A leadership team reviewing an AI governance framework and AI inventory on a shared screen
A leadership team reviewing an AI governance framework and AI inventory on a shared screen

What is AI governance?

Governance, risk and assurance

AI governance is the set of policies, roles, and routine checks an organisation uses to decide how it builds, buys, and uses artificial intelligence, and to keep that use safe, lawful, and aligned with its values. It is the system that answers a few simple questions clearly: who may use which AI tools, for what, with what data, under whose sign-off, and how problems are caught and fixed. Done well, it is proportionate to your size and risk, not a heavy bureaucracy that only large enterprises can carry.

Reviewed by Jackie, Head of Learning & Development, Levellers - Last reviewed 8 June 2026

What this means

AI governance is how an organisation stays in control of the artificial intelligence it uses. In everyday terms, it is the answer to a handful of practical questions. What AI are we actually using, including the tools staff have adopted on their own? Who is allowed to use it, and for what? What data can go into it? Who decides before a new use goes live? And how do we know if something goes wrong, and who fixes it? When those questions have clear, written answers that people actually follow, you have AI governance. When they do not, you have AI use without oversight, which is where most of the trouble starts.

A useful mental model is to think of governance as the steering and braking system for AI in your organisation, not the engine. The engine is the technology and the value it creates. Governance is what lets you go faster with confidence, because you can see where you are going and stop if you need to. It is not there to slow you down for its own sake. It is there so that speed does not turn into harm, legal exposure, or lost trust.

It helps to separate AI governance from two things it is often confused with. The first is general corporate governance, which is the broad framework of board oversight, accountability, and controls that keeps a whole organisation honest and well run. AI governance sits inside that framework as a specialist branch, in the same way that financial controls or health and safety do. It applies the same instincts, clear ownership and proportionate checks, to the specific risks that AI brings.

The second, and more important, distinction is between AI governance and data governance. Data governance is about the raw material. It answers the question, can we use this data, by managing its quality, where it came from, who can access it, and whether using it is lawful. AI governance is about what gets built and decided on top of that data. It answers a different question, can we trust how this system behaves, by managing risks such as biased decisions, models that drift and become less accurate over time, systems no one can explain, and automated decisions that affect real people. The two overlap and depend on each other. You cannot govern AI well on top of ungoverned data. But strong data governance on its own does not address bias, explainability, or the behaviour of a model in use, so it is necessary but not sufficient. This boundary is still being worked out in practice, and reasonable people draw the line in slightly different places, so it is worth being explicit about what your own organisation means by each term.

The umbrella idea is the one to hold onto. AI governance is not a single document or a piece of software. It is the connective tissue that links your AI strategy, your policies, your risk management, your assurance and testing activity, and your alignment to external frameworks into one coherent way of working. The rest of this article shows how those pieces fit together and what a sensible version looks like for a normal organisation.

Why it matters

The honest case for AI governance is not fear. It is that AI is now woven into ordinary work, often faster than leaders realise, and ungoverned use carries costs that fall on the organisation rather than the individual using the tool. In 2025, 81 percent of organisations reported that their employees were using AI, while only 28 percent had a formal AI policy. That gap is the risk in a single statistic. People are getting value from these tools every day, and at the same time they are making quiet decisions about what data to paste in and what answers to trust, with no shared rules to guide them.

The most immediate exposure is data. Staff routinely share confidential or personal information with free AI tools that may use it to train their models or store it outside your control. Roughly half of employees admit to using AI tools their employer has not approved, a pattern now common enough to have its own name, shadow AI. Each of those interactions can breach confidentiality, contracts, or data protection law, and you cannot manage a risk you cannot see.

Then there is the risk of the AI being wrong in ways that matter. AI systems can produce confident, fluent answers that are simply false, and they can reproduce bias from the data they learned from. The most cited cautionary tale is Amazon, which spent years building an experimental recruiting tool and then scrapped it after discovering that it penalised CVs containing the word "women's" and did not rate candidates in a gender-neutral way. The lesson is not that AI is dangerous in the abstract. It is that without checks, a system can quietly produce unfair or inaccurate results at scale, and the organisation owns the consequences.

