AI governance: what to put in place and how it connects
An employee asks AI to draft a customer email. What data may be included? Who checks the response? And what happens if something goes wrong?
AI governance is the set of agreements and responsibilities that enables you to use AI responsibly. The infographic shows what this involves and how the areas influence each other.
Manageable for small organisations too
In a small organisation, one person can hold several responsibilities. A simple overview of the AI in use, clear working agreements and appropriate checks provide a practical starting point. The greater the potential consequences, the more carefully you organise assessment and oversight.
1. Direction, policy and responsibility
Management decides what you use AI for and translates this into working agreements. Who may authorise an application, who checks its use and who may intervene? Also agree which risks are acceptable within the applicable rules. Assign someone to maintain an overview. This framework guides every other area.
2. AI inventory, purpose and impact
Keep track of which AI you use, for what purpose and who is responsible internally. Include free tools and AI within existing software. Determine what the application delivers and whether an alternative would be more suitable. Consider possible errors and consequences for people, including privacy, fundamental rights and equal treatment. The same AI can pose different risks when used for a different task.
3. Responsible selection and introduction
Assess whether the application and supplier suit your purpose, data and working agreements. Test familiar practical situations and agree who decides internally whether the AI may be used. This is what we mean by ‘approve internally’. Reassess when new features, software updates or a different use change how it works or the risks involved.
4. Data, security and access
Check whether data is reliable and suitable, where it comes from and whether you may use it for this application. Decide who gets access and what connected systems or AI tools may do. Protect against data leaks, unauthorised access and misuse. For example, an AI that only drafts a customer email needs fewer permissions than one that also sends it.
5. People, competence and oversight
Help employees understand AI’s capabilities and limitations and provide clear work instructions. Explain the role AI plays to those involved and provide understandable explanations of relevant outcomes. Agree who checks, intervenes and addresses concerns. Make reassessment possible and listen to employees’ and customers’ experiences. People providing oversight need the knowledge, time and authority to do so.
6. Evaluation, incidents and improvement
Keep monitoring whether the AI delivers adequate quality and what effects its use has. Arrange how errors are reported, harm is limited and those involved are informed. Use these experiences to improve the application or the way you work. Sometimes this means restoring proper operation or stopping safely. Think ahead about how work will continue in that situation.
What the frame, arrows and bottom band mean
The surrounding frame shows that direction and responsibility apply throughout. The double-headed arrows show mutual influence. Areas without a direct arrow can also affect each other; the numbers do not indicate a fixed working sequence.
For example, does the AI used for customer emails gain access to customer records? Then the inventory and access permissions change. Tests, work instructions and internal approval also need to be reviewed.
The bottom band applies to every area, including direction. Follow the applicable rules and record important decisions, checks and improvements. Regularly assess whether those agreements still fit. This allows you to demonstrate how you handle AI.
This infographic is our own practical synthesis, inspired by NIST AI RMF and the OECD AI Principles. It is not an official standards framework or a complete compliance checklist.