privacy assessments, vendor risk management and AI governance into one place, built on top of your data map, so every assessment and risk is connected to the real systems, vendors and data behind it.
What you can do with Governance
Governance supports three main programs. Most organizations run more than one, and they share the same assessments, risks and workflows.
| Program | What it covers | Typical work |
|---|---|---|
| Privacy | How your organization collects and uses personal data | Privacy impact assessments, data protection assessments, legitimate interest and transfer assessments |
| Vendor risk | The privacy, security and AI risk introduced by third parties | Vendor onboarding, security reviews, cyber posture monitoring, periodic reassessment |
| AI governance | How AI systems and agents are used across your organization | AI assessments, AI risk tracking, governance of discovered AI tools and agents |
These programs help you meet requirements across privacy, security and AI frameworks worldwide, from US state privacy laws and the EU and UK GDPR to Brazil's LGPD, the EU AI Act, NIST AI RMF, ISO standards and DORA.
How Governance is organized
In the left navigation, Governance includes Assessments, Risks and AI posture. These are the main capabilities behind them:
| Capability | What it does | Learn more |
|---|---|---|
| Assessments | Evaluate privacy, vendor, security and AI risk using templates, with help from Mira AI | Introduction to Assessments |
| Workflows and privacy by design | Trigger the right reviews automatically when a new vendor, product or AI tool is requested | Workflows / Privacy by design |
| Risk registry | Track every risk identified across your assessments through to mitigation | Managing the risk registry |
| Vendor onboarding | Add new vendors, run their risk assessments and record approval decisions | Onboarding and assessing vendors |
| Policies and alerts | Monitor your data map for governance issues and notify the right people | Creating and managing policies and alerts |
| AI posture | Discover and govern AI tools and agents used across your organization | AISPM overview |
How Governance connects to your data map
Governance works best when your inventory is up to date. Assessments pull data sources, data types and processing activities directly from your data map, risks link back to the systems they affect, and Mira AI uses your inventory to draft answers. The more complete your data map, the less you'll need to enter by hand. See Data mapping overview and quickstart.
Quickstart
- Check your inventory. Make sure the systems and vendors you want to assess are in your inventory, with owners and key details filled in. See Navigate Your Inventory.
- Set up your business profile. Give Mira AI context about your company and upload key policies, so its drafts reflect how you actually work. See Get started with Mira AI agents.
- Choose your templates. Start from the MineOS template catalog or build your own. See Building Templates.
- Create your first assessment. Pick a system, vendor or project, assign an owner and let Mira draft the first answers. See Creating Assessments.
- Review and track risks. Add the risks your assessment identifies to the risk registry, and mitigate them. See Managing the risk registry.
- Automate. Once your process is working, set up workflows so new vendors and projects are reviewed automatically. See Workflows / Privacy by design.
Updated about 1 hour ago