Regulation is the third reason, and it is no longer hypothetical. In the European Union, the AI Act carries penalties of up to 35 million euros or 7 percent of global annual turnover for the most serious breaches, and it reaches any organisation whose AI affects people in the EU, wherever that organisation is based. In the United Kingdom, existing law already applies to AI: data protection rules govern how personal data is used in AI systems, and there is no special exemption for AI. Markets have noticed. The share of S&P 500 companies disclosing AI as a material risk in their annual filings reached 72 percent in 2025, up from just 12 percent in 2023.

Trust and procurement turn governance from a defensive cost into a commercial asset. Buyers, partners, and insurers increasingly ask how you manage AI before they will work with you, and being able to answer well shortens sales cycles and protects your reputation. A whole market of AI assurance services now exists precisely because customers want evidence rather than promises. In the United Kingdom alone, an estimated 524 firms supply AI assurance goods and services, generating around 1.01 billion pounds in value and employing more than 12,500 people, with the potential to exceed 6.53 billion pounds by 2035.

All of this has to be balanced against proportionality, which is the single most important idea in this whole field. A two-person consultancy using a mainstream chatbot to draft emails does not need the same governance as a lender using AI to decide who gets credit. Good governance scales to the size of the organisation and the seriousness of the use. The point is not to do everything. It is to do the right amount, deliberately, rather than nothing by accident.

How it works

AI governance works by turning good intentions into a small number of repeatable habits: knowing what you have, deciding who owns it, writing down the rules, sorting uses by risk, putting proportionate checks in place, and reviewing all of it on a sensible rhythm. The major external frameworks exist to help you do this consistently and to prove you have done it. This section walks through what governance covers, the components that make it work, who is accountable, how the main frameworks fit together, the lifecycle that keeps it current, and how all of it scales by organisation size.

What AI governance covers

The scope of AI governance is broader than most people first assume. It covers AI you build, AI you buy, and AI that arrives inside software you already use, such as a new assistant feature bolted onto a tool your team has had for years. It covers the whole life of a system, from the first idea and the data that feeds it, through testing and launch, into everyday use, monitoring, and eventual retirement. And it covers the people and processes around the technology, not just the technology itself, because most AI problems are really problems of unclear responsibility, poor data, or missing checks rather than faulty code.

Crucially, governance covers internal use as well as customer-facing products. The chatbot your marketing team uses to draft copy, the model your operations team uses to forecast demand, and the screening tool your recruiters use all sit within scope. A common and costly mistake is to govern only the AI that customers see while leaving internal use, where much of the data risk actually lives, completely unmanaged.

The core components

A working governance setup has a recognisable set of parts, and they are the same whether you are small or large. The detail changes with scale; the parts do not.

The first is an AI inventory, sometimes called an AI register. This is simply a living list of the AI systems and tools in use across the organisation, what each is used for, what data it touches, and who is responsible for it. Everything else depends on this. You cannot set rules, assess risk, or respond to incidents for systems you have not catalogued, which is why building and maintaining the inventory is consistently the hardest and most valuable part of the work.

The second is policy. An AI policy is a short, readable document that sets out what people can and cannot do with AI: which tools are approved, what data must never be entered, when human review is required, and where to go with questions. It translates principles into everyday rules. A policy that no one reads or understands is worse than useless, so plain language matters more than length.

The third is risk assessment and classification. This is the discipline of sorting AI uses by how much they matter, so that a low-stakes use such as summarising public documents is waved through, while a high-stakes use such as influencing decisions about people gets proper scrutiny. Risk classification is what makes proportionality real rather than rhetorical.

The fourth is controls and guardrails. These are the practical safeguards you put around a use: requiring a person to check important outputs before they are acted on, restricting which data can be used, logging what the system does so you can investigate later, and disclosing to people when they are dealing with AI. Keeping a meaningful person in the loop on consequential decisions is one of the most important controls, because it preserves the ability to catch and override a bad answer.

