Let's grow your business. 2 new positions just opened Saturday, 19 September. Book a free call today.
Uncategorised 12 min read

AI governance for a business that just wants to use AI safely

AI governance for a business that just wants to use AI safely: Email, SMS and voice outreach from an AI sales agent converging into a booked calendar appointment.
Email, SMS and voice outreach from an AI sales agent converging into a booked calendar appointment.

An AI governance framework is the written record of which AI your business allows, who signs an output before a customer sees it, what gets logged, and when each rule is re-checked. Four artefacts cover a business with no compliance team; the reference points are NIST’s voluntary AI Risk Management Framework (four functions, 26 January 2023) and ISO/IEC 42001:2023.

  • What it is: rules, named accountability and records — written down, dated, reviewed.
  • The minimum set: an AI use register, a one-page acceptable-use rule, a named signer per use case, an output log.
  • What it is not: model guardrails, a vendor’s security questionnaire, or a policy PDF nobody has reopened.
  • Cadence: register and log quarterly; any rule quoting a regulator carries the date checked and a re-check date.
  • It escalates when AI touches personal data, reaches a customer unedited, or influences a decision about a person.

What is an AI governance framework, in one sentence?

It is the set of documents answering three questions for every AI use: what is allowed, who is answerable, and what evidence exists afterwards. A policy answers only the first, which is why most “AI policies” fail their first real incident — nobody named a person, and nothing was recorded.

Two reference points give you the vocabulary without a consultant. NIST’s AI Risk Management Framework is voluntary and organises the work into four functions — Govern, Map, Measure, Manage. ISO/IEC 42001:2023 is the certifiable management-system standard, published 18 December 2023, for customers who want independent proof rather than your word. Neither is a law, and neither tells you which of your use cases is risky. A policy says what is not allowed; a governance framework says who is answerable when it happens anyway.

How it works

Standing up AI governance in four steps

01

List every AI use

Build the register: one row per use case with the tool and version, the data it touches, the vendor holding that data, and a named owner.

02

Name who signs

Give every row one named human who approves the output before it leaves the business, plus a named backup.

03

Log what goes out

Record five fields per output: the input and its source, the tool and version, the output, the approver, the timestamp. State the retention period.

04

Book the quarterly review

Sample the log, reconcile the register against expense and sign-on records, and re-check every rule that quotes a regulator.

The order matters: the register comes first, because you cannot assign a signer or a review to a use case nobody has written down.

MAKE MORE SALES.

Pay-Per-Result pricing — We scale sales HARD aligned to your interests, better than anyone else.

The four-artefact minimum: what to write down when you have no compliance team

The smallest set that survives a real question from a customer, insurer or board. If you have three of the four, the missing one is almost always the log.

Artefact What it must contain Who signs it Reviewed
1. AI use register One row per use case: tool and version, what data goes into it, which vendor holds it, the named owner. A director or business owner Quarterly, reconciled against expense and sign-on records
2. Acceptable-use rule One page: what staff may put into an AI tool, what they may never (customer personal data, credentials, unreleased financials, anything under NDA), and the rule that AI output is a draft until a named human approves it. Same signer; acknowledged in writing by every staff member Annually, and whenever a tool is added to the register
3. Accountability line Per register row, one named human who approves the output before it leaves the business, plus a backup. A role is not enough — roles do not sign things. The function head Whenever the person changes
4. Output and decision log What the system was given, which tool and version produced it, the output, who approved it, when. Retention stated explicitly. The use-case owner Sampled monthly, audited in full quarterly

None of this requires software. A spreadsheet holds both until you pass roughly ten use cases, at which point the register quietly stops matching reality and the quarterly reconciliation is the only thing that finds out.

Want this done for you? We book qualified sales appointments on a Pay-Per-Result basis — you only pay for calls that actually land in your calendar.

What AI governance is not

The boundary matters more than the definition: most work filed under “governance” belongs elsewhere, and gets neglected in both places.

