Opens with a fictional UAE banking case in which a regulator demands full reconstruction of an AI credit decision and the bank can answer only one of four required questions.
Argues that AI governance programmes are commonly built backwards, with organisations deploying models before they can document what data or training conditions produced them.
Positions lineage and provenance as the load-bearing wall of AI governance, without which the rest of the management system cannot withstand regulator scrutiny.
Distinguishes three related but separate concepts, namely data provenance, data lineage and model lineage, each requiring its own register and evidence trail.
Written for AI governance leads, CISOs, compliance officers and internal auditors, it anchors traceability obligations in ISO 42001, ISO 27001 and EU AI Act Articles 10, 12 and 22.