AI governance through roles, policies, human oversight, controls and monitoring

GOVERNANCE · STRATEGY

AI governance: how to organise responsibilities, controls and decisions around artificial intelligence

AI governance means defining who decides, which rules apply, which controls exist and how the use of artificial intelligence is overseen within an organisation.

It sounds straightforward. But as different teams begin using AI, reality quickly becomes more complicated.

Marketing tests a generative tool. Human Resources introduces a recruitment-support system. IT contracts a solution with AI components. A team starts using assistants without formal approval. Senior management then discovers that more AI systems are in use than anyone realised.

The problem is not necessarily that AI is being used. It begins when nobody is entirely sure who may authorise it, who assesses its risks, who must oversee it or what happens when something goes wrong.

That is where AI governance begins.

What governing AI really means

Governing artificial intelligence does not mean creating a department that has to approve every tool. Nor does it mean producing dozens of procedures.

It means establishing a framework that can answer consistently which AI systems are used, why they are used, who may approve a new use, which risks must be assessed, who owns each system, which decisions require human oversight, which controls and evidence are needed, what happens when an incident occurs and when the system must be reviewed again.

The difference lies in moving from isolated decisions to a common way of working. Governance exists when decisions have owners, criteria, controls and traceability.

Governance begins with knowing which AI we use

It is difficult to govern something we do not know exists.

That is why one of the first elements of any governance model should be an AI systems inventory.

It does not need to be sophisticated at first. It should, however, show which system is used, who uses it, for what purpose, which data and provider are involved, which processes or decisions it may affect, who owns it, its level of risk and when it must be reviewed.

The inventory turns a scattered reality into something visible. That visibility makes decision-making possible. Inventorying AI systems is therefore not merely an administrative task; it is part of governance.

Define who decides and who is accountable

One of the most common problems arises when everyone is involved but nobody is clearly accountable.

IT understands the technology. Legal understands the obligations. Compliance assesses conformity. Data Protection reviews relevant processing. Business teams understand the process. Security assesses threats. Senior management sets priorities.

All these perspectives may be necessary, but the organisation still needs to know who does what.

System owner

The person or function accountable for ensuring that the system has a clear purpose, is used appropriately and remains under control. This does not have to be the person who developed the technology.

Risk owner

The person or function that follows specific risks and checks that agreed measures remain in place. The risk owner may or may not also be the system owner.

Control functions

Legal, Compliance, Security, Data Protection and other functions may need to take part, depending on the system and its context.

User or operational team

The people who actually use AI within the process. Their involvement matters because many problems emerge during day-to-day use.

Senior management

Management should be involved when decisions exceed defined thresholds for risk, investment, impact or accountability. Not every system needs a large committee, but every system should have clear decision rights.

An AI policy as a common framework

An AI policy should not be a document that someone signs and then files away. It should answer questions people genuinely face: which tools may we use, may client information be entered into a generative AI system, who may purchase a new solution, which uses need prior review, which decisions cannot be fully delegated and what should happen when a problematic result is detected?

A sound policy establishes limits, responsibilities and principles, but it must also be practical enough to use when a real question arises.

The aim is not simply to say that the organisation will use AI responsibly. It is to turn that intention into concrete behaviour.

Human oversight: more than having someone review

Human oversight is sometimes treated as if placing a person at the end of the process were enough.

Effective oversight requires that the person can understand the system’s role, recognise a potentially problematic result, challenge or disregard it, intervene before a significant consequence occurs and record relevant decisions.

Consider a system that recommends candidates for a role. A person makes the final decision, but that alone does not create effective oversight. If they accept every recommendation without question, their presence adds little control.

The right question is whether that person genuinely has the authority, information and time to intervene. Governing AI means designing that oversight, not merely declaring it.

From risk to controls

AI governance and AI risk management are directly connected.

First, the organisation understands what may go wrong. It then decides what to do about it. That is where controls appear.

A control may be as simple as requiring human review before a particular decision, or it may involve technical validation, access restrictions, data review, performance testing, monitoring, bias analysis, supplier contracts, decision records, security controls and incident procedures.

The right control depends on the risk. A drafting assistant should not be governed in the same way as a system that influences recruitment, credit or access to services. Governance must be proportionate.

