AI governance

Put clear controls around the AI your business uses

AI governance turns broad principles into practical rules for ownership, approved uses, data access, testing, human review, changes, monitoring and shutdown.

Assign an owner to every AI control

The inputs, sources, tests, human approval, release record, monitoring and ways to reverse a change each need an owner.

What we help you put in place

01

List each AI use and owner

Record the AI systems and uses that matter, who owns each one and who may approve changes.

02

Data and access rules

Define approved sources, sensitive information, providers, permissions, retention and deletion.

03

Testing and release

Test real examples, decide what counts as passing, record known limits and save the results before release.

04

Monitoring and incidents

Monitor failures, cost and changes in behaviour, with clear ways to escalate, override, reverse or stop the system.

Apply controls to each AI use

  1. List the AI systems

    List the systems, users, data and decisions already in use.

    You receiveList of AI systems

  2. Assess the risk

    Separate low-risk assistance from uses that affect people, money, rights or business commitments.

    You receiveRisk level

  3. Set the controls

    Set the rules, records and human decisions required for each risk level.

    You receiveRules and responsibilities

  4. Review changes and incidents

    Review changes and incidents so the controls remain useful after launch.

    You receiveReview notes

Next step

Tell us which AI system needs controls

We will map what it does, where the data goes and which controls need to exist around it.

Questions

Questions people ask us

What is AI governance?
Knowing which AI tools your business uses, what data reaches them, what it costs and what gets logged. For a business under a hundred people it is four practical things rather than a framework document.
Do we need this at fifty people?
If you handle client data with an obligation attached, or a client has asked how you control AI use, then yes. If you are ten people using ChatGPT for marketing copy, a clear policy and a paid team account will do and we will tell you that.
Our policy says staff cannot use AI tools. Is that enough?
Usually not. Policies mostly move the usage somewhere you cannot see, and the people who most need the help are the ones most likely to route around it on personal accounts.
A client has asked how we control AI use of their data. What do we tell them?
Ideally, that there is one controlled route in, that permissions match what each person could access anyway, and that you have logs. Most businesses find out they cannot answer this during the conversation where it matters.
How long does it take to put in place?
For a business of fifty people, about a fortnight for the four things that matter: one route in, permissions, cost limits and logging. It is a project rather than a transformation programme.
Will this slow our team down?
It should not. If controls make the approved tool slower than the unapproved one, people use the unapproved one. The point is to give them something good enough to use with the controls sitting underneath.