Skip to content

Glossary

AI governance

AI governance is how an organisation decides what AI it permits, who answers for each system, and how it knows what is in use, so those answers exist before anybody needs them.

In plain terms

Somebody decides what the company is willing to use, somebody owns each thing once it is in, and somebody can say what is running today. That is the whole of it. It sounds administrative and turns out to be the difference between answering a customer's due-diligence form in an afternoon and discovering that nobody knows which team wired an assistant into the support inbox.

01

Why it matters

Because the questions arrive whether or not the answers exist, and they arrive from directions that have nothing to do with regulation. A customer sends a questionnaire. An insurer asks what is automated. A board member reads something alarming and wants to know if it applies here. An organisation that has made these decisions answers in a day; one that has not spends a fortnight discovering what it is doing, and often finds more than it expected.

02

How it works

It is a set of decisions with names attached rather than a document, which is the distinction most often lost. A written policy states what the organisation intends. Governance is the arrangement that makes the intention true: who approves, who owns, who is told when something changes, and what happens when the answer is no. A policy with none of that behind it describes a company nobody works at.

Knowing what is actually in use comes first, and it is usually the uncomfortable part. Assistants arrive on individual subscriptions, features appear inside tools already bought, and an automation somebody built last quarter is quietly running every night. An inventory is simply the list of what exists, and the first honest one is nearly always longer than the people commissioning it expected.

Approval decides what gets in and on what basis. The useful version is proportionate: a drafting assistant used on public material is not the same decision as something reading customer records or acting without a person present. Treating those identically produces either a bottleneck nobody respects or a rubber stamp, and both end with the same outcome, which is that the process gets routed around.

Ownership after approval is the part most often skipped, and the part that decides whether any of this survives contact with a real year. Approval is a moment and ownership is a standing commitment: somebody whose job includes noticing that this system is still appropriate, still configured as agreed, and still worth what it costs. Systems without a named owner do not misbehave immediately; they drift, and nobody is watching the direction.

Evidence is what turns the arrangement into something a third party can rely on, and its shape has changed. The older pattern was a scramble before an audit, assembling screenshots of a state that may not have held all year. The pattern the compliance platforms now sell is continuous: connections into the systems themselves, so the evidence is collected as things happen rather than reconstructed afterwards.

Published frameworks give the arrangement a recognised shape, and their value is mostly that they are recognised. Two of the compliance platforms in this guide now list frameworks specific to AI alongside the general security ones, which is the clearest available sign that buyers ask about this in the same conversation as everything else. What a framework requires is its own subject and it changes; the durable part is a vocabulary your customer already knows.

Systems that act rather than answer are the hard case, and the one the arrangement is usually least ready for. A drafting assistant produces something a person reads before it goes anywhere. Something that resolves a customer's request end to end, or takes an action in another system, has no such pause in it by default. The support platforms selling this say plainly that outputs in regulated settings need human oversight and audit trails, which is a governance requirement stated as a product caveat.

The failure mode is governance that exists on paper, and it is common enough to be the default rather than the exception. The signs are consistent: a policy nobody can quote, an inventory that was accurate once, approvals granted by someone with no way to judge the request, and an owner who left. Each is individually forgivable and together they mean the honest answer to what is running here is that nobody knows.

The document and the arrangement

The document and the arrangementSetting the two side by side explains a conversation that recurs in almost every organisation approaching this for the first time. Someone asks whether the company has AI governance, and the honest answer given is yes, because a policy exists and was circulated. The policy is real and it is not the thing being asked about. What the questioner wants, whether they phrase it this way or not, is the right-hand column: can you tell me what is running, who answers for it, and how you know. Those cannot be written in advance because they describe a state of the world rather than an intention about it, and a state of the world has to be kept current or it silently stops being true. The practical consequence is that effort spent lengthening the policy has almost no effect on the answer, while effort spent on the inventory changes it immediately.What a policy statesWhat the organisation intends.Which uses are acceptable.What staff should not do.Written once, reviewedannually.What governance requiresA list of what is actuallyrunning.A named owner for each of them.A decision recorded, and bywhom.Evidence collected as ithappens.The left column can be producedin an afternoon and the rightcolumn cannot be produced atall, only maintained. Thatasymmetry is why so manyorganisations have the first andbelieve it is the second.
Setting the two side by side explains a conversation that recurs in almost every organisation approaching this for the first time. Someone asks whether the company has AI governance, and the honest answer given is yes, because a policy exists and was circulated. The policy is real and it is not the thing being asked about. What the questioner wants, whether they phrase it this way or not, is the right-hand column: can you tell me what is running, who answers for it, and how you know. Those cannot be written in advance because they describe a state of the world rather than an intention about it, and a state of the world has to be kept current or it silently stops being true. The practical consequence is that effort spent lengthening the policy has almost no effect on the answer, while effort spent on the inventory changes it immediately.
03

