Governance & Compliance · Data artifact
Departmental Policy
Data artifactGovernance & ComplianceSafety, Security & Governancearc:DepartmentalPolicy
An enforceable policy set that inherits the organizational baseline and adds domain-specific constraints for one business function, such as dual authorization or refund limits.
Responsibility. Extends the baseline with function-specific constraints for a department's agents.
Also known as: Departmental policy tier
Relationships
configures structural
constrains control
is constrained by control
Design guidance
- SHOULD inherit the organizational baseline while adding domain constraints (e.g., dual authorization for journal entries above materiality thresholds, supervisor approval for refunds above limits).
Classification
- Patterns
- Risk-based policy tieringPolicy inheritance
- Quality attributes
- Maintainability (ISO/IEC 25010)Transparency and accountability (NIST AI RMF: accountable and transparent)
Sources
- Ch10.5: T. Nguyen, "Human-over-the-Loop," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 10.5. ISBN: 9798244538229.