The minimum viable framework
| Visibility | One maintained AI system inventory, including embedded and supplier AI. |
|---|---|
| Accountability | A named executive sponsor, system owner, risk approver and control owners. |
| Decisions | Recorded scope, role, risk, data, transparency and human-oversight decisions. |
| Controls | Risk-tiered approval, testing, monitoring, incident response and change control. |
| Evidence | Versioned records showing who decided what, when, on what basis and with what result. |
| Review | Monthly operating review and quarterly board-level trend reporting. |
A practical example
Customer-support copilot: the inventory names the product owner and supplier; the risk record explains why the use is not high-risk; the control set prohibits automated account decisions, requires human approval for refunds and logs model/version changes. Monthly sampling records whether the controls worked. That connected trail is governance evidence.
What boards and buyers should be able to see
- Which AI systems are operating, who owns them and where they affect people.
- Which systems are prohibited, high-risk, transparency-relevant or otherwise material.
- Whether testing, human oversight and incident controls are operating as designed.
- Which suppliers have unresolved evidence gaps or material model changes.
- Trends in incidents, exceptions, overdue reviews and staff AI-literacy coverage.
Use the AI governance metrics guide and roles and RACI guide to make reporting operational.
A 90-day operating rhythm
- Days 1–30: establish the inventory, accountable owner, policy baseline and risk triage.
- Days 31–60: assign controls, supplier evidence requirements and approval routes.
- Days 61–90: test control operation, review exceptions and issue the first management report.
ISO/IEC 42001 can provide a management-system structure, while the NIST AI RMF provides a useful risk vocabulary. Neither removes the need to design controls around actual systems and uses.
Frequently asked questions
What is AI governance?
It is the accountable operating system used to direct, control and evidence an organisation’s AI use.
What should the framework contain?
An inventory, roles, risk decisions, approval rules, policies, operational controls, incidents, supplier oversight, metrics and review.
Can a small business keep it proportionate?
Yes. Start with one owner, one inventory, risk-tiered approval, a usable AI policy and a monthly evidence review.
How do you prove it works?
Keep system-level decisions, approvals, tests, disclosures, incidents, supplier checks, training and control-review records.
Turn the framework into buyer-ready evidence
Start with the free exposure check, or use the Full Assessment to identify gaps across governance, EU AI Act readiness and procurement evidence.
Related guidance
Sources
Last reviewed 14 August 2026. General information, not legal advice.