Practical guide
Bring the right participants
Governance crosses functions. Include leadership, policy, privacy, legal, security, procurement, HR, information management, technology and operational owners as appropriate.
Classify AI uses
Separate low-risk assistance, internal productivity, sensitive information, external service, automation and high-impact decisions. Different uses need different controls.
Define roles and accountability
Clarify who proposes, approves, configures, uses, verifies, monitors and can suspend an AI use. Human accountability should remain explicit.
Build procurement questions
Ask about data handling, retention, jurisdiction, model changes, access, evidence, testing, security, accessibility, intellectual property and exit arrangements.
Document decisions and evidence
Create records of use cases, assessments, approvals, policies, incidents, monitoring and review. Governance should support learning rather than becoming a one-time document exercise.
Leave with an action plan
Capture owners, policy priorities, pilot gates, training needs, unresolved questions and the next governance milestone.

