An AI governance framework is the written record of which AI your business allows, who signs an output before a customer sees it, what gets logged, and when each rule is re-checked. Four artefacts cover a business with no compliance team; the reference points are NIST’s voluntary AI Risk Management Framework (four functions, 26 January 2023) and ISO/IEC 42001:2023.
- What it is: rules, named accountability and records — written down, dated, reviewed.
- The minimum set: an AI use register, a one-page acceptable-use rule, a named signer per use case, an output log.
- What it is not: model guardrails, a vendor’s security questionnaire, or a policy PDF nobody has reopened.
- Cadence: register and log quarterly; any rule quoting a regulator carries the date checked and a re-check date.
- It escalates when AI touches personal data, reaches a customer unedited, or influences a decision about a person.
What is an AI governance framework, in one sentence?
It is the set of documents answering three questions for every AI use: what is allowed, who is answerable, and what evidence exists afterwards. A policy answers only the first, which is why most “AI policies” fail their first real incident — nobody named a person, and nothing was recorded.
Two reference points give you the vocabulary without a consultant. NIST’s AI Risk Management Framework is voluntary and organises the work into four functions — Govern, Map, Measure, Manage. ISO/IEC 42001:2023 is the certifiable management-system standard, published 18 December 2023, for customers who want independent proof rather than your word. Neither is a law, and neither tells you which of your use cases is risky. A policy says what is not allowed; a governance framework says who is answerable when it happens anyway.
How it works
Standing up AI governance in four steps
List every AI use
Build the register: one row per use case with the tool and version, the data it touches, the vendor holding that data, and a named owner.
Name who signs
Give every row one named human who approves the output before it leaves the business, plus a named backup.
Log what goes out
Record five fields per output: the input and its source, the tool and version, the output, the approver, the timestamp. State the retention period.
Book the quarterly review
Sample the log, reconcile the register against expense and sign-on records, and re-check every rule that quotes a regulator.
MAKE MORE SALES.
Pay-Per-Result pricing — We scale sales HARD aligned to your interests, better than anyone else.
The four-artefact minimum: what to write down when you have no compliance team
The smallest set that survives a real question from a customer, insurer or board. If you have three of the four, the missing one is almost always the log.
| Artefact | What it must contain | Who signs it | Reviewed |
|---|---|---|---|
| 1. AI use register | One row per use case: tool and version, what data goes into it, which vendor holds it, the named owner. | A director or business owner | Quarterly, reconciled against expense and sign-on records |
| 2. Acceptable-use rule | One page: what staff may put into an AI tool, what they may never (customer personal data, credentials, unreleased financials, anything under NDA), and the rule that AI output is a draft until a named human approves it. | Same signer; acknowledged in writing by every staff member | Annually, and whenever a tool is added to the register |
| 3. Accountability line | Per register row, one named human who approves the output before it leaves the business, plus a backup. A role is not enough — roles do not sign things. | The function head | Whenever the person changes |
| 4. Output and decision log | What the system was given, which tool and version produced it, the output, who approved it, when. Retention stated explicitly. | The use-case owner | Sampled monthly, audited in full quarterly |
None of this requires software. A spreadsheet holds both until you pass roughly ten use cases, at which point the register quietly stops matching reality and the quarterly reconciliation is the only thing that finds out.
Want this done for you? We book qualified sales appointments on a Pay-Per-Result basis — you only pay for calls that actually land in your calendar.
What AI governance is not
The boundary matters more than the definition: most work filed under “governance” belongs elsewhere, and gets neglected in both places.
- Not technical guardrails. System prompts, tool permissions, rate limits and escalation thresholds are engineering controls owned by whoever builds the workflow. Governance requires evidence they exist; it is not the same job.
- Not your operating model. Who runs an AI agent day to day and who gets paged when it breaks is a separate staffing question.
- Not your vendor’s security review. A completed questionnaire is evidence about their governance, not yours. The questions enterprise security reviews put to an AI vendor are what you ask outward; the register is what you owe inward.
