The difference between an AI governance consulting engagement that delivers transformative results and one that stalls in committee is often determined before the first workshop. Preparation — understanding the customer's context, their adoption journey, their political landscape, and their expectations — is the foundation that everything else builds on.
This framework provides a structured approach to pre-meeting preparation that ensures you walk into every customer engagement with the context needed to add value from minute one.
Part 1: Customer Context and History
Before discussing governance, understand where the customer is and how they got there.
Business Context
Pre-Meeting Research Checklist
- Industry and sector: Financial services, insurance, healthcare, energy, public sector? Each has different regulatory pressures, risk appetites, and AI maturity norms
- Company size and structure: Revenue, employee count, geographic footprint, business units. Governance complexity scales with organizational complexity
- Regulatory landscape: Which regulations apply? AI Act (all EU), DORA (financial), NIS2 (essential/important entities), sector-specific? Has the customer already been examined by regulators on AI topics?
- Recent events: Mergers, reorganizations, regulatory findings, public AI incidents, leadership changes. These create context for urgency and organizational dynamics
- Strategic priorities: Annual report, investor presentations, press releases — what is the executive team focused on? AI governance must connect to strategic priorities to get traction
AI History and Current State
Gather as much as possible before the meeting; validate and deepen during the conversation:
- AI journey timeline: When did the organization start with AI? First PoC? First production model? Key milestones and setbacks?
- Current AI portfolio: How many models in production? What types (classical ML, deep learning, GenAI)? Which business processes?
- Previous governance attempts: Has the organization tried to implement AI governance before? What worked? What didn't? Understanding past failures prevents repeating them
- Technology stack: Cloud provider(s), ML platforms, data platforms, existing governance tooling. This determines what's feasible and what requires new investment
- Existing policies: Does the organization already have AI-related policies? Data governance policies? IT security policies that cover AI? These are starting points, not blank slates
- Known incidents: Has the organization experienced AI-related incidents (biased outputs, data breaches, model failures)? Incidents create urgency and teachable moments
Engagement History
- Previous engagements: Has Open Empower (or another consultancy) worked with this customer before? On what topics? What was delivered? What's the relationship quality?
- Trigger for this engagement: Why now? Regulatory deadline? Board directive? Incident response? New AI initiative? Understanding the trigger reveals the real priority
- Budget and timeline expectations: Is there an approved budget? A fixed deadline (e.g., AI Act enforcement date)? Resource constraints?
- Decision-making process: How does this organization make decisions? Consensus-driven? Executive mandate? Committee-based? This determines your engagement approach
Part 2: Adoption and Change Management Status
AI governance is fundamentally a change management challenge. Technology is 20% of the problem; organizational adoption is 80%.
Current Adoption Assessment
AI Adoption Maturity
- Experimentation phase: Scattered PoCs, no production AI, individual enthusiasts driving adoption
- Early production: 1-5 models in production, dedicated data science team, basic infrastructure
- Scaling: 10+ models, cross-functional AI teams, platform approach emerging
- Enterprise-wide: AI embedded across business units, self-service platform, AI-first culture
Governance Adoption Maturity
- No governance: AI deployed without oversight. Shadow AI prevalent. No policies or processes
- Awareness: Organization recognizes governance is needed. Some documentation exists. No consistent enforcement
- Partial implementation: Policies exist for some areas. Inconsistent application across teams. Manual processes
- Systematic: Comprehensive framework in place. Consistent enforcement. Beginning to automate
Adoption Initiatives in Progress
Map what's already underway — don't duplicate or conflict with existing efforts:
Adoption Initiative Inventory
- AI strategy programs: Is there a formal AI strategy? Who owns it? Is governance included or treated as a separate workstream?
- Platform initiatives: Is an Internal Developer Platform or MLOps platform being built? Governance can be embedded in the platform rather than layered on top
- Training programs: Are there AI literacy programs for business users? Technical training for engineers? Governance-specific training?
