AIAdopt
InfographicarticleSeptember 20263 min reading time

AI governance: what to put in place and how it connects

An employee asks AI to draft a customer email. What data may be included? Who checks the response? And what happens if something goes wrong?

AI governance is the set of agreements and responsibilities that enables you to use AI responsibly. The infographic shows what this involves and how the areas influence each other.

Manageable for small organisations too

In a small organisation, one person can hold several responsibilities. A simple overview of the AI in use, clear working agreements and appropriate checks provide a practical starting point. The greater the potential consequences, the more carefully you organise assessment and oversight.

1. Direction, policy and responsibility

Management decides what you use AI for and translates this into working agreements. Who may authorise an application, who checks its use and who may intervene? Also agree which risks are acceptable within the applicable rules. Assign someone to maintain an overview. This framework guides every other area.

2. AI inventory, purpose and impact

Keep track of which AI you use, for what purpose and who is responsible internally. Include free tools and AI within existing software. Determine what the application delivers and whether an alternative would be more suitable. Consider possible errors and consequences for people, including privacy, fundamental rights and equal treatment. The same AI can pose different risks when used for a different task.

3. Responsible selection and introduction

Assess whether the application and supplier suit your purpose, data and working agreements. Test familiar practical situations and agree who decides internally whether the AI may be used. This is what we mean by ‘approve internally’. Reassess when new features, software updates or a different use change how it works or the risks involved.

4. Data, security and access

Check whether data is reliable and suitable, where it comes from and whether you may use it for this application. Decide who gets access and what connected systems or AI tools may do. Protect against data leaks, unauthorised access and misuse. For example, an AI that only drafts a customer email needs fewer permissions than one that also sends it.

5. People, competence and oversight

Help employees understand AI’s capabilities and limitations and provide clear work instructions. Explain the role AI plays to those involved and provide understandable explanations of relevant outcomes. Agree who checks, intervenes and addresses concerns. Make reassessment possible and listen to employees’ and customers’ experiences. People providing oversight need the knowledge, time and authority to do so.

6. Evaluation, incidents and improvement

Keep monitoring whether the AI delivers adequate quality and what effects its use has. Arrange how errors are reported, harm is limited and those involved are informed. Use these experiences to improve the application or the way you work. Sometimes this means restoring proper operation or stopping safely. Think ahead about how work will continue in that situation.

What the frame, arrows and bottom band mean

The surrounding frame shows that direction and responsibility apply throughout. The double-headed arrows show mutual influence. Areas without a direct arrow can also affect each other; the numbers do not indicate a fixed working sequence.

For example, does the AI used for customer emails gain access to customer records? Then the inventory and access permissions change. Tests, work instructions and internal approval also need to be reviewed.

The bottom band applies to every area, including direction. Follow the applicable rules and record important decisions, checks and improvements. Regularly assess whether those agreements still fit. This allows you to demonstrate how you handle AI.

This infographic is our own practical synthesis, inspired by NIST AI RMF and the OECD AI Principles. It is not an official standards framework or a complete compliance checklist.

You'll want to know this too...

All insights
📄
February 2026

Shadow AI in SMEs: risks, scale and how to respond

Shadow AI, the unapproved use of AI tools at work, is growing fast in SMEs. The risks for data, quality, compliance and reputation, and how to channel it.

Read more →
🧰
August 2026

Which AI model is inside? That does not yet tell you what the AI can do

Knowing the model does not tell you what the AI may do. The agentic harness sets access, tools and permissions. The questions to ask before you commit.

Read more →
🕸️
August 2026

One safe AI agent does not make a safe AI system

You can test every AI agent carefully on its own and still end up with a system that is not safe. That is the central finding of a new report from the Australian AI Safety Institute, published on 10 August 2026.

Read more →

Shall we talk?

Get in touch for a no-obligation conversation about what AIAdopt can do for your organisation.