- Not legal advice, and not an ethics statement. A values page with no named signer and no log is a press release.
Guardrails stop the machine doing the wrong thing; governance decides who is answerable when it does it anyway.
“Who signs this?” — the test that tells you whether a use case is governed
Take any AI use in your company and ask one question: name the person who approves that output before it reaches someone outside the business. If you cannot name them in five seconds, that use case is not governed — you have a tool, not a process. Run the test down your register and the ungoverned rows identify themselves.
It is blunt on purpose: what it catches is AI that arrived on someone’s own subscription and never reached anyone’s list — invisible rather than reckless, and nobody reviews what nobody recorded.
If we can’t make you money, we don’t deserve yours.
Pay-Per-Result pricing — performance-based alignment.
What to log, and how long to keep it
A log with too many fields is abandoned in a fortnight. Five survive: the input and its source, the tool and version, the output, the approver, the timestamp. Those answer the only questions asked after an incident — what did it see, what did it produce, who let it out.
Set retention as the longest of three: your contract term, the complaint window you realistically face, and the retention your AI vendor applies. Stating the number is the point; an unstated retention period defaults to forever. Then sample rather than read — twenty items or five per cent monthly, whichever is larger, and a full pass quarterly. Sampling is what makes a log a control instead of an archive.
How often to review it — and what an unreviewed output costs
Set the cadence to what you ship: register and log quarterly, and a monthly sample if AI-assisted material goes out weekly. Book it rather than intend it, because nothing upstream catches these failures. A generation step cannot audit itself, and the reviewer has to be someone other than whoever produced the output.
The clearest documented case is Moffatt v. Air Canada (2024 BCCRT 149, decided 14 February 2024). A chatbot on Air Canada’s website told a passenger they could apply for a bereavement fare retroactively; another page on the same website said they could not. Air Canada argued it was not liable for what the chatbot said. The tribunal called that “a remarkable submission” and held: “It should be obvious to Air Canada that it is responsible for all the information on its website. It makes no difference whether the information comes from a static page or a chatbot.” It ordered Air Canada to pay C$812.02, of which C$650.88 was damages for negligent misrepresentation, plus interest and tribunal fees.
The money is trivial; the finding is not. An AI output that reached a customer unreviewed became the operator’s own representation, and the operator carried it. That is the whole case for the accountability line and the output log — not that the model will be wrong, but that when it is, the business owns the sentence and has to be able to show who let it out. We publish the definitions behind our own reported numbers on our measurement methodology page for the same reason: a number with no stated method cannot be reviewed.
When the answer changes: the triggers and what each one adds
The four-artefact minimum is the floor for internal, human-reviewed AI use. Five triggers move you off it, each adding a specific artefact rather than general caution.
| Trigger | What you add | Why the threshold is there |
|---|---|---|
| AI output reaches a customer unedited | A pre-send check recorded in the log, and a disclosure line stating how a person can be reached | The log entry is the only evidence the check happened |
| AI touches personal data | A data map per use case: which fields go to which vendor, retention, whether the vendor trains on your data | Your privacy regulator, not the AI rules, is the binding constraint here |
| AI influences a decision about a person (hiring, credit, pricing, service refusal) | Documented human review before the decision takes effect, and the ability to explain the basis plainly | Decisions about people are the uses the EU AI Act lists as high-risk in Annex III — recruitment and worker management, education access, and creditworthiness among them |
| You place a product or service on the EU market | A classification of each system against the EU AI Act tiers, and a dated implementation plan | Prohibited practices applied from 2 February 2025 and general-purpose AI obligations from 2 August 2025; high-risk obligations run from 2 December 2027 (Annex III) and 2 August 2028 (AI embedded in regulated products) |
| An enterprise customer’s procurement asks for proof | ISO/IEC 42001:2023 certification, or the register, log and accountability list in a form you can send | Procurement accepts evidence, not assurances; the four artefacts often pass uncertified |
One half of that table ages badly. Who signs and what you log is stable for years; the regulatory half moves after you write it down. The EU AI Act’s high-risk dates were published, then amended — the European Commission’s own AI Act page now records the omnibus amendment that entered into force on 27 July 2026 and the revised dates above. National voluntary standards have been superseded outright over the same period — the harder case, because the old guidance is still online and still confidently cited. Every rule in your AI policy that quotes a regulator carries three things beside it: the source URL, the date you checked it, and the date you will check it again.