- Center of Excellence (CoE): Is there an AI CoE? What's its mandate — advisory, delivery, governance, or all three?
- Vendor programs: Is a cloud provider (Microsoft, AWS, Google) running an AI adoption program? These often include governance components that should be coordinated
Champion Programs
Champions — influential individuals who advocate for AI governance within their teams — are the most effective adoption accelerator:
- Do champions exist? Are there individuals in business units who naturally advocate for responsible AI practices?
- Is there a formal champion network? Some organizations have structured champion programs with regular meetings, shared resources, and recognition
- Champion profile: Effective AI governance champions combine technical credibility with business understanding and organizational influence. They're often senior engineers, tech leads, or business analysts — not executives
- Champion gaps: Which business units or teams lack a governance advocate? These are the areas where adoption will struggle most
Training and Enablement Plans
- Current training inventory: What AI and governance training exists? Who's been trained? When was it last updated?
- Training gaps: Common gaps include:
- Business stakeholders: AI literacy and responsible AI awareness
- Data scientists: governance requirements, documentation standards, fairness testing
- Engineers: security practices for AI, MLOps governance integration
- Leadership: AI risk and opportunity, regulatory landscape, governance investment case
- Preferred training modalities: Self-paced e-learning? Workshop-based? On-the-job coaching? Blended? Understanding preferences increases adoption of training programs
Known Adoption Challenges
Every organization has friction points. Identify them before proposing solutions:
- "Governance slows us down": The most common complaint. Usually indicates governance processes are not risk-proportionate — every model gets the same heavy review regardless of risk
- "We don't have enough people": Governance team is overwhelmed. Need to identify what can be automated, what can be delegated, and what genuinely requires additional headcount
- "The business doesn't care about governance": Business stakeholders see governance as IT's problem. Need executive sponsorship and clear connection between governance and business value
- "We've tried this before and it failed": Previous governance initiative stalled. Understand why: too ambitious? No executive support? Wrong approach? Organizational change resistance?
- "Our data isn't ready": Data quality and governance issues block AI initiatives. Often used as a reason to delay governance — but data governance and AI governance should be parallel workstreams
- "Legal/compliance doesn't understand AI": Governance and compliance teams lack technical understanding. Results in overly conservative policies that block legitimate AI use
- "Shadow AI is everywhere": Business users adopting GenAI tools outside IT governance. Attempting to block it drives adoption further underground. Need a sanctioned alternative with guardrails
Kubernetes Recipes
A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).
Watch on Skillshare →Part 3: Key Customer Stakeholders
Stakeholder mapping is the most politically sensitive and most valuable preparation activity. Get this right and the engagement flows; get it wrong and you'll spend months navigating organizational politics.
The Stakeholder Map
Decision Makers
People who can approve budget, allocate resources, and mandate change:
- Executive sponsor: The senior leader championing the governance initiative. Typically CTO, CIO, CRO, or CDO. Assess: How committed are they? Do they have budget authority? Are they willing to mandate compliance?
- Board representative: Board member with AI or technology oversight. Important for high-level governance approval and regulatory credibility
- Budget owner: May or may not be the executive sponsor. Identify who controls the budget for this initiative
Influencers
People who shape opinions and can accelerate or block adoption:
- Head of Data Science / AI: Technical leader for AI capabilities. Their buy-in determines whether governance is seen as enabling or obstructing. Often the most influential voice on AI matters
- Chief Risk Officer / Head of Risk: Natural ally for governance — their job is risk management. But may push for overly conservative controls if not properly engaged
- Chief Information Security Officer: Controls security infrastructure and policy. Must be aligned on AI security approach. Potential ally if AI security is framed as extending their existing mandate
- Head of Compliance / Legal: Interprets regulatory requirements. Can be either an enabler (pragmatic interpretation) or blocker (ultra-conservative interpretation). Understanding their disposition is critical
- Business unit leaders: The people whose teams will live with governance processes. Their feedback on process design is essential for adoption
Doers
People who will implement and operate governance:
- Governance team: If one exists — who's on it? What's their capacity? What's their current mandate?
