Practical guide

Bring the right participants

Governance crosses functions. Include leadership, policy, privacy, legal, security, procurement, HR, information management, technology and operational owners as appropriate.

Classify AI uses

Separate low-risk assistance, internal productivity, sensitive information, external service, automation and high-impact decisions. Different uses need different controls.

Define roles and accountability

Clarify who proposes, approves, configures, uses, verifies, monitors and can suspend an AI use. Human accountability should remain explicit.

Build procurement questions

Ask about data handling, retention, jurisdiction, model changes, access, evidence, testing, security, accessibility, intellectual property and exit arrangements.

Document decisions and evidence

Create records of use cases, assessments, approvals, policies, incidents, monitoring and review. Governance should support learning rather than becoming a one-time document exercise.

Leave with an action plan

Capture owners, policy priorities, pilot gates, training needs, unresolved questions and the next governance milestone.

Important: This guide provides general implementation information. Formal legal, privacy, security, research-ethics, procurement or regulatory advice should come from the appropriate qualified professionals.