The fifth is assurance, which means building confidence that a system actually meets the standards you have set by measuring, evaluating, and communicating the results. Assurance includes activities such as impact assessments, bias testing, performance checks, and, for some organisations, independent audit. How assurance and audit relate is still an evolving area: audit tends to imply a formal, often independent check against a defined standard, while assurance is the broader family of techniques for generating justified confidence, of which audit is one. It is fair to say the profession is still maturing and the vocabulary is not yet fully settled.

The sixth is monitoring and incident response. AI systems change as the world around them changes, so governance includes watching live systems for drift and failure, giving people a clear way to report problems, and having a plan for what to do when something goes wrong.

Roles and accountability

Governance fails most often not because the rules are wrong but because no one owns them. The fix is to name a single accountable person for AI governance, someone senior enough to make decisions and resource the work. In a large organisation this might be a chief risk, data, or technology officer, or a dedicated committee. In a small one it may be a director or owner who simply adds it to their remit. The title matters far less than the clarity.

Around that owner sit a few clear responsibilities. Someone approves new high-stakes uses. Someone maintains the inventory. The people who actually use AI day to day carry responsibility for following the policy and flagging concerns. And where AI touches personal data, the people responsible for data protection are involved, because the two areas overlap heavily. Accountability also has to extend to suppliers. When you buy AI from a vendor, you are still responsible to your own customers and regulators for how it behaves, so contracts and due diligence need to make clear who is responsible for what.

The major frameworks and how they fit together

Several international frameworks now exist to help organisations govern AI. They are not competitors so much as different tools for different jobs, and a sensible organisation borrows from them rather than treating any one as gospel. Understanding what each is for saves a great deal of confusion.

The OECD AI Principles are the foundation layer. Adopted in 2019 and updated in May 2024, they are the first intergovernmental standard on AI and are now backed by 47 adherents. They set out five values-based principles, covering inclusive growth and sustainable development, human-centred values and fairness, transparency and explainability, robustness and security and safety, and accountability. They are high level and non-binding, but they matter because they are the shared vocabulary that most national rules and other frameworks build on. The 2024 update added emphasis on generative AI, safety, information integrity, and managing misinformation amplified by AI.

The NIST AI Risk Management Framework is the practical playbook for managing risk. Released by the United States National Institute of Standards and Technology in January 2023, it is voluntary, non-sector-specific, and designed to work for organisations of any size. Its core is four functions: Govern, which runs across everything and sets culture, accountability, and policy; Map, which works out the context and what could go wrong; Measure, which tests and tracks the risks; and Manage, which acts on them and keeps watch after launch. It deliberately offers no single checklist or scoring system, and its companion Playbook states plainly that it is neither a checklist nor an ordered list of steps, which makes it flexible but means you have to adapt it to your situation. A profile for generative AI adds further practical detail.

ISO/IEC 42001 is the certifiable management system standard. Published in December 2023, it is the world's first international standard for an artificial intelligence management system, and it is the one a third party can formally certify you against. It is built on the familiar Plan-Do-Check-Act improvement cycle and the same high-level structure as other management standards such as the well-known information security standard, which makes it easier to bolt onto systems you may already run. Its requirements sit in clauses 4 to 10, covering context, leadership, planning, support, operation, performance evaluation, and improvement, and it offers a reference set of 38 controls in Annex A across nine areas, from AI policy to data, from the system lifecycle to relationships with suppliers. You choose which controls apply through a risk assessment and record your reasoning in a document called a Statement of Applicability. Because it is certifiable, it is the framework that most directly produces the evidence that customers and procurement teams increasingly ask for.