Seen in the wild

  • A compliance platform that collects evidence continuously from cloud, HR and identity systems, so the state of things is recorded as it happens rather than assembled before an audit.

    Vanta
  • A trust management platform that tests controls continuously and publishes the resulting posture through a trust centre, which is the outward-facing half of the same arrangement.

    Drata
  • An enterprise agent platform with governance and guardrails built in, whose own documentation says outputs in regulated settings need human oversight and audit trails.

    Sierra
04

Common misconceptions

People assume

This is a large-company concern.

In fact

The questions scale down long before the paperwork does. A small company selling to a large one inherits the large one's questionnaire, and answering it well is a commercial advantage rather than an overhead. What changes with size is the formality, not whether anybody asks.

People assume

We have a policy, so we have governance.

In fact

A policy is one artefact of it. Without an inventory the policy governs things nobody has listed, without owners it describes duties nobody holds, and without evidence it is an assertion. The document is the easiest part to produce and the least useful on its own, which is why it is so often the only part that exists.

People assume

A compliance platform provides it.

In fact

It automates the work around the arrangement, not the accountability. The vendors say so themselves: certifications still require an independent human auditor, drafted policies and questionnaire answers need review by someone qualified to stand behind them, and risk acceptance stays with the company. The tool makes an owned programme cheaper to run and does not supply the owner.

05

Telling them apart

AI governance vs AI policy

AI governance

The arrangement: inventory, approval, owners, evidence.

AI policy

The document stating what the organisation intends.

The policy is one output of the governance. A policy without the rest of it describes a company nobody works at.

06

Questions

Where does an organisation with none of this start?
With the inventory, because every other decision depends on knowing what exists. What is in use, who introduced it, what it touches. It is unglamorous and it is the only step that cannot be done out of order, since approving, owning and evidencing all presuppose a list of things to approve, own and evidence.
Who should own it?
Someone with the authority to say no and enough proximity to the work to know when saying no is wrong. It sits variously with security, legal, operations or a named executive, and the pattern that fails is the one where it belongs to a committee, because a committee can deliberate but cannot be accountable.
How is this different from the security review we already run?
Much of it is the same review, which is genuinely good news. The additions are about behaviour rather than architecture: what the system does on its own, what it was trained on, how its output is checked, and who is answerable when it is confidently wrong. Those questions do not have a natural home in a review designed around data and access.
Does a framework have to be adopted?
No, and adopting one is a decision about who you sell to rather than about being well run. The frameworks give a vocabulary customers already recognise, which shortens conversations and satisfies procurement. An organisation nobody is asking can be governed perfectly well without naming one.
What does it look like when it is working?
Someone can say what is running, who owns each thing, and what was decided about it, without a project to find out. That is the whole test, and it is more demanding than it sounds: most of the effort goes into keeping those three answers current rather than producing them once.
07

Key takeaways

  • An arrangement with names attached, and the policy is only one output of it.
  • Approval is a moment; ownership is the standing commitment that decides whether it lasts.
  • Evidence has moved from a pre-audit scramble to something collected continuously.
  • Platforms automate the work around it and never the accountability, which the vendors say plainly.
  • It is working when someone can say what runs, who owns it and what was decided, without a project.
09

Tools that use this

  • Vanta

    Continuous evidence collection across cloud, HR and identity systems.

  • Drata

    Continuous control testing, with the posture published through a trust centre.

  • Sierra

    Governance and guardrails built in, with human oversight named for regulated settings.

Last checked July 2026

All glossary terms