- Platform/MLOps team: Will embed governance in technical infrastructure. Their enthusiasm and capacity are key constraints
- Data governance team: Often already has processes that can be extended to AI. Potential for synergy or territorial conflict
Allies and Skeptics
Stakeholder Classification
- Champions (high influence, high support): Engage early. Give them ownership of visible governance wins. Use their credibility to bring others along. They're your force multiplier
- Supporters (low influence, high support): Valuable for execution. Engage them in working groups, pilot programs, and champion networks. Build their influence through governance successes
- Skeptics (high influence, low support): The highest-priority stakeholder management challenge. Understand their objections. Address concerns directly. Find ways to demonstrate value to their specific priorities. A converted skeptic becomes the strongest champion
- Disengaged (low influence, low support): Lowest priority for active engagement. Keep informed through general communications. May become engaged as governance matures
Common Skeptic Profiles and Strategies
- "The Innovator" — fears governance will kill innovation: Show risk-proportionate governance. Demonstrate that low-risk models have a fast track. Emphasize governance as a competitive advantage (enables AI in regulated markets competitors can't enter)
- "The Pragmatist" — wants to see ROI before investing: Lead with business value. Start with a quick win that demonstrates tangible benefit. Frame governance investment as regulatory risk reduction with quantified cost avoidance
- "The Perfectionist" — wants to govern everything before deploying anything: Show the cost of over-governance (delayed AI value, team frustration, competitive disadvantage). Advocate for iterative governance that matures alongside AI maturity
- "The Burned" — previous governance initiative failed: Acknowledge the failure. Understand root causes. Demonstrate how this approach is different. Start small, prove value, then expand
- "The Territorial" — sees governance as threatening their domain: Position governance as extending their existing capabilities, not replacing them. Find ways to give them ownership of governance components within their domain
Stakeholder Engagement Plan
For each key stakeholder, document:
- Name and role
- Classification: Champion / Supporter / Skeptic / Disengaged
- Influence level: High / Medium / Low
- Key concerns: What do they care about? What are they worried about?
- Engagement approach: How will you engage them? (1:1 meeting, workshop participation, steering committee, email updates)
- Success metric: How will you know they're engaged and supportive?
- Owner: Who on the consulting team owns this relationship?
Part 4: Meeting Logistics and Next Steps
Pre-Meeting Logistics
Meeting Design
- Objective: Define a clear, specific objective for the meeting. "Discuss AI governance" is too vague. "Align on governance maturity assessment scope and timeline" is actionable
- Agenda: Share agenda 48 hours in advance. Include time allocations. Leave 15-20% buffer for discussion
- Duration: 60-90 minutes for initial meetings. Longer workshops require formal agenda and breaks
- Format: In-person preferred for initial engagement (builds trust). Virtual acceptable for follow-ups
Attendee Management
- Right people in the room: Executive sponsor (for at least the opening 15 minutes), SPOC or governance lead, technical lead for AI, and one business stakeholder who will be directly impacted by governance
- Not too many: Decision-making meetings: 4-6 people maximum. Workshops: 8-12. Larger groups become presentations, not discussions
- Pre-meeting 1:1s: For initial engagements, schedule 15-minute 1:1 calls with key stakeholders before the main meeting. Builds rapport, surfaces concerns privately, and prevents surprises in the meeting
Materials Preparation
- Context summary: One-page brief summarizing your understanding of their situation (share in advance for validation)
- Framework overview: High-level view of your governance approach — enough to orient discussion, not enough to overwhelm
- Relevant case studies: 1-2 examples from similar organizations (same industry, similar maturity level). Anonymized but specific enough to be credible
- Draft proposal: If the meeting is to agree on scope — bring a draft. It's easier to critique a draft than to build from scratch in a meeting
Meeting Structure
Recommended 90-Minute Initial Meeting Agenda
- 0-10 min — Introductions and objective: Brief intros. Confirm meeting objective. Set expectations for outputs
- 10-25 min — Customer context: Customer shares their AI journey, current state, and aspirations. Listen more than talk. Validate your pre-research understanding
- 25-40 min — Challenges and priorities: What's driving the governance need? What are the pain points? What does success look like? This is where you discover the real priorities (often different from the stated brief)
- 40-55 min — Approach overview: Present your governance framework at a high level. Focus on how it addresses their specific challenges. Invite questions and pushback
- 55-70 min — Scope and timeline discussion: What's feasible within their constraints? Agree on assessment scope, team involvement, and target timeline
- 70-80 min — Stakeholder alignment: Who else needs to be involved? What's the decision-making process? Any organizational sensitivities to navigate?
