A Jira workflow template for AI governance in regulated environments
Embeds governance decisions into the moment they are made. PM, architect, and risk manager each answer specific questions at Epic creation. The evidentiary record is a byproduct of the workflow, not an additional artefact.
| Field | Type | Description |
|---|---|---|
| AI Agent Scope Statement | Text area | What is this agent permitted to do? What is explicitly out of scope? Good answers name specific actions, data types, and systems. |
| Permitted Data Types | Checkbox | PII / Financial data / Health data / Internal comms / Public data only / Other. At least one required. |
| Behavioural Violation Definition | Text area | What constitutes a violation of documented scope? Give a specific, observable example. This is what the monitoring mandate checks against. |
| Named Accountability Owner | User picker | Which named individual holds the ongoing monitoring mandate? Must be a person. Cannot be blank at Stage 5. |
| Regulatory Framework in Scope | Checkbox | EU AI Act / DORA / CRA / FCA / HIPAA / PCI DSS / Other. Selection activates relevant overlays. |
| High-Risk Classification | Dropdown | EU AI Act: Unacceptable / High / Limited / Minimal / Not assessed. |
| DORA Critical Function | Dropdown | Yes / No / Under assessment. Triggers DORA overlay in v1.1. |
| Third-Party AI Components | Text area | All third-party LLMs, APIs, AI services: provider, version, data processing location. |
| Monitoring Cadence | Dropdown | Daily / Weekly / Fortnightly / Monthly. Must be set before Stage 5 closes. |
| Pre-deployment Sign-off | PM | User + date | PM confirmation at Stage 5 that Inception fields are accurate and complete. |
| Pre-deployment Sign-off | Architect | User + date | Architect confirmation at Stage 5. |
| Pre-deployment Sign-off | Risk | User + date | Risk Manager confirmation at Stage 5. |
| Field | Type | Description |
|---|---|---|
| Governing Epic | Epic link | Link to the controlling Epic. Mandatory for all stories in AI agent projects. |
| Governance Relevance | Dropdown | Affects agent scope / Tool boundaries / Credential access / Monitoring / No impact. First four require Epic review before close. |
| OWASP Risk Reference | Dropdown | ASI01 / ASI02 / ASI03 / ASI05 / ASI10 / Other / Not applicable. |
| Compliance Evidence Required | Yes / No | Yes makes Evidence Reference mandatory before item closes. |
| Evidence Reference | Text / link | Link to compliance evidence record. Required when Compliance Evidence Required is Yes. |
| Scope Deviation | Yes / No | Yes requires Governing Epic Scope Statement to be updated and re-signed before this item closes. |
v1.1 will add compliance check decision nodes for Story and testing evidence branches
Create a new Epic-level issue type in Jira settings. Name it "AI Agent Epic". Keeps custom fields scoped to AI agent work.
Settings > Issues > Issue types > Add issue type
Name: AI Agent Epic | Type: EpicCreate each field from the Epic Field Reference above. Associate with "AI Agent Epic" issue type only.
Settings > Issues > Custom fields > Create custom field
Select type > Name as listed > Associate with AI Agent EpicCreate each field from the Story Field Reference. Associate with Story, Task, and Bug across projects containing AI agent work.
Prevent "Move to In Development" unless Named Accountability Owner and Scope Statement are populated. Prevent Stories closing if Scope Deviation is Yes and Epic is not updated.
Workflow > Edit workflow > Transition: "Move to In Development"
Condition: "Named Accountability Owner" is not empty
Condition: "AI Agent Scope Statement" is not emptyAdd the five OWASP overlay fields to the AI Agent Epic screen for relevant projects. Mark as required at Stage 5.
Automate Stage 6 monitoring tasks to generate on the cadence set in the Monitoring Cadence field, assigned to the Named Accountability Owner.
Automation > Scheduled trigger > Frequency: [Monitoring Cadence]
Create Task > "Monitoring review | [Epic name]"
Assignee: Named Accountability Owner > Link to EpicPublished by 4iGov.cloud. Version 1.0, April 2026. Free to use and adapt with attribution.
Citation: Source: 4iGov Design-Time Contract v1.0 | 4igov.cloud/dtc
Questions: [email protected] | Not legal or compliance advice.