AI governance: from the context of a use to a recorded decision
AI governance is the set of roles, criteria, controls and records that lets an organisation know where artificial intelligence is used, which risks and obligations each use carries, and who decided what. It applies both to organisations that build models and to those that adopt third-party AI tools. In practice it starts with an inventory of uses and ends in documented, reviewable decisions.
What AI governance has to answer
A governance structure exists to answer concrete questions at any moment, without depending on one person's memory.
- Which AI uses exist today, with purpose and accountable owner.
- Which data each use involves and who is affected by it.
- Which internal, contractual and regulatory obligations apply to that use.
- Which risks were identified and which controls answer them.
- Which evidence supports each control, and when it was last updated.
- Who authorised, restricted or ended the use, and on what basis.
Why an isolated inventory is not governance
Most organisations start with a spreadsheet of AI systems. The inventory is necessary, but if it is not linked to risks, controls, evidence and decisions it ages quickly and cannot support an answer to an auditor, a customer or a regulator.
What makes the information useful is the relationship between records: a use connected to the obligation that reaches it, the control that addresses it, the evidence that proves it and the decision that authorised it.
How to structure it in stages
A realistic sequence avoids programmes that stall at diagnosis.
- Inventory the AI uses that already exist, including third-party tools.
- Name accountable owners per use, not only a central committee.
- Map the obligations that apply, from contracts to regulation.
- Assess risk with criteria defined before the urgent case appears.
- Apply proportional controls with owners and deadlines.
- Record evidence and decisions with a review date.
Frequently asked questions
Who is responsible for AI governance?
Accountability sits with the business area that owns the use, supported by legal, security, technology and leadership. Governance defines the criteria and keeps the record; it does not replace the owner of the decision.
Does AI governance apply if we only use third-party tools?
Yes. Adopting a contracted AI tool creates the same duties around purpose, data, transparency and human oversight as building a model in house.
How is it different from data governance?
Data governance answers for the data itself. AI governance answers for the use: its purpose, the degree of automation in the decision, the people affected and the human oversight point.