The EU AI Act is the binding law. It is the world's first comprehensive AI statute, it entered into force on 1 August 2024, and it sorts AI into four risk tiers. A small number of practices are banned outright as unacceptable. A defined set of high-risk uses, such as AI in recruitment, credit scoring, and certain essential services, face strict obligations including risk management, data governance, documentation, human oversight, and conformity assessment. Limited-risk uses, such as chatbots, carry transparency duties so people know they are dealing with AI. Everything else is minimal risk and largely unregulated, which the European Commission estimates covers the large majority of AI systems on the market. Penalties are severe, reaching up to 35 million euros or 7 percent of global annual turnover for breaching the bans, with lower tiers of up to 15 million euros or 3 percent for most other breaches. The timeline is the part to watch carefully, because it is in flux. Under the original law, the main high-risk obligations were due to apply from 2 August 2026. A package of amendments known as the Digital Omnibus reached a provisional political agreement on 7 May 2026 that revises several of these dates: the use-based high-risk obligations in Annex III move to 2 December 2027, the obligations for high-risk AI embedded in regulated products in Annex I move to 2 August 2028, and the transparency and content-labelling duties move to 2 December 2026. These revised dates are provisional and depend on formal adoption by the European Parliament and Council and publication in the Official Journal. Until that happens, the original date of 2 August 2026 technically still stands, so any plan should treat the new dates as the likely direction of travel rather than settled law.

The UK approach is the lighter-touch, principles-based alternative. The United Kingdom has deliberately chosen not to pass a single AI law. Instead, its 2023 pro-innovation white paper set out five cross-sector principles, namely safety and security and robustness, appropriate transparency and explainability, fairness, accountability and governance, and contestability and redress, and asked existing regulators to apply them within their own areas. These principles are not statutory. The data protection regulator has been the most active, with detailed guidance on AI and data protection and a strategy focused on preventing harm while promoting trust, and reform of UK data law through the Data (Use and Access) Act 2025 has changed the rules on automated decision-making. The government has continued down the sectoral path rather than legislating broadly, opening a call for evidence in October 2025 on an AI Growth Lab that would let regulators relax specific rules under licence for supervised trials. A dedicated AI bill has been expected for some time but, as of mid-2026, none has been introduced. Notably, the government also stepped back from a self-assessment tool it had consulted on, AI Management Essentials, deciding in early 2026 not to publish it or build it into public sector buying, and instead to develop simpler guidance aimed at smaller firms.

How they fit together is the practical question. Think of the OECD principles as the shared values, the NIST framework as the method for managing risk, ISO/IEC 42001 as the management system you can be certified against, the EU AI Act as the law you must obey if you touch the EU market, and the UK principles as the regulatory backdrop for UK operations. They are broadly consistent because they all grew from the same ideas, and the sensible move is to adopt one as your backbone, usually NIST for method or ISO for certification, and use it to meet whatever legal duties apply to you. You do not need all five. You need a coherent spine that satisfies your obligations and your customers.

The governance lifecycle and review cadences

AI governance is a cycle, not a project with an end date, because the technology, your uses of it, and the rules around it all keep changing. A practical rhythm has a few fixed points. New uses are assessed and signed off before they go live, with the depth of that check scaled to the risk. Live systems are monitored continuously for the highest-risk uses and reviewed periodically for the rest. The inventory is kept current as tools are added and dropped, ideally as part of normal procurement and onboarding rather than as a separate chore. The policy itself is revisited on a regular schedule, perhaps annually, and whenever something significant changes, such as a major new regulation taking effect or a new class of tool entering the business. And incidents, near misses, and complaints feed back into the rules so that governance learns from experience rather than repeating mistakes.

Proportionality by organisation size

The same components apply at every size, but their weight differs enormously, and pretending otherwise is how governance gets a bad name. For a small organisation, proportionate governance can be genuinely light: a one-page policy, a shared spreadsheet as the inventory, a single named owner, a simple rule that anything affecting customers or staff decisions gets a second human look, and a short quarterly conversation to review it. That is real governance, and it is enough for most low-risk use. The evidence suggests smaller firms lag badly here. An AI policy is in place at around 55 percent of small companies, against roughly 80 percent of larger ones, only about 36 percent of small firms have a clear governance owner, against 62 to 64 percent of larger firms, and just 14 percent report familiarity with the major frameworks. That is a gap worth closing precisely because it is cheap to close.

