Know what is being used and why

Start with an inventory of AI-enabled tools and proposed applications. Record the business purpose, users, information involved, supplier and accountable owner. Include AI features inside existing software, not only tools purchased specifically as AI products. A feature switched on within a familiar platform can still change how information is processed.

Our governance service helps turn that inventory into usable operating controls. The goal is not a policy document that lives apart from delivery. It is a clear route for approving use, checking changes, handling problems and deciding when a system should stop.

Scale the controls to the consequences

Drafting an internal agenda is different from evaluating a job applicant or influencing access to a service. Consider the people affected, the sensitivity of the data and the consequences of an error. A low-friction internal aid and a consequential decision system should not pass through the same review without distinction.

The NIST AI Risk Management Framework organises work around Govern, Map, Measure and Manage. It provides a useful structure for thinking about risk, not a certificate that makes a deployment safe. Adapt the controls to your actual use and document the reasoning behind the decision.

Make data rules specific

Tell staff which categories of information may enter which tools. “Do not share sensitive data” is too vague if people cannot distinguish an approved business account from a personal chatbot account. State how customer records, staff information, credentials and confidential commercial material must be handled.

UK GDPR and the Data Protection Act form part of the relevant UK data protection framework, as amended. Consider lawful basis, transparency, minimisation, security and individual rights. Use ICO guidance on AI and data protection and involve your data protection lead. Obtain qualified advice where the legal position or a consequential use needs assessment.

Read the supplier terms against the use

Check what the supplier does with prompts, uploaded files and generated output. Look at retention, model-training use, subprocessors, international transfers and deletion arrangements. Distinguish the terms for the product and account type you intend to use; a consumer service description may not describe the business contract.

Ask how changes are communicated and whether you can export the information you need. Identify the dependency created by proprietary formats or specialised integrations. A supplier’s security claims are inputs to due diligence, not a substitute for your own assessment. Record what remains uncertain and who accepts the remaining risk.

Give human review real authority

A person is not meaningfully in control simply because their name appears in the process. They need enough information, time and authority to challenge the output. Define which decisions need review and what evidence the reviewer should see. Make rejection and escalation straightforward.

Training should cover plausible errors, unsupported citations, data leakage and malicious instructions embedded in documents. Use authorised practice material and the actual workflow. Staff should know how to report a problem without continuing the action that caused it. Where specialist judgement is required, retain the relevant professional rather than treating AI review as a generic administrative task.

Keep evidence of the checks that matter

Agree evaluation criteria before rollout and repeat relevant checks after material changes. Record the test inputs, expected behaviour and observed outcomes without retaining unnecessary personal data. Include accessibility and permission boundaries alongside output quality. An accurate answer delivered to the wrong person is still a failure.

Create an incident route with a responsible contact, a way to disable the affected function and a plan for preserving useful evidence. Determine whether a privacy or security incident triggers separate reporting duties. Your response process should not depend on the same AI component that may be malfunctioning.

Leave with controls people can follow

An agreed governance scope can include an AI-use policy, system inventory, supplier questions, approval records, review guidance and an incident procedure. Each control needs an owner and a place in the normal operating process. Keep requirements proportionate so that staff can comply without inventing workarounds.

This service supports operational governance; it is not legal advice, certification or a guarantee of regulatory compliance. Bring specialist advisers into regulated or high-impact uses. If your next step is choosing a first project, connect these controls to AI strategy. If a workflow is already being designed, build the permissions and approval points into the implementation rather than adding them at the end.