What it actually costs to run this yourself
Writing the first version of all four artefacts is an afternoon. Running them, in our own experience at around ten use cases, is roughly a half-day per quarter: register reconciliation, the log sample, re-checking the dated rules. The constraint is not hours. It is that the signer must be senior enough to stop something shipping, and the reviewer must be someone other than whoever produced the output. In a small team those are the same person, and that is where review stops finding anything.
What transfers is the evidence layer, not the accountability. If an AI system speaks to your customers, its operator should hand you the log, the retention period, the disclosure wording and the opt-out path unasked — the standard we hold ourselves to for our own AI sales agents, and the outward-facing form of it is our AI outbound compliance checklist for enterprise. The signature cannot be outsourced: whoever built it, your business published, called or decided. Our AI for business overview covers the systems these artefacts end up governing.
Frequently asked questions
How do I implement AI governance if we don’t have a compliance team?
Write the register first: one row per AI use case, with the tool, the data it touches and a named owner. Then the one-page acceptable-use rule, the named signer per row, and the log. Give one person the quarterly review and put it in the calendar as an invitation, not an intention. Four artefacts and one recurring meeting is a complete framework at small scale — a committee formed before the register exists produces minutes, not control.
Is there an official AI governance standard we should follow?
Two are worth knowing. NIST’s AI Risk Management Framework was released on 26 January 2023, is voluntary, and organises the work into Govern, Map, Measure and Manage. ISO/IEC 42001:2023, published 18 December 2023, specifies requirements for an AI management system and can be certified by an independent body — usually what an enterprise customer means by “certified”. Neither replaces the law where you operate.
Why is AI governance important if we’re only using AI to draft things?
Because drafting is where the output leaves the building. The failure mode is not a rogue model; it is an unreviewed sentence that becomes your representation. In Moffatt v. Air Canada (2024 BCCRT 149) a website chatbot gave a passenger the wrong refund rule and the tribunal held the airline answerable for it, rejecting the argument that the chatbot was a separate legal entity responsible for its own actions. None of that was high-risk by any regulatory definition; it was ordinary customer-facing text. Governance for drafting is one rule and one habit: a named approver before it goes out, and a review that samples what was published.
Do we need an AI policy if the law in our country hasn’t caught up?
Your customers and contracts move before your legislature does. Procurement, insurers and data-processing agreements already ask what AI you use, what data it sees and who approves its output, and those obligations bind you regardless of local law. Extraterritorial rules matter too: under Article 2 the EU AI Act reaches providers outside the EU who place a system on the Union market, and providers and deployers outside the EU where the output the system produces is used in the Union. Check what applies where you operate at the regulator’s own site, not a summary.
How often should an AI policy be reviewed?
Register and log quarterly; acceptable-use rule annually, or whenever a tool is added. Any rule quoting a regulator gets its own re-check date, because that half goes stale first — the EU AI Act’s high-risk dates were amended by an omnibus that entered into force on 27 July 2026, moving them to 2 December 2027 and 2 August 2028. A policy citing superseded dates reads as current until someone checks.
Pay-Per-Result appointments
See if we’re a fit
We book qualified sales appointments for you and you pay on results, not retainers. Our booking page asks a few quick questions so you find out in two minutes whether that model suits your business.
- 50,769+ appointments booked without cold calling.
- Pay-Per-Result pricing — you pay for booked, qualified calls.
- Pick your own time on our live calendar, no phone tag.