For a mid-sized organisation, the same parts become a little more formal: a proper policy, a maintained register, a small cross-functional group that meets regularly, defined sign-off for higher-risk uses, and some structured testing. For a large or highly regulated organisation, or one whose AI directly affects people's rights or safety, governance becomes a full management system, quite possibly certified to ISO/IEC 42001, with dedicated roles, formal assurance, and audit. The trap to avoid in both directions is mismatch: a heavy process around trivial uses wastes effort and breeds resentment, while a light touch on a high-stakes use is where real harm happens. Proportionality means matching the effort to the stakes, deliberately.

Examples

Governance becomes concrete in the small moments of organisational life. Consider four ordinary situations.

A team wants to start using a new AI tool. Someone has found a clever assistant that summarises meetings, and they want to roll it out. Under proportionate governance, this does not require a committee. It requires a quick pass through a few questions: what data will it see, is that data sensitive or personal, does the vendor train on our inputs, and who signs off. If the answers are benign, it is approved, added to the inventory, and a line in the policy tells everyone how to use it safely. If the answers raise flags, for instance if the tool would ingest client confidential material, it goes to the accountable owner for a closer look before anyone uses it. The whole point is that the path exists and is fast, so people use it rather than going around it.

An AI feature is added to a customer process. Suppose a company adds an AI chatbot to its website to answer customer questions. Governance here means deciding what the bot may and may not say, making sure customers are told they are speaking to AI, keeping a person available to take over difficult cases, logging conversations so problems can be reviewed, and checking periodically that the answers remain accurate. None of this is exotic. It is the same care any organisation would apply to a new customer-facing process, applied to a system that can produce unexpected answers on its own.

A high-stakes use needs real scrutiny. Now imagine the same company wants to use AI to help screen job applicants. This is a different order of risk, because it affects people's livelihoods, it is the kind of use regulators watch closely, and it is exactly where bias has caused real harm before. Proportionate governance treats it accordingly. A formal impact assessment is done before launch. The tool is tested for bias across different groups. A human makes the actual decisions rather than rubber-stamping the machine. Applicants are told AI is involved and can ask for a review. And the whole arrangement is documented, because if it is ever questioned, the organisation needs to show it acted responsibly. The contrast with the meeting-summary tool is the entire lesson: same organisation, wildly different governance, because the stakes are wildly different.

A small company runs a lightweight governance forum. A thirty-person business does not need a governance department. What it can do is hold a thirty-minute meeting once a quarter, involving the owner, someone from operations, and whoever knows most about the tools in use. They look at the inventory, note any new tools people have started using, talk through anything that worried them, and update the one-page policy if needed. That meeting, plus a clear named owner and a simple approval habit, is a complete and credible governance system for a business of that size. It costs almost nothing and it closes the dangerous gap between heavy AI use and no oversight.

Common misunderstandings

A handful of misreadings cause most of the resistance to AI governance, and each is worth correcting plainly.

Governance equals bureaucracy. This is the most common fear and the most misplaced. Bureaucracy is process for its own sake. Governance is the opposite: a deliberate decision about where to spend effort and where not to. A good governance system actually reduces friction, because it gives people clear permission to use approved tools confidently instead of guessing or hiding what they do. The bureaucracy people dread comes from getting it wrong, not from doing it at all.

Only big companies need it. The evidence points the other way. Small organisations are more exposed, not less, because they have the same access to powerful tools but fewer instincts and resources for managing the risks, and they are less likely to spot a problem before it bites. Proportionate governance for a small firm is genuinely small, but its absence is not safe, it is just invisible until something goes wrong.

It is the same as data protection. The two overlap heavily and data protection law is a major part of the picture, but they are not the same thing. Data protection asks whether you are handling personal data lawfully and fairly. AI governance asks a broader set of questions about how AI systems behave, including accuracy, bias, explainability, human oversight, and uses that involve no personal data at all. You need both, and treating AI governance as merely a data protection exercise leaves real risks unmanaged.