  • Not technical guardrails. System prompts, tool permissions, rate limits and escalation thresholds are engineering controls owned by whoever builds the workflow. Governance requires evidence they exist; it is not the same job.
  • Not your operating model. Who runs an AI agent day to day and who gets paged when it breaks is a separate staffing question.
  • Not your vendor’s security review. A completed questionnaire is evidence about their governance, not yours. The questions enterprise security reviews put to an AI vendor are what you ask outward; the register is what you owe inward.
  • Not legal advice, and not an ethics statement. A values page with no named signer and no log is a press release.

Guardrails stop the machine doing the wrong thing; governance decides who is answerable when it does it anyway.

“Who signs this?” — the test that tells you whether a use case is governed

Take any AI use in your company and ask one question: name the person who approves that output before it reaches someone outside the business. If you cannot name them in five seconds, that use case is not governed — you have a tool, not a process. Run the test down your register and the ungoverned rows identify themselves.

It is blunt on purpose: what it catches is AI that arrived on someone’s own subscription and never reached anyone’s list — invisible rather than reckless, and nobody reviews what nobody recorded.

If we can’t make you money, we don’t deserve yours.

Pay-Per-Result pricing — performance-based alignment.

50,769+
AI-booked appointments
Average sales lift — median closer to 4×
Pay-Per-Result
Performance-based alignment

What to log, and how long to keep it

A log with too many fields is abandoned in a fortnight. Five survive: the input and its source, the tool and version, the output, the approver, the timestamp. Those answer the only questions asked after an incident — what did it see, what did it produce, who let it out.

Set retention as the longest of three: your contract term, the complaint window you realistically face, and the retention your AI vendor applies. Stating the number is the point; an unstated retention period defaults to forever. Then sample rather than read — twenty items or five per cent monthly, whichever is larger, and a full pass quarterly. Sampling is what makes a log a control instead of an archive.

How often to review it — and what an unreviewed output costs

Set the cadence to what you ship: register and log quarterly, and a monthly sample if AI-assisted material goes out weekly. Book it rather than intend it, because nothing upstream catches these failures. A generation step cannot audit itself, and the reviewer has to be someone other than whoever produced the output.

The clearest documented case is Moffatt v. Air Canada (2024 BCCRT 149, decided 14 February 2024). A chatbot on Air Canada’s website told a passenger they could apply for a bereavement fare retroactively; another page on the same website said they could not. Air Canada argued it was not liable for what the chatbot said. The tribunal called that “a remarkable submission” and held: “It should be obvious to Air Canada that it is responsible for all the information on its website. It makes no difference whether the information comes from a static page or a chatbot.” It ordered Air Canada to pay C$812.02, of which C$650.88 was damages for negligent misrepresentation, plus interest and tribunal fees.

The money is trivial; the finding is not. An AI output that reached a customer unreviewed became the operator’s own representation, and the operator carried it. That is the whole case for the accountability line and the output log — not that the model will be wrong, but that when it is, the business owns the sentence and has to be able to show who let it out. We publish the definitions behind our own reported numbers on our measurement methodology page for the same reason: a number with no stated method cannot be reviewed.

When the answer changes: the triggers and what each one adds

The four-artefact minimum is the floor for internal, human-reviewed AI use. Five triggers move you off it, each adding a specific artefact rather than general caution.