What an AI committee should review

Not every business needs a formal committee. Where several systems, business areas or significant decisions are involved, however, a shared governance forum may be useful.

Its purpose should be to make decisions rather than receive general updates. It may approve certain systems, review sensitive uses, accept residual risks, analyse incidents and indicators, decide exceptions, assign owners, prioritise actions and oversee improvement plans.

It should also be clear which decisions do not need to reach the committee. If every minor tool requires executive approval, governance is likely to obstruct normal use.

Practical thresholds can help: low risk may receive operational approval; medium risk may require additional review; and high risk may be escalated to control functions or the committee. The aim is to bring important decisions to the right level, not to add bureaucracy.

Suppliers and external tools

A significant share of the AI used by organisations is not developed internally. It is purchased, contracted or activated within tools already in use.

Before bringing in a solution, the organisation may need to understand which AI function it contains, which data it uses and where that data is processed, whether the supplier may reuse it, how the model can change, what information is available about its operation, which security arrangements exist, what happens after an incident and how responsibilities are allocated contractually.

A supplier may provide the technology, but the organisation must still understand how it uses that technology in its own context. Outsourcing technology does not outsource every responsibility.

Indicators, monitoring and evidence

A governance model does not end when a system is approved. The organisation must check that it continues to work as expected.

Useful indicators may include systems inventoried or awaiting assessment, open risks, pending controls, incidents, completed reviews, approved exceptions, completed training, systems without an owner and overdue assessments.

Not every indicator is necessary. The organisation should select those that genuinely support decisions.

Indicators should be supported by AI evidence. It is not enough to say that a system is supervised; the organisation should be able to show who reviewed it, when, what they found and what they decided. Evidence turns a statement into something verifiable.

AI governance and compliance

AI governance should not be designed only to comply with a standard, but a sound model makes compliance considerably easier.

ISO/IEC 42001 structures an AI management system around leadership, responsibilities, risk, controls, evaluation and improvement.

The EU AI Act also creates obligations that, particularly for certain high-risk AI systems, must be translated into real organisational processes.

Governance and compliance are connected, but they are not identical. Compliance asks which requirements must be met. Governance adds another question: how does the business organise itself to make those decisions consistently? That question remains relevant even when a particular legal obligation does not apply.

Practical workshop to define AI governance policies, roles, controls and monitoring

A proportionate governance model

A small business does not need to copy the governance model of a multinational. An organisation using three low-impact tools should not build the same structure as one operating dozens of systems in critical processes.

Maturity is not about having more documents. It is about ensuring that important decisions are genuinely under control.

Basic model

Suitable for organisations with few systems and limited risks.

  • Inventory
  • Basic AI policy
  • Assigned owners
  • Simple assessment
  • Approval criteria
  • Incident log

Intermediate model

Useful as the number of systems or teams involved increases.

  • Risk classification
  • Formal approval process
  • Control functions
  • Supplier governance
  • Indicators
  • Periodic reviews
  • Evidence register

Advanced model

Appropriate for organisations with significant, regulated or high-risk systems.

  • AI committee
  • Formalised responsibilities
  • System-specific controls
  • Continuous evaluation
  • Audit and metrics
  • Structured incident management
  • Integration with other management systems
  • Management review

Governing AI means being able to explain how decisions are made

An organisation with effective AI governance should be able to explain which systems it has, who owns them, why they are used, which risks they create, which controls have been applied, who may approve and supervise them, which evidence is retained, what happens when they change and what the organisation does when something goes wrong.

The answers do not all need to sit in one document, but they should exist.

Governing AI is not about attempting to control every algorithm. It is about creating the conditions in which people can make responsible decisions about them.

That may be one of the most important challenges of organisational AI: deciding not only which technology can be used, but how the organisation wants to use it.

Do you know how your organisation is governing AI?

The first step is to understand which systems you use, which risks exist and which control mechanisms are currently in place.

The Céntrika assessment provides an initial view of your organisation’s AI governance, risk and compliance position and helps identify where a deeper review would be useful.

Take the assessment →The assessment provides initial guidance and does not replace a specific evaluation.

You may also be interested in

AI systems inventory: the starting point many businesses overlook AI risk management: how to identify, assess and treat risks AI evidence: how to show that your organisation is doing things properly