How to Approach AI Governance from Scratch
Artificial intelligence is no longer something organisations can treat as a future issue. Staff are already using AI tools to draft documents, summarise information, analyse data, write code, support customer service and improve productivity. Vendors are also embedding AI into everyday business systems such as email, collaboration platforms, finance systems, HR tools, CRM platforms and cybersecurity products.
For many organisations, the real question is no longer whether AI will be used. It is about whether AI will be used safely, responsibly, and in a way that protects the organisation, its people, its clients, and its reputation.
That is where AI governance comes in.
AI governance is the set of structures, policies, controls and practices that help an organisation make good decisions about AI. It helps answer questions such as:
- Who is accountable for AI use?
- What AI tools are approved?
- What data can and cannot be entered into AI systems?
- Which AI uses are too risky?
- When does AI output need human review?
- How do we manage AI vendors?
- How do we detect and respond when AI causes harm or produces poor outcomes?
For organisations starting from scratch, AI governance can feel overwhelming. The good news is that it does not need to begin as a large, complex program. The best approach is to start with visibility, accountability and practical controls, then mature the program over time.

Figure 1: How to Approach AI Governance from Scratch
1. Start with accountability
The first step is to decide who owns AI governance.
AI should not sit only with IT, innovation or data teams. It creates legal, privacy, cyber security, operational, reputational, ethical and people risks. That means governance needs executive ownership and cross-functional input.
A practical starting point is to appoint an executive owner and establish an AI governance working group. This group should include representatives from technology, cyber security, risk, legal, privacy, data governance, procurement, HR and key business areas.
The role of the group is to set direction, approve the AI governance framework, review higher-risk AI use cases, monitor risks and report to senior leadership or the board.
2. Find out where AI is already being used
Most organisations are using more AI than they realise.
Staff may be using public tools such as ChatGPT or Gemini. Business units may be trialling AI tools without central approval. Vendors may have switched on AI features inside existing software platforms. Developers may be using AI coding assistants. Marketing teams may be using AI to create content. Customer service teams may be experimenting with chatbots.
Before an organisation can govern AI, it needs to know where AI is being used.
This requires an AI inventory or register. At a minimum, the register should capture:
- the AI tool or system being used;
- the business owner;
- the purpose of use;
- the type of data being entered;
- whether personal or confidential information is involved;
- whether the output is used for decisions;
- whether customers, employees or other people may be affected;
- the vendor or platform provider;
- the risk rating;
- the approval status.
This step is important because unmanaged AI use can quickly create privacy, confidentiality, security, legal and reputational exposure.
3. Set clear rules for acceptable AI use
Once there is basic visibility, the organisation should issue clear rules for staff.
An AI acceptable use policy should explain what people can and cannot do with AI. It should be short enough to be understood, but clear enough to be enforceable.
A good AI acceptable use policy should cover:
- approved AI tools;
- prohibited tools or uses;
- what data must not be entered into AI systems;
- rules for confidential, personal, client and sensitive information;
- requirements for checking AI-generated outputs;
- use of AI for external communications;
- use of AI for code or technical work;
- copyright and intellectual property considerations;
- recordkeeping expectations;
- escalation and approval requirements.
One of the most important rules is data handling. Staff should know that confidential business information, client information, personal information, legal advice, credentials, source code, security information and commercially sensitive material must not be entered into unapproved public AI tools.
4. Classify AI use by risk
Not all AI use carries the same level of risk.
Using AI to help draft an internal meeting agenda is very different from using AI to assess job applicants, make lending decisions, analyse medical information, provide legal advice, or interact directly with customers.
Organisations should classify AI use into risk tiers. A simple model might include:
- Low-risk use — internal productivity tasks, such as drafting, summarising or brainstorming, where no sensitive data is used and humans review the output.
- Medium-risk use — internal operational support, analysis or decision support involving business data.
- High-risk use — AI that affects customers, employees, legal rights, financial outcomes, access to services, safety, health, employment or vulnerable people.
- Prohibited use — AI uses the organisation will not allow because they are unlawful, unethical, unsafe or outside risk appetite.
This risk classification helps avoid two common mistakes: treating every AI use as equally dangerous, or treating every AI use as harmless.
5. Introduce an AI impact assessment
For medium and high-risk AI use, organisations should require an AI impact assessment before the system is approved.
An AI impact assessment helps the organisation understand the purpose, benefits, risks and required controls for a proposed AI use case.
It should consider:
- What problem is the AI system trying to solve?
- Is AI necessary, or is a simpler solution available?
- What data will be used?
- Is personal, confidential or sensitive information involved?
- Who could be affected by the AI output?
- Could the system create unfair, biased or discriminatory outcomes?
- How accurate and reliable does the system need to be?
- How will outputs be checked?
- Who is accountable for the final decision?
- What happens if the AI system is wrong?
- What monitoring will be performed?
- What records need to be retained?
This process does not need to be overly bureaucratic. The level of assessment should match the level of risk.
6. Put human oversight in the right places
AI can support people, but in many situations it should not replace human judgement.
For higher-risk use cases, organisations should define when human review is required. This is especially important where AI outputs could affect people’s rights, opportunities, access to services, financial position, employment, safety or reputation.