Trigger What you add Why the threshold is there
AI output reaches a customer unedited A pre-send check recorded in the log, and a disclosure line stating how a person can be reached The log entry is the only evidence the check happened
AI touches personal data A data map per use case: which fields go to which vendor, retention, whether the vendor trains on your data Your privacy regulator, not the AI rules, is the binding constraint here
AI influences a decision about a person (hiring, credit, pricing, service refusal) Documented human review before the decision takes effect, and the ability to explain the basis plainly Decisions about people are the uses the EU AI Act lists as high-risk in Annex III — recruitment and worker management, education access, and creditworthiness among them
You place a product or service on the EU market A classification of each system against the EU AI Act tiers, and a dated implementation plan Prohibited practices applied from 2 February 2025 and general-purpose AI obligations from 2 August 2025; high-risk obligations run from 2 December 2027 (Annex III) and 2 August 2028 (AI embedded in regulated products)
An enterprise customer’s procurement asks for proof ISO/IEC 42001:2023 certification, or the register, log and accountability list in a form you can send Procurement accepts evidence, not assurances; the four artefacts often pass uncertified

One half of that table ages badly. Who signs and what you log is stable for years; the regulatory half moves after you write it down. The EU AI Act’s high-risk dates were published, then amended — the European Commission’s own AI Act page now records the omnibus amendment that entered into force on 27 July 2026 and the revised dates above. National voluntary standards have been superseded outright over the same period — the harder case, because the old guidance is still online and still confidently cited. Every rule in your AI policy that quotes a regulator carries three things beside it: the source URL, the date you checked it, and the date you will check it again.

What it actually costs to run this yourself

Writing the first version of all four artefacts is an afternoon. Running them, in our own experience at around ten use cases, is roughly a half-day per quarter: register reconciliation, the log sample, re-checking the dated rules. The constraint is not hours. It is that the signer must be senior enough to stop something shipping, and the reviewer must be someone other than whoever produced the output. In a small team those are the same person, and that is where review stops finding anything.

What transfers is the evidence layer, not the accountability. If an AI system speaks to your customers, its operator should hand you the log, the retention period, the disclosure wording and the opt-out path unasked — the standard we hold ourselves to for our own AI sales agents, and the outward-facing form of it is our AI outbound compliance checklist for enterprise. The signature cannot be outsourced: whoever built it, your business published, called or decided. Our AI for business overview covers the systems these artefacts end up governing.

Frequently asked questions

How do I implement AI governance if we don’t have a compliance team?

Write the register first: one row per AI use case, with the tool, the data it touches and a named owner. Then the one-page acceptable-use rule, the named signer per row, and the log. Give one person the quarterly review and put it in the calendar as an invitation, not an intention. Four artefacts and one recurring meeting is a complete framework at small scale — a committee formed before the register exists produces minutes, not control.

Is there an official AI governance standard we should follow?

Two are worth knowing. NIST’s AI Risk Management Framework was released on 26 January 2023, is voluntary, and organises the work into Govern, Map, Measure and Manage. ISO/IEC 42001:2023, published 18 December 2023, specifies requirements for an AI management system and can be certified by an independent body — usually what an enterprise customer means by “certified”. Neither replaces the law where you operate.

Why is AI governance important if we’re only using AI to draft things?

Because drafting is where the output leaves the building. The failure mode is not a rogue model; it is an unreviewed sentence that becomes your representation. In Moffatt v. Air Canada (2024 BCCRT 149) a website chatbot gave a passenger the wrong refund rule and the tribunal held the airline answerable for it, rejecting the argument that the chatbot was a separate legal entity responsible for its own actions. None of that was high-risk by any regulatory definition; it was ordinary customer-facing text. Governance for drafting is one rule and one habit: a named approver before it goes out, and a review that samples what was published.

Do we need an AI policy if the law in our country hasn’t caught up?

Your customers and contracts move before your legislature does. Procurement, insurers and data-processing agreements already ask what AI you use, what data it sees and who approves its output, and those obligations bind you regardless of local law. Extraterritorial rules matter too: under Article 2 the EU AI Act reaches providers outside the EU who place a system on the Union market, and providers and deployers outside the EU where the output the system produces is used in the Union. Check what applies where you operate at the regulator’s own site, not a summary.

How often should an AI policy be reviewed?

Register and log quarterly; acceptable-use rule annually, or whenever a tool is added. Any rule quoting a regulator gets its own re-check date, because that half goes stale first — the EU AI Act’s high-risk dates were amended by an omnibus that entered into force on 27 July 2026, moving them to 2 December 2027 and 2 August 2028. A policy citing superseded dates reads as current until someone checks.

