Why frameworks start in the wrong place
The usual first move is to write an AI policy. It is visible, it can be approved at a board meeting, and it produces a document. It also governs nothing, because a policy is a set of rules about a population you have not yet identified.
The ordering that works is the reverse. Find out what you run. Classify it. Assign someone to each thing. Only then write the rules, because now they can be specific enough to follow.
The test of a governance framework is not whether it exists but whether it can answer four questions on demand: what AI systems do we operate, what does each one decide, who is accountable for it, and what would we do if one of them failed. Most frameworks that exist as documents cannot answer the first.
This lesson builds the foundation those questions rest on. The next covers the policy, decision rights and risk register that sit on top, and the third covers documentation and the evidence trail.