It is a one-off document. Writing a policy and filing it away is one of the most common failures. AI changes too fast for a static document to stay useful. Governance is a living habit of reviewing, updating, and learning, and the document is only the visible tip of it.

It blocks innovation. Sensible governance does the reverse. The organisations that move fastest and most safely with AI are usually the ones that know what they are using, trust their guardrails, and can therefore say yes quickly to new ideas because they have a clear way to assess them. The real brake on innovation is uncertainty and fear, and governance is how you remove it.

Risks and boundaries

It is just as important to be clear about what AI governance does not do. It is not a guarantee. A good governance system reduces the chance and the severity of harm, and it ensures that when something goes wrong you find out and respond well, but it cannot promise that AI will never make a mistake. Anyone selling certainty is overselling.

Governance also does not replace technical safeguards, good data, or competent people. It sits alongside them. A policy cannot fix a badly built model, and a register cannot make a poor decision good. Governance organises and oversees the work; it does not do the work itself.

There is genuine risk at both extremes. Under-governance is the obvious danger, and it is where most real harm occurs: data leaks, biased decisions, false information acted on, and regulatory breaches, all because no one was watching. But over-governance is a real failure too, and a more insidious one, because it looks responsible. Smothering low-risk uses in approvals and paperwork wastes money, frustrates good people, slows the organisation down, and, worst of all, pushes staff towards unapproved tools to get their work done, which recreates the very shadow AI problem governance is meant to solve. The aim is calibration, not maximum control.

Finally, a clear boundary on this article itself. This is general guidance to help a non-specialist understand and establish AI governance. It is not legal advice. The law in this area, especially the EU AI Act and UK data protection rules, is detailed, fast-moving, and dependent on your specific circumstances, and several important dates are currently provisional. For decisions with real legal or financial consequence, take professional advice that is current and specific to your situation.

What to do next

Establishing proportionate AI governance is a sequence, not a leap, and a normal organisation can make real progress in a few weeks. The steps below run in a deliberate order, because each one depends on the last.

Start with an inventory. Before anything else, find out what AI is actually in use, including the tools people have adopted quietly. Ask teams directly, look at what software you already pay for, and write it all down in a simple list with what each tool does and what data it touches. Expect surprises. You cannot govern what you cannot see, and this step alone often reveals the most urgent risks.

Name an owner. Assign one senior person clear accountability for AI governance. This is the decision that makes everything else stick, because it turns a good idea into someone's actual job. The person needs enough authority to set rules and enough access to leadership to escalate when needed.

Write a short, usable policy. Produce a plain-language document that says which tools are approved, what data must never be entered into AI, when a human must review, and where to take questions. Keep it short enough that people will read it and clear enough that they will follow it. A page or two beats a manual.

Classify uses by risk. Sort your inventory into tiers: low-stakes uses that can proceed freely, and higher-stakes uses, especially anything affecting decisions about people or involving sensitive data, that need proper scrutiny. This is what lets you concentrate effort where it counts and leave the rest light.

Put proportionate controls in place. For the higher-risk uses, add the safeguards that fit: human review of important outputs, restrictions on data, disclosure to affected people, logging, and testing for bias or accuracy. For low-risk uses, keep it light. Match the control to the stakes.

Set a review cadence. Decide how often you will revisit the inventory, the policy, and the live systems, and put those reviews in the calendar. For a small organisation, a short quarterly check plus an annual policy review is plenty. Build the inventory update into how you buy and adopt new tools so it stays current on its own.

Align to a framework. Once the basics are working, pick one external framework as your backbone to give your approach structure and credibility. The NIST AI Risk Management Framework is a strong, free starting point for method. If customers or regulators are asking for proof, ISO/IEC 42001 gives you something you can be certified against. If you touch the EU market, map your high-risk uses against the EU AI Act timeline now, treating the revised provisional dates as the likely shape of things while keeping an eye on formal adoption.