- 80-90 min — Next steps: Agree on specific next actions with owners and deadlines. Schedule follow-up meeting
Post-Meeting Follow-Up
- Same day — meeting notes: Send structured meeting notes within 4 hours. Include: key points discussed, decisions made, action items with owners and deadlines, open questions
- Within 48 hours — proposal update: If scope was discussed, send updated proposal reflecting meeting discussion
- Within 1 week — stakeholder follow-ups: Schedule 1:1 conversations with stakeholders identified during the meeting who weren't present
- Ongoing — relationship maintenance: Share relevant articles, regulatory updates, or industry news that connects to their situation. Stay visible between formal meetings
Next Steps Framework
Every meeting should conclude with clear next steps. Standard progression for governance engagements:
- Discovery meeting (this meeting): Understand context, align on objectives
- Maturity assessment: Structured evaluation across 4 domains (Business Value, Usage, Governance, Security)
- Findings presentation: Scorecard, gap analysis, priority recommendations
- Roadmap workshop: Collaborative session to build the improvement roadmap
- Implementation kickoff: Begin executing Tier 1 actions
- Monthly check-ins: Progress reviews, obstacle resolution, scope adjustments
- Quarterly maturity re-assessment: Measure progress against baseline
Root Cause Analysis: Principles and Benefits
Master root cause analysis techniques for systematic problem solving. In collaboration with Starweaver.
Start on Coursera →The One-Page Briefing Template
Prepare this for every customer meeting — it forces structured thinking and provides a reference during the conversation:
Customer Meeting Briefing Template
- Customer: [Name, industry, size]
- Meeting objective: [One sentence]
- Attendees: [Name, role, classification (champion/skeptic)]
- Context: [2-3 sentences on current AI state and governance maturity]
- Trigger: [Why now? What's driving this engagement?]
- Key concerns: [Top 3 customer concerns based on pre-research]
- Our hypothesis: [What we think they need, to be validated in the meeting]
- Questions to answer: [3-5 specific questions we need answered in this meeting]
- Desired outcome: [What specific agreement or decision do we want from this meeting?]
- Risk/sensitivity: [Anything politically sensitive, previous failures, relationship issues]
Common Meeting Mistakes
- Presenting before listening: The customer doesn't care about your framework until they believe you understand their situation. Listen first, present second
- Assuming the brief is the real problem: The stated reason for the engagement is often a symptom. "We need AI governance" might really mean "the regulator asked uncomfortable questions" or "our data scientists are frustrated with compliance overhead"
- Ignoring the skeptics: It's tempting to work with the champions and avoid difficult conversations with skeptics. But unaddressed skepticism becomes active resistance later
- Over-promising scope: Enthusiasm in the first meeting leads to scope creep. Be clear about what's achievable within the discussed timeline and budget
- Leaving without next steps: Every meeting must end with specific, dated, owned next actions. "We'll follow up" is not an action item
AI Readiness Checklist
50-point interactive checklist covering strategy, data, infrastructure, governance, and people. Score your organisation's AI readiness.
Get Free Checklist →Related Solution
Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 2-3 weeks.
Explore AI Readiness for Regulated Enterprises →
Luca Berton
