AI governance

Before a policy or certification target, establish what AI is used, who owns it, and what decisions it shapes.

Find the systems actually in use

AI use rarely sits in one team. It may appear in customer products, employee tools, vendor platforms, security operations, marketing workflows, and automated decision support. A useful inventory records the system’s purpose, provider, users, data, outputs, integrations, and owner.

Include experiments and third-party features. A small internal tool can create meaningful exposure if it processes sensitive data or influences a consequential decision.

Assess risk in context

Risk depends on what a system does, who it affects, and how humans use its output. Consider data quality, privacy, security, explainability, bias, robustness, and the ability to contest or correct outcomes. The level of review should match the impact and the organization’s legal obligations.

For EU operations, assess applicable AI Act roles and obligations with qualified legal input. Regulatory milestones have evolved, so the inventory should carry the facts needed to reassess classification as rules and guidance develop.

Build an accountable lifecycle

ISO/IEC 42001 provides a management system approach to AI. That means setting objectives and policy, assigning roles, assessing impacts, controlling the lifecycle, monitoring performance, and improving the system. It is broader than a one-time model review.

Define checkpoints for procurement, design, testing, deployment, change, and retirement. Document why a system is used, what safeguards are applied, and who can stop or change it when performance or context shifts.

Make governance useful to product teams

Governance should help teams make decisions early, with clear escalation for higher-risk uses. A short intake, a risk tier, an owner, and a path to specialist review often create more reliable behavior than a lengthy policy no one can apply.

Put it into practice

  • Create an AI inventory across products, internal tools, and suppliers.
  • Record purpose, owner, data, outputs, users, and material impacts for each system.
  • Set review thresholds so higher-risk uses receive specialist input before deployment.
  • Reassess classifications and controls when a system or applicable rule changes.

Primary sources

Normstone resources are general information, not legal advice or an independent assessment.

All resources