Service / Governance
Define who
is responsible.
AI governance means the responsibilities and controls used to decide how an organisation may use AI. It should explain permitted tasks, data boundaries, review requirements and what happens when something goes wrong. A policy is useful only when people can apply it to their actual work.

1. Record each proposed use.
Create a register describing the purpose, users, supplier, information involved and system owner. Include informal use of general-purpose chat tools as well as commissioned applications. Distinguish drafting internal text from producing material for customers, making recommendations about people or taking actions through connected systems.
Describe consequences in ordinary terms. Could an incorrect answer delay a task, disclose confidential information or influence a consequential decision? Identify affected people, not just technical assets. Use this description to determine the level of review required. Do not assume that a small implementation has a small impact.
2. Assign decisions to named roles.
Identify who approves the business purpose, who owns the data and who can authorise deployment. Separate these responsibilities where practical. The implementation team may understand the software but should not independently decide whether a proposed use is acceptable for the organisation or its customers.
Give each role a decision it can make: approve a source collection, accept a release, investigate an incident or suspend access. Document an escalation route when owners disagree. Human oversight requires time, authority and relevant information; placing a person at the end of a workflow is not enough if they cannot challenge its output.
3. Set practical data boundaries.
Specify what staff may enter into approved tools and what they must exclude. Address personal data, client confidentiality, access credentials and unpublished business information separately. Explain how to request an exception and which sharing method is approved. A general instruction to “be careful” leaves too much interpretation to the user.
For UK personal data processing, consider lawful basis, transparency, minimisation, security and individual rights under the UK GDPR and Data Protection Act 2018. A data protection impact assessment may be required for processing likely to create high risk. Use the ICO’s guidance and obtain qualified advice on the specific legal position.
4. Review suppliers and dependencies.
Check the contractual service being purchased, the processing locations, retention options, subprocessors and whether customer inputs may be used for model improvement. Consumer and business offerings can have different terms. Record the terms relied upon and an owner responsible for reviewing changes.
Consider exit arrangements. Determine how documents, indexes, prompts and configuration can be exported or deleted, and what remains if a supplier becomes unavailable. Where open-weight models are used, review licence conditions and the responsibilities transferred to your organisation. Operating a model internally still requires security, update and access-control decisions.
5. Connect policy to release checks.
Require evidence appropriate to the proposed task before release: representative evaluation, access tests, failure handling and a usable operating guide. Keep the approval record with the implementation details. If the system can take external actions, review its permitted tools and confirmation steps as part of the release decision.
The NIST AI Risk Management Framework offers a reference for identifying and managing AI risks. It is not a substitute for applicable law or a certification of a system. Use it to ask concrete questions about context, measurement and controls, then document the decisions relevant to your own use.
6. Prepare for incidents and change.
Define how staff report incorrect outputs, suspected disclosure or unexpected actions. Explain who can pause the system, preserve relevant records and restore the manual process. Limit incident records to what investigators need. Where personal data is involved, seek advice on notification duties and applicable time limits promptly.
A governance engagement can include a use register, responsibility map, acceptable-use guidance and operational review gates. Agree the scope and the legal questions that require specialist input. Revisit controls when the purpose, model, data sources or users change. Treat governance as an operating responsibility rather than a document completed once and forgotten.