1. Record the use and its owner

Create an inventory of AI uses, including purchased software with embedded AI features. Record the business purpose, users, data sources and outputs. Distinguish a tool that drafts internal notes from a system that influences decisions about people. The second may need substantially different scrutiny even if both rely on a language model.

Assign a business owner who understands the intended outcome and a technical owner who can change or pause the system. Identify the person responsible for privacy and security review. Document prohibited uses and a route for requesting an exception. A policy that says only “use AI responsibly” leaves employees without a practical way to decide what is allowed.

2. Use references for their intended purpose

The NIST AI Risk Management Framework describes the functions Govern, Map, Measure and Manage. It is a voluntary reference for addressing AI risks, not a product certification. ISO/IEC 42001 specifies requirements for an AI management system. These references can help organise responsibilities and records, but citing them does not establish that an organisation complies with them.

For UK personal data, consider the UK GDPR and Data Protection Act alongside guidance from the Information Commissioner’s Office. A data protection impact assessment may be required where processing is likely to result in high risk to individuals. Whether a particular project triggers legal duties depends on its facts. Seek qualified advice for legal conclusions, including projects affecting people beyond the UK.

3. Review the service, not only the supplier name

Ask how the particular service handles inputs, outputs, logs and support access. Establish whether submitted data is used for training, which settings affect that treatment and what the contract says. Review subprocessors, hosting locations, deletion arrangements and international transfers. A consumer product and a business API from the same supplier may have different terms.

Include technical controls in the review: authentication, role management, audit records and the ability to restrict integrations. Document dependencies on models and external tools. If a supplier changes a model or service behaviour, identify how the organisation will notice and respond. Supplier assurances should be supported by relevant documentation rather than copied into a policy as an unchecked general statement.

4. Require evidence before enabling a use

Define acceptable behaviour for the task and maintain evaluation examples. Include unsupported requests, sensitive information and plausible misuse. For systems that affect people, consider whether outcomes can disadvantage particular groups and how a meaningful review would identify that. Do not reduce the release decision to whether the application runs without technical errors.

Record the evaluated configuration, known limitations and the person authorising release. Ensure human reviewers have the information and authority to reject an output; a nominal approval click is not necessarily meaningful oversight. Keep permissions narrow and provide a rollback or pause route. Decide which changes require another review instead of assuming the initial approval covers every future configuration.

5. Keep controls active after deployment

Provide a clear reporting route for incorrect outputs, data exposure and unexpected actions. Decide who investigates, who can disable the system and how affected records will be corrected. Preserve relevant evidence with proportionate access and retention. An incident process should fit into the organisation’s existing security and privacy arrangements rather than creating an isolated AI-only channel.

A governance service can be scoped around an AI inventory, supplier questions, an acceptable-use policy, approval records and incident procedures. Agree whether the work covers policy drafting, technical implementation or both. This service does not replace legal advice, a security assessment or independent certification. Its practical purpose is to make responsibilities and operating decisions explicit.

Consult the primary sources: the NIST AI Risk Management Framework, ISO/IEC 42001 and ICO guidance on AI and data protection. Check applicable law with a qualified adviser before deploying a consequential use.

Discuss governance needs