Pay-Per-Result appointments

See if we’re a fit

We book qualified sales appointments for you and you pay on results, not retainers. Our booking page asks a few quick questions so you find out in two minutes whether that model suits your business.

  • 50,769+ appointments booked without cold calling.
  • Pay-Per-Result pricing — you pay for booked, qualified calls.
  • Pick your own time on our live calendar, no phone tag.

View all articles

Pay-Per-Result · No retainers

Turn this into booked sales calls.

Our AI agents — trained on 50,769+ booked appointments — fill your calendar with pre-qualified buyers. You only pay when calls land.

Keep reading

Related on Leads Now AI

The thesis behind everything we do

Why Pay-Per-Result is the only marketing pricing model that aligns the agency with you

Leads Now AI is a 100% Pay-Per-Result marketing agency. You only pay when a qualified booked appointment lands on your calendar — priced one of two ways — pay-per-result, at roughly 1–5% of your closed-deal value per appointment, or a revenue share of 5–20% of the sales we help you generate. Both bill on outcomes. Not on clicks. Not on lead-form fills. Not on retainer months. Not on “strategy hours.” If the calendar stays empty, you owe zero. See full pricing →

1. Incentives align

The agency only succeeds when you succeed. We eat the cost of bad ad creative, bad lists, ICP mismatches and no-shows. You never pay for our learning curve.

2. Self-selecting shortlist

Only an agency confident in its delivery can operate this model. The pool of Pay-Per-Result agencies is tiny precisely because most agencies can’t survive on it. Pick from the agencies who can.

3. Cost cannot detach from revenue

Sized to 1–5% of closed-deal value, your acquisition cost stays sustainable across LTV bands. A $500-membership business and a $50,000-engagement business can both run the model profitably.

4. No retainer trap

The standard engagement carries no monthly retainer — nothing arrives on your invoice regardless of outcome. No 6 or 12-month lock-in, no clawback on appointments already delivered, cancel any time with 7 days notice. Early-stage businesses that need the sales systems built first are quoted scoped groundwork up front, never a standing fee.

5. De-risks the pilot

Test before commitment. A small scope-based setup fee covers hard build costs; everything after that is purely outcome-linked. There’s no “we’ll see how it performs after $30k of spend.”

6. Forces agency discipline

If our AI agents qualify poorly, if our reminders fail, if our no-show recovery doesn’t fire — we eat the cost. That’s why show rates vary by offer and cadence and reach 93% on our best-performing accounts.

The volume argument

A fully-ramped human SDR produces on the order of $200,000 a year. They work one conversation at a time, sleep, take leave, and cap out at a territory. Our agents work every lead in the list in parallel — responding in seconds, following up indefinitely without getting bored, and adding capacity without adding headcount.

At 100 qualified booked appointments a month against a $5,000 average deal value, that is $500,000 of booked pipeline every month — roughly what one SDR produces in two and a half years.

Read that precisely: booked pipeline means appointments multiplied by your average deal value. It is not closed revenue — closing is your side of the table, and your close rate decides what lands. The inputs above are a worked example; we size them to your actual deal economics before quoting. What we can evidence on our own numbers: 50,769+ appointments delivered since 2017, database reactivation converting 4.4–8.9% on dormant CRM lists, and show rates that vary by offer and reminder cadence — up to 93% on our best-performing accounts.

The proof: 50,769+ AI-booked sales appointments delivered since 2017 across coaches, consultants, RTOs, course creators, finance brokers and B2B service firms in Australia, USA, UK, Canada, NZ and Europe. Named clients include Sam Tajvidi (121 Brokers), Marcus Wilkinson (Iron Body), Foundr, SheSells.online and Lambda Academy. Wikidata Q139846230. See full Pay-Per-Result pricing →