What is AI governance?
AI governance is how a business decides which AI tools it uses, for what and under which rules, and how it checks they're working as intended. For a smaller business, that means a named owner, a short policy, a list of where AI is used, a check before each new use and a regular review.
Why does AI governance matter for a smaller business?
AI tools are easy to start using and hard to keep track of. Without anyone in charge, staff pick their own tools and accounts, personal data goes where it shouldn't, and nobody can say what AI is doing in the business when a client, an insurer or the ICO, the UK's data protection regulator, asks.
What does the UK government expect?
The UK government chose not to create a new AI regulator. Its 2023 white paper set five principles for existing regulators to apply: safety, security and robustness; transparency and explainability; fairness; accountability and governance; and contestability and redress. Data protection law applies whenever AI uses personal data.
The ICO says people's data protection rights apply wherever personal data is used in an AI system, from the data that goes in to the outputs that come back.
A simple AI governance framework
A workable framework for a smaller business has six parts: one owner, a short AI policy, a register of where AI is used, a check before each new use, a named person checking outputs, and a review every six months. The table shows what each part involves and which free template covers it.
| Part | What it means | Template |
|---|---|---|
| An owner | One person accountable for how the business uses AI, with time to do it. | |
| An AI policy | Which tools staff can use, what never goes in and who checks the work. | AI policy template |
| A register of AI uses | A list of each tool, the job it does, who owns it and when it was approved. | |
| A check before each new use | What goes in, where it goes and which route to test, with a data protection impact assessment (DPIA) where personal data is involved. | DPIA template |
| A person checking outputs | A named reviewer for each use, so AI work is checked before it's relied on. | |
| A regular review | The register and policy reviewed every six months, or when tools change. | AI risk assessment |
How do you put AI governance in place?
Start with what's already happening: ask who uses AI and for what, and write it into a simple register. Name an owner, agree the policy, and run a check before anything new goes live. Then review the register and the policy every six months, or sooner if your tools change.
What should an AI register include?
For each use, record the tool and supplier, the job it does, who uses it, what information goes in, who checks the output, whether a DPIA or risk assessment was done, who approved it and when, and the next review date. A spreadsheet is enough to start with.
- The tool and the supplier
- The job it does, and who uses it
- What information goes in
- Who checks the output
- Whether a DPIA or risk assessment was done
- Who approved it, and when
- The next review date