Skip to content
AIRAS Cloud

Resource

What is AI governance?

AI governance is the operating discipline that determines how an organisation identifies, assesses, controls, approves, monitors and evidences its use of artificial intelligence.

A working definition

AI governance is the set of accountable decisions, controls and records that determine whether a given use of artificial intelligence is permitted, on what conditions, under whose ownership and with what oversight.

That definition is deliberately operational. Governance is not a statement of values, an ethics charter or a training module. It is the mechanism by which a specific system, model, agent or vendor feature is registered, assessed against consistent criteria, given controls and owners, reviewed independently, decided by an accountable person, monitored in production and reassessed when something material changes.

AI policy is not AI governance

Most organisations already have an AI policy. Very few can answer the questions that follow from it: how many AI systems are in use, who owns each one, which were assessed, under what criteria, by whom, when, and where the evidence sits.

Policy expresses intent. Governance is what happens at the operational layer, and it is that layer where failures are found — in the gap between what the policy says and what can be produced when someone asks.

The eight capabilities that make it real

  • Inventory: one authoritative register of AI systems, models, agents and vendor features
  • Intake: structured, adaptive capture of purpose, data, autonomy and affected populations
  • Assessment: deterministic scoring against versioned, human-approved criteria
  • Controls: applicable obligations derived from assessed context, with owners and dates
  • Evidence: artefacts attached, hashed and visibly complete or incomplete
  • Review and decision: independent review, segregation of duties, attributable approval
  • Monitoring: signals, incidents, drift and material-change detection
  • Reassessment and audit: periodic re-review and an append-only, exportable record

Who is accountable

Effective governance names people, not committees. Each registered AI entry needs a business owner accountable for its use, a technical owner accountable for its behaviour, and a reviewer who is independent of both and authorised to approve, approve with conditions, or refuse.

Segregation of duties is the control that makes the rest credible. If the person who assessed the risk is also the person who approved it, the record proves process was followed but not that judgement was independent.

Why AI must not approve AI

Using a language model to score or approve AI risk introduces variance into the exact place that requires reproducibility. Two identical submissions can produce different outcomes, and the reasoning cannot be reliably reconstructed months later.

Deterministic, rule-based assessment solves this: the same inputs always produce the same score, the same band and the same explanation trace, against a ruleset version that is itself under change control. AI can assist with drafting and summarising; it must not hold the decision.

How to start

Begin with the register. An incomplete inventory makes every downstream activity approximate. Capture what is in use — including embedded vendor AI — then assess the highest-exposure entries first under a single published rulebook, and let the evidence accumulate from real work rather than from a documentation exercise.

See operational AI governance working

A forty-five minute executive briefing covering your AI estate, your obligations and what a governed operating model would look like.

No pricing commitment. No confidential information required.