Skip to content

Guide

AI governance: a practical guide

AI governance is how you keep the AI your business uses safe, compliant and accountable, without grinding to a halt. This guide walks the practical path, from finding your AI to running a management system aligned to ISO 42001 and the EU AI Act, with links to go deeper on each step.

What AI governance is

AI governance is knowing what AI your organisation uses, being able to show it is safe and compliant, and catching problems before they become incidents. It is the policies, roles, processes and records that keep your AI controlled and accountable. It does not have to be heavy: it scales to your size, from a light framework for a small deployment to a full management system for a regulated one.

What "governed" AI actually means

Why it matters now

AI arrived in tools you bought, tools your teams adopted on their own, and processes nobody formally signed off, and the obligations came with it. Regulators are applying existing law to AI now, the EU AI Act is phasing in, and procurement teams increasingly ask for ISO 42001 before they will sign. Getting governance right early is far cheaper than retrofitting it after an incident or a failed tender.

Shadow AI: finding the tools you don’t know you’re using

Step 1: find your AI

You cannot govern what you cannot see, and most AI exposure now lives in tools nobody signed off: personal accounts, AI features switched on inside SaaS you already own, note-takers, browser extensions. The first move is to find all of it, the shadow AI included, by asking, following the money and the data, and auditing the AI inside the tools you already run.

How to find your shadow AI

Step 2: build the register

Everything you find goes into a single, maintained AI system register: what each tool is, who owns it, what data it touches, its risk tier and status. It is the foundation the rest of governance sits on, and the thing both ISO 42001 and the EU AI Act assume you have.

The AI system register: what to actually track

Step 3: classify by risk

Not every system needs the same scrutiny. Classify each one by how much it could harm your business, customers or staff, and, where the EU AI Act applies, by its legal risk tier. The classification decides how much control each system gets, so effort goes where the risk actually is rather than drowning every tool in the same paperwork.

How to classify your AI systems by risk

Assess the impact on people

Classification tells you how risky a system is to you; an impact assessment asks the outward question, who could this harm and how badly, before it goes live. ISO 42001 requires one and ISO 42005 sets out how; for some deployers of high-risk AI the EU AI Act makes it law as a Fundamental Rights Impact Assessment. Run it as a real process with a named owner, not a form.

How to run an AI impact assessment

Step 4: run a management system

A working AI Management System (AIMS) pulls it together: an AI policy, named accountability, the register, risk classification, controls, human oversight, monitoring, and a standing evidence trail. ISO 42001 is the international standard that defines what one should contain. It is a system you run continuously, not a document you file.

What an AI Management System (AIMS) actually contains

Start with the AI policy

The AI policy is the top-level document the whole management system hangs off: your principles, who is accountable, what use is acceptable, what is prohibited, and how AI risk is handled. Under ISO 42001 it is mandatory and it anchors everything else. Written well it is short, owned, and built around data classification rather than a list of tool names.

How to write an AI policy (with a template)

ISO 42001, and whether you need it

ISO 42001 is the AI equivalent of ISO 27001 for information security: a certifiable standard for governing AI responsibly. You do not always need full certification, but the framework is the backbone of doing AI well, and it increasingly shows up as a procurement requirement. We are ISO 42001 Lead Implementer certified and build to it as standard.

Do you need ISO 42001? An honest answer

Governance and the EU AI Act

The EU AI Act is the law; ISO 42001 is the management system that makes complying with it practical and provable. Run a real governance system and you are doing most of what the Act asks, in a structure a regulator or customer recognises. The two are complementary, not alternatives.

ISO 42001 vs the EU AI Act

Governing the AI you buy

Most AI risk now comes from tools you bought, not models you built. Part of governance is evaluating vendors properly, what happens to your data, how it is secured, whether it locks you in, and whether it helps or hinders your own compliance, before a tool enters your systems.

How to evaluate an AI vendor

Prove it: AI assurance

Governance is running your AI well; assurance is proving it to others. As enterprise buyers and regulators start to vet the AI you sell, assurance, from impact assessments and audits to ISO 42001 certification, is what lets you answer "prove it" with evidence. A working management system is what makes you assurance-ready.

AI assurance: what it is, and how to get assurance-ready

How mature is your AI governance?

A free, self-serve check that reads your AI governance maturity against ISO 42001.

10 min No email
Take the check

AI governance: common questions

What is AI governance? +

AI governance is the set of policies, roles, processes and records an organisation uses to control its AI: knowing what AI is in use, being able to show it is safe and compliant, and catching problems before they become incidents. ISO 42001 is the international standard that defines what a full AI governance system should contain.

Do small businesses need AI governance? +

If you use or build AI in any way that touches customers, staff or decisions, then yes, but it does not have to be heavy. Governance scales to your size: a small deployment needs a light framework, not a committee. Increasingly it is also what customers, insurers and regulators expect to see, so getting it right early is cheaper than retrofitting it.

What is ISO 42001? +

ISO 42001 is the international standard for an AI Management System, the AI equivalent of ISO 27001 for information security. It sets out how to govern, monitor and improve your AI systems, and it is certifiable, so you can prove your approach rather than just assert it.

How do we start with AI governance? +

Start by finding all the AI you use (including shadow AI), putting it in a register, and classifying each system by risk. That closes the three biggest gaps, visibility, accountability and classification, and gives you something defensible to build on. Our free AI governance check gives you a maturity read in about ten minutes.

Going deeper on a specific area? See our ISO 42001 implementation guide, our AI assurance guide, or the EU AI Act guide.