There is now consensus on the principle: data governance constitutes the foundation of any AI strategy. Quality, freshness, traceability, access rights and purpose determine the reliability of the results. The NIST AI RMF also places the “Govern” function at the heart of risk management, throughout the lifespan of artificial intelligence systems.
Powerful models, but foreign to your business
From a theoretical point of view, a language model knows how to write, synthesize, classify information or construct reasoning. However, it doesn’t know what exactly an “active customer” means in your business, what pricing should be applied to a branch, or why a blocked order shouldn’t be restarted automatically. This knowledge remains dispersed in the information system. Some are formalized in repositories, others included in the rules of an ERP, CRM workflows or simply the habits of the teams. Thus, a general AI can perfectly master the vocabulary of finance or logistics… without understanding your validation thresholds, your internal responsibilities or the exceptions specific to your activity.
We therefore quickly realize that the context provided to the model becomes as important as the model itself.
Hence the importance of being able to answer some very concrete questions. Which application is authoritative? Which version of the data is correct? Who can consult it? For what purpose can it be used?
Because an AI governance policy will not produce anything truly solid and reliable as long as these answers remain implicit.
ERP, CRM and business tools carry operational memory
However, the necessary elements already exist, to a large extent, in the applications which record the daily operations of the company:
- Your ERP brings together financial processes, orders, inventory, purchasing or production;
- your CRM stores opportunities, exchanges and part of customer knowledge;
- Your BI tool consolidates this information for management;
- and your business software adds rules specific to the sector, products and organization.
The ERP can thus provide an AI with the real status of an order, when the CRM provides it with the commercial history necessary to prepare a response. The quality of the result will depend here on the consistency between these two readings. The difficulty appears when each application has its own definition.
Connecting applications therefore involves aligning repositories, documenting priority rules and preserving the origin of each piece of information..
“ A successful AI project does not rely solely on technology, it relies above all on the quality, governance and security of data coming from business tools, and particularly from ERP and CRM », Anne CANU Pre-sales Manager at TVH Consulting.
It remains to make this operational memory accessible to future AI services, without indiscriminately opening the entire information system.
Open the information system without losing control
APIs, connectors, integration platforms, data warehouses and lakehouse architectures help bring data closer to the applications that need it. The objective is to provide the AI with the information necessary for a defined use, in an understandable format and with limited rights. A well-thought-out architecture notably avoids point-to-point connections which multiply over the course of projects. It exposes reusable services, for example to consult a customer account, check stock or retrieve the status of a contract. Each service thus applies the same access rules and keeps track of the exchanges.
Also, the more flows circulate, the more strategic their supervision becomes. You need to know which application provided a piece of data, what transformation it underwent, and which system consumed it, because an error in a repository can now feed multiple assistants, automations, or agents before a team even detects it.
The opening must therefore remain reversible and controllable. But applying these principles first requires knowing what each piece of information really means.
Available data must still become understandable
A column entitled “status” can also designate a commercial, accounting or logistical situation. Just as a date can correspond to the creation of a file, its last modification or its closure… Without a common definition, the AI will mechanically interpret identical words as if they described the same reality. The quality of the data therefore relies on its mapping, its classification, its documentation and the identification of an owner. It also requires remediation rules when systems contradict each other.
You must in fact be able to link each piece of data to its origin, its purpose and the processing it has undergone. Its freshness must be specified depending on the use. A price, consent or stock level may require immediate updating, while other information may take longer.
Having data in the ERP, CRM or business applications is not enough to make it usable by artificial intelligence. It is still necessary to be able to understand its origin, meaning, level of quality, conditions of access and successive transformations. This is precisely the role of an approach allowing structure data governance across the information system as summarized by Alexis de Saint-Jean, Product Marketing Director at SoftProject: “AI does not automatically transform business data into knowledge. Between the two, we need governance capable of making this data reliable, understandable, traceable and accessible in the right context. It is this layer of trust and context that will allow us to move from experiments to truly industrialized AI uses. »
This governance must live in the tools and flows. Data integration and management platforms can apply standards, control exchanges and monitor anomalies between applications. Interoperability, flow management and governance are also conditions for a more coherent and usable information system. Documented and traceable data then becomes usable in several projects. You thus avoid each POC rebuilding its own data set, its own connectors and its own definition of the profession.
Common governance to sustainably exit the POC
Because the industrialization of AI requires transversal governance. Data teams cannot decide alone on the purpose of a use, just as businesses cannot ignore security constraints. Bringing together data governance, application architecture, cybersecurity, supervision and business responsibility is therefore essential.
An owner must be named for the use case, another for the data and a third for technical operation, and the conditions for stopping, correction and human validation must be known before going into production.
Governance supports the evaluation, deployment and monitoring of systems.
In practice, it makes it possible to reuse the same data services, the same access rules and the same control mechanisms from one project to another. Teams thus save time without giving up traceability, and audits are simplified, because responsibilities, sources and transformations are already documented.
The battle for reliable AI is therefore played out in the ERP, the CRM, the repositories, the interfaces and the processes that produce business knowledge. When these foundations remain fragile, AI especially accelerates the circulation of inconsistencies. Conversely, when they are governed, it can finally exploit the information system without losing the context which gives the data their value.
Content offered by Cloudlistthe crossroads for information on the IT sector