The benchmarks that should change your plan are straightforward. If your inventory turns up high-stakes uses you did not know about, raise the urgency and tighten controls immediately. If you operate in or sell into the EU and have any high-risk uses, formal compliance work cannot wait for the final dates. If customers begin asking for assurance or certification, move ISO/IEC 42001 up your list. And if you find staff routinely using unapproved tools, treat it as a signal that your approved options or your policy are not meeting real needs, and fix that rather than simply banning more.

Related: AI bias.

Related: a fundamental-rights impact assessment for AI.

Related: an AI approval workflow.

Related: AI procurement and contracting.

Related: an AI control library.

Related: an AI incident response plan.

Related: AI change control.

Related: an AI record-retention and evidence pack.

Have a question or a suggestion, or want to understand how we research and review these guides? Read about our editorial standards and how to reach us.

FAQs

What is AI governance in simple terms?

It is how an organisation stays in control of the AI it uses. It is the set of clear answers to practical questions: what AI are we using, who can use it and for what, what data can go into it, who signs off new uses, and how do we catch and fix problems. When those answers are written down and followed, you have AI governance.

Who is responsible for AI governance in an organisation?

One named senior person should be accountable, with enough authority to set rules and resource the work. In a large organisation this may be a chief risk, data, or technology officer, or a committee. In a small one it can be a director or owner. Everyone who uses AI shares responsibility for following the policy, and where personal data is involved, the people responsible for data protection are closely involved.

How is AI governance different from data governance?

Data governance manages the raw material and asks whether you can use a given set of data lawfully and well, covering quality, source, access, and security. AI governance manages what is built and decided on top of that data, and asks whether you can trust how a system behaves, covering bias, accuracy, explainability, human oversight, and automated decisions. You need both. Strong data governance is necessary for good AI governance but does not replace it.

Which AI governance framework should we use?

Pick one as your backbone rather than trying to use them all. The NIST AI Risk Management Framework is a free, flexible method for managing risk and a good starting point. ISO/IEC 42001 is the certifiable management system standard to choose if customers or regulators want proof. The OECD principles provide shared values, the EU AI Act is binding law if you touch the EU market, and the UK principles form the backdrop for UK operations. Use your chosen backbone to meet whatever legal duties apply to you.

Do small companies really need AI governance?

Yes, but in proportion. Small firms are often more exposed because they use powerful tools with fewer resources to manage the risks. Proportionate governance for a small business can be a one-page policy, a shared spreadsheet inventory, a single named owner, a simple rule that consequential uses get a human check, and a short quarterly review. That is genuine governance and enough for most low-risk use.

How does AI governance relate to the EU AI Act and ISO/IEC 42001?

The EU AI Act is a law you must obey if your AI affects people in the EU, and it sorts uses into risk tiers with strict duties for high-risk ones and heavy penalties for breaches. ISO/IEC 42001 is a voluntary management system standard you can be certified against. Good AI governance is the broader practice that helps you meet the Act's requirements and, if you choose, achieve certification. Several of the Act's high-risk deadlines were revised by a provisional agreement in May 2026 and are not yet finally adopted, so treat the new dates as the likely direction while watching for formal confirmation.

How do we actually start with AI governance?

Begin by building an inventory of the AI already in use, including tools staff have adopted on their own. Then name an accountable owner, write a short usable policy, sort uses by risk, put proportionate controls around the higher-risk ones, and set a regular review. Only once those basics work should you formally align to an external framework. The first step, finding out what you actually have, is the most important.

How do we measure whether our AI governance is working?

Look at a few practical signals rather than a single score. Is the inventory complete and current? Does every high-stakes use have a clear owner and documented checks? Are staff using approved tools rather than unapproved ones? Are incidents and near misses being reported and feeding back into the rules? Can you produce evidence quickly if a customer or regulator asks? Improvement on those questions over time is a better measure than any one number.

Sources