Practical AI governance

AI governance framework checklist for business

A framework becomes useful when a manager and a member of staff can both tell what is allowed, who decides and what evidence must be retained.

Written and reviewed by Jon Goodey. Updated 20 August 2026.

The short answer

An effective AI governance framework covers use-case approval, data classification, tool and supplier controls, accountable owners, human review, evaluation, record keeping, incidents, training and scheduled reassessment.

Working method

Govern the use case through its full life

Approve the purpose, set the boundary, review the real output and keep monitoring as the tool and work change. 01 Approve 02 Control 03 Review 04 Monitor evidence review
Approve the purpose, set the boundary, review the real output and keep monitoring as the tool and work change.

1. Define purpose and risk

  • Record the business purpose, intended users and affected people.
  • Describe the decision or output AI will influence.
  • Rate the consequence of an inaccurate, biased, confidential or unavailable output.
  • Identify whether a simpler non-AI process could meet the need.
  • Name the accountable business owner.

2. Control data and sources

  • Classify the input as public, internal, confidential, personal or regulated.
  • State which data must never be entered into an unapproved tool.
  • Confirm the lawful and contractual basis for processing personal or client data.
  • Record where source material came from and who may update it.
  • Set retention, deletion and access rules for inputs, outputs and logs.

3. Approve tools and suppliers

  • Use an organisational account when administration, access and data terms matter.
  • Check the current contract, product surface, hosting route and retention controls.
  • Review connected apps because they introduce another supplier and data flow.
  • Record model or product changes that could alter performance or handling.
  • Define who can approve a new tool, connector or automation.

4. Design human review

“A human checks it” is not enough. Define who checks, what they compare, what evidence they need and what happens when they are uncertain.

RiskProportionate reviewRecord
Low-impact draftingUser reads and edits before useFinal approved content where normally retained
Client or public factual outputNamed reviewer checks sources and claimsSources, reviewer and approval
Material decision supportQualified owner reviews evidence and alternativesDecision, rationale, exceptions and escalation
High-impact or regulated useFormal legal, risk and technical assuranceFull assessment, testing and monitoring trail

5. Evaluate before adoption

  • Create representative test cases, including difficult and prohibited examples.
  • Set the quality threshold and failure conditions before the pilot result is seen.
  • Compare with the current human or non-AI method.
  • Test for unsupported claims, missing evidence, inconsistency and harmful bias.
  • Record whether the pilot should stop, change, continue or scale.

6. Document operation and ownership

  • Maintain an AI use-case register with status, owner and review date.
  • Document the workflow, prompts or instructions, sources, version and human checkpoints.
  • Train users on both the expected method and the prohibited shortcuts.
  • Set access removal and handover procedures.
  • Keep a contact route for questions and suspected incidents.

7. Prepare for failure and change

  • Define how a user reports an incorrect, unsafe or confidential output.
  • Identify who can pause the workflow or revoke access.
  • Record affected people, data and downstream systems.
  • Review the incident, correct the process and communicate where required.
  • Re-test after material tool, model, source or workflow changes.

A minimum viable framework for a smaller organisation

If a full programme would prevent any progress, begin with five controls: an approved-tool list, a prohibited-data rule, a use-case owner, mandatory review before external use and a simple register with the next review date. Add more assurance as the consequence and scale increase.

Read the companion guide to AI governance for small and growing businesses, or use an AI adoption programme to connect governance with a controlled first workflow.

Questions people ask

What is an AI governance framework?

An AI governance framework defines how an organisation approves AI uses, controls data, assigns accountability, reviews outputs, records decisions and responds when something goes wrong.

Does a small business need AI governance?

Yes, but the framework should be proportionate. A small organisation may begin with approved tools, prohibited data, named owners, mandatory human review and a simple use-case register.

Who should own AI governance?

Executive accountability should be clear, but operation is usually shared across the business owner, information security or privacy, legal or compliance, IT and the teams using the system.

Is an AI policy the same as AI governance?

No. A policy states rules. Governance includes the process, owners, evidence, review, monitoring and escalation that make those rules operational.

How often should an AI governance framework be reviewed?

Review it when tools, data, regulation or use cases change, and on a defined regular cycle. High-impact uses should be reviewed more frequently than low-risk drafting support.

Jon Goodey discussing practical AI work with a team

A practical first conversation

Bring the work that is causing the problem.

Tell us what the team is trying to improve, what it has already tested and where confidence breaks down. We will suggest a proportionate next step.

Talk it through with Jon