AI Governance and Controls for Acquisition Programs
AI governance defines what the system may read, recommend, and do, and who remains accountable for each decision. Implement those boundaries in access controls and tools, then test that they hold under failure and misuse.
NIST organizes AI risk management around Govern, Map, Measure, and Manage. Its generative AI profile adds guidance for the risks these systems introduce. Use those resources to structure ownership and assessment; they do not certify a particular acquisition workflow. NIST AI RMF Core and Generative AI Profile.
Define authority by action
Read-only analysis, draft creation, internal updates, and external commitments deserve different permissions. A model's recommendation should not expand its authority.
| Action | Recommended boundary | Evidence to retain |
|---|---|---|
| Read permitted research | Enforce user and deal scope at retrieval | Sources accessed and requesting identity |
| Draft a screening memo | Label status and preserve cited inputs | Draft version and evidence references |
| Propose a pipeline change | Validate allowed transition and required review | Old state, proposed state and reviewer |
| Send outreach or disclose materials | Require authorized approval of exact recipients and payload | Approval and delivery record |
| Approve price, terms or a transaction | Keep with authorized human decision-makers | Decision, conditions and supporting versions |
Delegated credentials should have limited scope and lifetime. Recheck authority when a queued job runs and when it delivers an artifact. A user may lose access after scheduling the work.
Protect both documents and derived outputs
Deal permissions must cover originals, extracts, embeddings, search results, caches, generated reports, and exports. A confidential finding does not become unrestricted because AI paraphrased it.
Define what happens when permissions change or a retention period ends. Identify dependent artifacts for withdrawal, restriction, or review. Preserve records required by the organization's legal obligations under counsel's direction. Do not promise universal deletion without checking all copies and retention requirements.
Allow cross-deal learning through approved templates, generalized lessons, and explicitly permitted aggregates. A clean team arrangement requires counsel-defined membership and information rules; a “clean team” folder name provides no protection by itself.
Treat retrieved text as untrusted input
A document can contain instructions that try to redirect an AI system. OWASP describes this as indirect prompt injection when instructions arrive through external content. Its guidance also makes clear that retrieval-augmented generation does not eliminate the problem. OWASP: Prompt Injection.
Separate document content from system instructions. Restrict tools and outbound destinations, validate structured outputs, and require approval for consequential actions. Prompts can reinforce the boundary, but they cannot replace server-side authorization.
Test malicious instructions in realistic locations: a footnote in a seller deck, a spreadsheet cell, a company website, or an apparent source citation. Include attempts to reveal another deal's information and to mark an unresolved issue approved.
Make quality failures visible to reviewers
Show missing sources, incomplete extraction, unresolved contradictions, and estimates where they affect the conclusion. A confidence number should have a defined meaning and calibration evidence. Otherwise use explicit evidence states such as supported, disputed, and unknown.
Record model and workflow versions. Before a change reaches users, run the evaluation set and review failures by severity. A small improvement in drafting quality cannot compensate for a new permission leak.
Define an incident path: stop the affected workflow, preserve logs with appropriate access, identify impacted outputs, correct or withdraw them, and notify responsible owners. Resume only after the failure has a verified repair.
Continue with AI system architecture, measurement and learning, and AI in M&A.
© 2026 CorpDev.Ai Unified Process for M&A