Many organisations now have an AI policy. It usually sets out principles — fairness, transparency, accountability, human oversight — and asks staff to use AI responsibly. Ask the same organisation which AI systems it currently uses, who is accountable for each and what decisions they inform, and the answer is often that nobody knows.
A policy that cannot be applied to a specific system by a specific person is a statement of values. It may be a good one. It is not governance.
Start with the inventory
Governance begins with knowing what exists. An AI inventory lists every system that uses machine learning or generative AI in a way that affects the organisation's work: tools bought from vendors, AI features switched on inside existing software, models built in-house and the general-purpose assistants staff use for work.
For each entry, record at least:
- what it does and which process it sits in,
- the decision it informs or makes, and who is affected by that decision,
- a named owner accountable for its use,
- the data it uses, including whether personal or confidential data leaves the organisation,
- how its outputs are checked before anyone relies on them.
The inventory is usually the most revealing document a governance programme produces. Systems turn up that nobody approved, and systems thought to be minor turn out to sit inside consequential decisions.
Classify by consequence, not by technology
Not every use of AI needs the same controls. A tool that drafts internal meeting notes and a model that screens job applicants are both AI, and treating them identically either buries the first in process or under-controls the second.
Classify each system by the consequence of it being wrong: who could be harmed, how seriously, and how easily an error would be noticed and corrected. The major frameworks take the same approach. The EU AI Act sorts systems into risk categories, and the NIST AI Risk Management Framework and ISO/IEC 42001 both centre on assessing and treating risk in context. Whichever applies in a given jurisdiction, proportionality is the common thread.
Make human oversight real
"A human reviews the output" is the control most often written into AI policies and the one most often hollow in practice. Oversight is real only if the reviewer has the time to review, the information to judge whether the output is right and the authority to override it. A reviewer who approves hundreds of outputs an hour, or who cannot see why the system produced a result, is a signature rather than a control.
For higher-consequence systems, define what the reviewer checks, how long they should spend and what they do when they disagree. Then test it: take a sample of reviewed outputs and see whether the errors were caught.
Keep a decision record
When the organisation decides to adopt, restrict or retire an AI system, record the decision, the reasoning and the evidence considered. Regulators, auditors and affected people increasingly ask how a judgement was reached, and a record written at the time is far more credible than one reconstructed afterwards.
Where to begin
An organisation starting from a policy and little else should build the inventory first, classify what it finds by consequence, and put named owners and real review around the highest-consequence systems. The principles in the policy then have something to attach to. Until they do, the policy describes intentions rather than practice.
