Guide
AI governance: a practical guide
AI governance is how you keep the AI your business uses safe, compliant and accountable, without grinding to a halt. This guide walks the practical path, from finding your AI to running a management system aligned to ISO 42001 and the EU AI Act, with links to go deeper on each step.
What AI governance is
AI governance is knowing what AI your organisation uses, being able to show it is safe and compliant, and catching problems before they become incidents. It is the policies, roles, processes and records that keep your AI controlled and accountable. It does not have to be heavy: it scales to your size, from a light framework for a small deployment to a full management system for a regulated one.
What "governed" AI actually meansWhy it matters now
AI arrived in tools you bought, tools your teams adopted on their own, and processes nobody formally signed off, and the obligations came with it. Regulators are applying existing law to AI now, the EU AI Act is phasing in, and procurement teams increasingly ask for ISO 42001 before they will sign. Getting governance right early is far cheaper than retrofitting it after an incident or a failed tender.
Shadow AI: finding the tools you don’t know you’re usingStep 1: find your AI
You cannot govern what you cannot see, and most AI exposure now lives in tools nobody signed off: personal accounts, AI features switched on inside SaaS you already own, note-takers, browser extensions. The first move is to find all of it, the shadow AI included, by asking, following the money and the data, and auditing the AI inside the tools you already run.
How to find your shadow AIStep 2: build the register
Everything you find goes into a single, maintained AI system register: what each tool is, who owns it, what data it touches, its risk tier and status. It is the foundation the rest of governance sits on, and the thing both ISO 42001 and the EU AI Act assume you have.
The AI system register: what to actually trackStep 3: classify by risk
Not every system needs the same scrutiny. Classify each one by how much it could harm your business, customers or staff, and, where the EU AI Act applies, by its legal risk tier. The classification decides how much control each system gets, so effort goes where the risk actually is rather than drowning every tool in the same paperwork.
How to classify your AI systems by riskAssess the impact on people
Classification tells you how risky a system is to you; an impact assessment asks the outward question, who could this harm and how badly, before it goes live. ISO 42001 requires one and ISO 42005 sets out how; for some deployers of high-risk AI the EU AI Act makes it law as a Fundamental Rights Impact Assessment. Run it as a real process with a named owner, not a form.
How to run an AI impact assessmentStep 4: run a management system
A working AI Management System (AIMS) pulls it together: an AI policy, named accountability, the register, risk classification, controls, human oversight, monitoring, and a standing evidence trail. ISO 42001 is the international standard that defines what one should contain. It is a system you run continuously, not a document you file.
What an AI Management System (AIMS) actually containsStart with the AI policy
The AI policy is the top-level document the whole management system hangs off: your principles, who is accountable, what use is acceptable, what is prohibited, and how AI risk is handled. Under ISO 42001 it is mandatory and it anchors everything else. Written well it is short, owned, and built around data classification rather than a list of tool names.
How to write an AI policy (with a template)ISO 42001, and whether you need it
ISO 42001 is the AI equivalent of ISO 27001 for information security: a certifiable standard for governing AI responsibly. You do not always need full certification, but the framework is the backbone of doing AI well, and it increasingly shows up as a procurement requirement. We are ISO 42001 Lead Implementer certified and build to it as standard.
Do you need ISO 42001? An honest answerGovernance and the EU AI Act
The EU AI Act is the law; ISO 42001 is the management system that makes complying with it practical and provable. Run a real governance system and you are doing most of what the Act asks, in a structure a regulator or customer recognises. The two are complementary, not alternatives.
ISO 42001 vs the EU AI ActGoverning the AI you buy
Most AI risk now comes from tools you bought, not models you built. Part of governance is evaluating vendors properly, what happens to your data, how it is secured, whether it locks you in, and whether it helps or hinders your own compliance, before a tool enters your systems.
How to evaluate an AI vendorProve it: AI assurance
Governance is running your AI well; assurance is proving it to others. As enterprise buyers and regulators start to vet the AI you sell, assurance, from impact assessments and audits to ISO 42001 certification, is what lets you answer "prove it" with evidence. A working management system is what makes you assurance-ready.
AI assurance: what it is, and how to get assurance-readyHow mature is your AI governance?
A free, self-serve check that reads your AI governance maturity against ISO 42001.
AI governance: common questions
What is AI governance? +
AI governance is the set of policies, roles, processes and records an organisation uses to control its AI: knowing what AI is in use, being able to show it is safe and compliant, and catching problems before they become incidents. ISO 42001 is the international standard that defines what a full AI governance system should contain.
Do small businesses need AI governance? +
If you use or build AI in any way that touches customers, staff or decisions, then yes, but it does not have to be heavy. Governance scales to your size: a small deployment needs a light framework, not a committee. Increasingly it is also what customers, insurers and regulators expect to see, so getting it right early is cheaper than retrofitting it.
What is ISO 42001? +
ISO 42001 is the international standard for an AI Management System, the AI equivalent of ISO 27001 for information security. It sets out how to govern, monitor and improve your AI systems, and it is certifiable, so you can prove your approach rather than just assert it.
How do we start with AI governance? +
Start by finding all the AI you use (including shadow AI), putting it in a register, and classifying each system by risk. That closes the three biggest gaps, visibility, accountability and classification, and gives you something defensible to build on. Our free AI governance check gives you a maturity read in about ten minutes.
Going deeper on a specific area? See our ISO 42001 implementation guide, our AI assurance guide, or the EU AI Act guide.