Your AI policy exists. Does anything check it?
Most organizations now have an AI policy. Far fewer can tell you which of their production models are running without a documented accuracy score, or which were trained on data whose sensitivity nobody has classified. Gartner already states that AI policies are not enough. The open question is whether anything checks them.
What’s new: Out of the box controls for Control Tower
Collibra Control Tower adds 80+ pre-built controls you can import and run covering AI governance and BCBS 239 risk reporting. With this addition you now have more than 100 controls ready to import, adjust and run.
Each one is a control that pairs a query —in simple terms, which assets does this apply to— with a condition those assets must satisfy. For example, an AI governance control might check that every AI Model Version has its Model Accuracy attribute populated, or that the data behind an AI Use Case carries a Data Category.
You import them in bulk and adjust to match how your program actually runs.
How the out-of-the-box controls for Control Tower helps
Writing a control that means anything takes two kinds of expertise in the same head: what your governance team expects, and how that expectation maps onto your asset types, attributes and relations. Most teams have both somewhere in the building, rarely in one person, almost never with time to spare. This enforcement gap is where AI and data programs fall short. These pre-defined controls close the gap by providing ready-to-use, essential checks for AI governance and BCBS239 adherence.
Problems it solves
- The blank page: Start from 100+ controls that already encode what to check, rather than specifying your first one from nothing.
- Regulatory translation: Each control names the rule, the asset type in scope, and the EU AI Act, NIST or BCBS239 article it was written against, so the mapping comes already done.
- Inconsistent logic: A shared library means two teams checking the same obligation check it the same way.
How the out-of-the-box controls work
Take one control from the AI governance set: AI Model Training Data Source System Has Open Issue
Its query defines the population: AI Models.
Its condition is the test each of those assets has to pass: That there are no un-resolved issues
Its schedule decides how often the check runs.
None of that machinery is new; it is the same anatomy any Control Tower control uses. What ships pre-built is the specification. The judgment that there should not be any AI Model whose source data has quality, system or infrastructure issues —which can be managed, tracked and resolved in Collibra.
The other 100+ controls work identically and differ only in what they specify. Some check that an attribute is populated, like “Owner”. Another checks “Sensitivity level”. But the power of Control Tower is when you need to run checks on metadata that’s multiple hops away in the knowledge graph: that the column, inside a table, used for a specific report, has a classification tag. And Control Tower supports up to 50 levels deep. That means no metadata is left behind.
Failures appear on the Control Tower dashboard, and the people who own them get an alert by email—with Slack and Microsoft Teams coming soon— with drill-down to the specific attribute that caused the violation.
And in just a couple clicks, you are confident that your most critical metadata is being watched and you have answers ready when leadership or the regulators ask.
Why you should be excited
Risk & Compliance Officer: The mapping work arrives done and documented: each control states the rule it enforces and the article or principle it was written against, so your programme starts from a compliance-derived rationale instead of your own team's interpretation of one.
AI/ML Platform Lead: Out-of-the-box controls covering model documentation, deployment monitoring and training data classification means you forget about AI governance knowing your AI building blocks are being monitored and ready when regulators ask.
Data Steward: Every control ships with a description of the rule and why the gap matters, so an alert tells you what failed and why it's worth your afternoon, with no reverse-engineering of somebody else's query logic.
Use cases
- BCBS 239 risk reporting: Thirty-two controls cover the reporting chain for Critical Data Elements with owners, definitions, calculation rules, and physical implementations that actually exist. If your programme has been tracked in a spreadsheet, this is the same scope running on a schedule.
- AI governance: Forty-six controls cover the AI estate from model documentation, deployment monitoring, training data classification to use case risk assessment. Mapped to the EU AI Act articles and NIST functions each was written against.
- Metadata best practice, regulation aside: Underneath the labels, these controls check things every governed estate needs: is it documented, does someone own it, is it linked to what it depends on, is the data behind it classified, are there data quality rules on it. Because each control is editable, the pattern retargets to whatever assets you govern. Most programs measure adoption by how much metadata they hold; this measures whether it holds up.
Key takeaways
The distance between having governance policies and enforcing them was never so short. Control Tower takes “manual” out from policy enforcement and the new out-of-the-box controls remove the blank page paralysis: deciding what to check, on which assets, and why the gap matters. These controls move that work out of your backlog and into your instance, where you can import, adjust, and find out what fails today.
Where to learn more about Control Tower
Get started with our product documentation and related resources.
Keep up with the latest from Collibra
I would like to get updates about the latest Collibra content, events and more.
Thanks for signing up
You'll begin receiving educational materials and invitations to network with our community soon.