What belongs in an AI governance framework?
A company's framework connects policy to everyday decisions across the AI lifecycle: selecting a tool, approving data access, testing a use case, releasing it, monitoring it, and retiring it. It applies to purchased AI tools as well as systems your team builds. The controls should reflect the use's impact on people, the sensitivity of its data, and the actions it can take.
Separate three decisions: whether the vendor is acceptable, whether a particular workflow is acceptable, and whether the people using it are prepared. Approval of a tool does not automatically approve every use of that tool.
This guide provides operational guidance, not legal advice. Ask qualified legal and privacy advisers to determine the laws, sector requirements, and contractual obligations that apply to your organisation and each use case.