As AI spreads through an organisation, informal approaches break down. AI governance provides consistent rules and oversight.
Key Components
- Policy: acceptable and prohibited uses, data rules, approval requirements.
- Roles: executive sponsor, system owners, risk and legal reviewers, data protection officer.
- AI inventory: a register of AI systems in use, including third-party tools, with owners and risk levels.
- Risk assessment: a proportionate review process — light for low-risk tools, thorough for high-impact ones.
- Standards: documentation, testing and monitoring requirements.
- Training: so staff know the rules and the risks.
Risk-Based Tiers
Classify uses by potential harm. For example: internal productivity tools (low), customer-facing assistants (medium), decisions about people's rights or opportunities (high). Apply stronger controls as risk increases.
Third-Party and Generative AI Tools
Staff adopt AI tools quickly. Provide approved tools with suitable data protections, clear guidance on what data may be shared, and a simple way to request new tools.
Lifecycle Controls
Build checks into project stages: approval before building, review before launch, and monitoring and periodic review after.
Align With Frameworks
Standards and frameworks — such as ISO/IEC 42001 for AI management systems and the NIST AI Risk Management Framework — provide structure, and regulations increasingly require governance practices.
Keep It Practical
Governance that is too heavy drives people to work around it. Make the right path the easy path.