Human oversight should be meaningful. It is not enough for a person to rubber-stamp an AI output they do not understand. The reviewer needs enough information, authority and competence to challenge the AI output and make the final decision.
Practical controls include:
- requiring human approval before high-impact decisions;
- documenting the final decision-maker;
- recording when AI was used;
- keeping evidence of review;
- allowing decisions to be challenged or appealed;
- creating fallback processes if the AI system fails.
7. Strengthen data, privacy and security controls
AI governance must be supported by technical and operational controls.
Policies alone are not enough. If staff can still paste sensitive data into unapproved AI tools, the organisation has not really controlled the risk.
Useful controls include:
- approved AI platforms for business use;
- single sign-on and multi-factor authentication;
- role-based access control;
- data loss prevention controls;
- monitoring of AI tool usage;
- restrictions on browser plugins and unauthorised AI tools;
- secure configuration of enterprise AI platforms;
- logging and audit trails;
- controls over AI integrations and APIs;
- prompt injection and output filtering controls for AI applications;
- incident response procedures for AI-related issues.
AI should also be included in cyber security, privacy, data governance and records management processes.
8. Manage AI vendors and embedded AI
Many AI risks come through third-party vendors.
Software providers are rapidly adding AI features to their products. Sometimes these features are enabled by default, or introduced through product updates. Organisations need to understand what vendors are doing with data and how AI functionality is being controlled.
Procurement and vendor risk processes should be updated to ask:
- Does the product include AI functionality?
- What data is processed by the AI system?
- Is customer data used to train or improve models?
- Where is data stored and processed?
- Who has access to the data?
- What security controls are in place?
- Can the AI feature be disabled or configured?
- What audit logs are available?
- What happens if the AI system produces harmful or incorrect output?
- What contractual protections are provided?
- What incident notification obligations apply?
Contracts should address data use, confidentiality, privacy, security, audit rights, subcontractors, model training, retention, deletion, incident notification and exit arrangements.
9. Train staff and leaders
AI governance will fail if people do not understand the risks and expected behaviours.
Training should be tailored to different audiences. General staff need practical guidance on safe AI use. Executives and directors need to understand accountability, risk appetite and oversight. Developers need guidance on AI-assisted coding and secure development. Procurement teams need to understand AI vendor risk. HR, legal, finance, customer service and marketing teams each need training relevant to their use of AI.
Training should cover:
- what AI is and how it is commonly used;
- the limitations of AI, including hallucinations and bias;
- what data can and cannot be entered into AI tools;
- how to verify AI-generated outputs;
- when to disclose AI use;
- copyright and confidentiality risks;
- how to report concerns or incidents;
- where to find approved tools and guidance.
The goal is not to scare people away from AI. The goal is to help them use it safely and effectively.
10. Monitor, report and improve
AI governance is not a one-off project. AI tools, regulations, risks and business uses are changing quickly.
Organisations should monitor AI use and report regularly to management or the board. Useful measures include:
- number of AI use cases identified;
- number of approved AI tools;
- number of high-risk AI use cases;
- completion of AI impact assessments;
- AI-related incidents or near misses;
- staff training completion;
- vendor reviews completed;
- unresolved risks or exceptions;
- data loss prevention alerts involving AI tools;
- assurance or audit findings.
The AI governance framework should be reviewed regularly and improved as the organisation learns more.
A practical roadmap for getting started
For an organisation with no AI governance in place, a practical roadmap could look like this.
First 30 days: stabilise and discover
Appoint an executive owner, form an AI governance working group, issue interim rules for AI use, launch an AI discovery process, create an initial AI inventory and communicate clear data handling expectations to staff.
Days 31 to 60: design the framework
Develop the AI acceptable use policy, define risk categories, create an AI impact assessment template, establish approval pathways, update procurement requirements and agree on reporting to senior leadership.
Days 61 to 90: implement priority controls
Approve business AI tools, implement data and access controls, assess the highest-risk AI use cases, update vendor risk processes, deliver targeted training and add AI to incident response procedures.
Months 4 to 6: embed into business-as-usual
Integrate AI governance into project delivery, procurement, privacy, cyber security, risk management and internal audit processes. Begin regular reporting and control testing.
Months 6 to 12: mature and assure
Review the effectiveness of controls, test high-risk AI systems, conduct assurance activities, refine the AI risk appetite and mature the governance framework in line with recognised standards such as the NIST AI Risk Management Framework and ISO/IEC 42001.
Final thought
AI can create significant value, but unmanaged AI can also create serious risk.
The organisations that will benefit most from AI are not those that allow uncontrolled experimentation, nor those that block AI completely. They are the organisations that create clear rules, understand their risks, support safe innovation and put practical controls around how AI is used.
The best way to approach AI governance from scratch is to start simple:
- assign accountability;
- find out where AI is being used;
- set clear rules;
- assess risk before deployment;
- protect sensitive data;
- require human oversight where it matters;
- manage vendors;
- train staff;
- monitor what is happening;
- improve over time.
AI governance is not about slowing the organisation down. Done well, it gives leaders, staff, customers and stakeholders the confidence to use AI responsibly.