The UK Corporate Governance Code never uses the word AI. The guidance written around it does, and so do a regulator's audit toolkit and two ISO standards.
AI Governance for a Business: What UK Governance Sources Ask of Boards and Senior Management
By James Cotton · Last updated · 9 min read
Part of our topic guides on AI Governance & Data Strategy and AI Skills for Business.
By James Cotton, Founder, iO-Sphere
The sources at a glance
| Source | Who it speaks to | On AI or technology risk, and its standing |
|---|---|---|
| UK Corporate Governance Code 2024 (FRC) | Boards of companies in two listing categories | Annual review of material controls; no mention of AI. Comply or explain |
| FRC Corporate Governance Code Guidance | The board | AI given as an example of a risk whose controls could be material. Not mandatory |
| FRC Guidance on the Strategic Report (February 2026) | Companies preparing a strategic report | As an example, should consider risks and opportunities from emerging technologies including AI. Guidance |
| AI audit toolkit, governance section (the Information Commission, formerly the ICO) | Senior management and compliance roles | Senior management sign-off of AI risks. "Ways to meet our expectations"; under review |
| Cyber Governance Code of Practice (April 2025) | Boards and directors | Board actions on cyber risk; one sentence on AI as a technology. Government code of practice |
| ISO/IEC 38507:2022 | Members of the governing body | Guidance on governing the use of AI |
| ISO/IEC 42001:2023 | Organisations of any size developing, providing or using AI | Requirements for an AI management system; certifiable by a UKAS-accredited body |
Every source on this page was read on 2 October 2026.
The Corporate Governance Code, and where the FRC names AI
The FRC's UK Corporate Governance Code 2024 "is applicable to all companies listed in the commercial companies category or the closed-ended investment funds category, whether incorporated in the UK or elsewhere". It works on a comply or explain basis and applies to accounting periods beginning on or after 1 January 2025.
Provision 28 says: "The board should carry out a robust assessment of the company's emerging and principal risks." Provision 29 asks the board to review the effectiveness of its risk management and internal control framework at least annually, covering "all material controls, including financial, operational, reporting and compliance controls."
That annual review existed under the 2018 Code. What is new is a "declaration of effectiveness of the material controls as at the balance sheet date" in the annual report. The revised Provision 29 applies for financial years beginning on or after 1 January 2026.
The Code itself does not use the words "artificial intelligence" or "AI". That wording sits in the FRC's Corporate Governance Code Guidance, published on 29 January 2024 and last updated on 3 June 2026, which says of itself that it "is not mandatory, and not part of the Code itself, and is not prescriptive."
In its section on material controls, the subject of Provision 29, the guidance leaves the choice to the board, weighing "how a deficiency in the control could impact the interests of the company, shareholders and other stakeholders." Material controls "could include" those over "information and technology risks including cybersecurity, data protection and new technologies (e.g. artificial intelligence)" (paragraphs 270 to 272).
Among its questions for boards on strategy is this: "Are we aware of emerging technologies (e.g. Responsible Artificial Intelligence) being used by the company, for example, in reporting?" A second asks: "Is our supply chain using emerging technologies and if so, how?" Neither is tied to a numbered provision.
The same guidance points to the Companies Act 2006 for directors' duties. Section 172 requires a director to act in the way they consider, in good faith, "would be most likely to promote the success of the company"; section 174, to "exercise reasonable care, skill and diligence". Neither section mentions AI, and the two AI passages in the FRC's Code guidance do not mention the Companies Act.
The FRC's Guidance on the Strategic Report (February 2026) turns to disclosure. It gives as an example that an entity "should consider the risks and opportunities arising from factors such as technological change, digital transformation and emerging technologies including artificial intelligence" and disclose material information about their effect on its future business model and strategy (paragraph 7.31).
The FRC's Provision 29 mythbuster on cyber, from September 2026, calls cyber security "a significant issue for companies, especially those who rely on digital systems and technologies, like AI", and says: "When considering material controls, it is likely that many companies will attribute one to cyber security." It says nothing equivalent about AI controls.
The Code does not apply to private companies. The FRC notes that large private companies in scope of the Companies (Miscellaneous Reporting) Regulations 2018 must disclose their governance arrangements. The Wates Corporate Governance Principles for Large Private Companies were first issued on 10 December 2018. Smaller companies have a guide of their own, as do regulated sectors, and UK laws on AI, with their dates, are in our guide to UK AI regulation in 2026.
What the AI audit toolkit looks for from senior management
The Information Commission (the ICO until 30 September 2026) has an AI toolkit within its data protection audit framework, whose governance section "is aimed at senior management and those in compliance-focused roles". The toolkit is under review following the Data (Use and Access) Act.
One control measure is "a documented and embedded privacy management framework endorsed by senior management that supports the AI system's development, use and oversight." Beneath it the regulator lists "ways to meet our expectations", not legal requirements. One is: "Evidence that senior management have seen and signed off the risks associated with using AI."
Elsewhere the section runs the same way: completed DPIAs go to senior management to "get sign off on the outcome of the assessment", AI risks are tracked "at a corporate level through an appropriate risk register", and audit findings are shared with senior management. An oversight committee appears only as an option to consider.
Another of those ways is: "Appoint a DPO, or a nominated data protection lead, with designated responsibility for overseeing AI systems." We train people taking on that responsibility on the Data & AI Governance apprenticeship (Level 4). How that lead relates to the board is set out role by role, and the governance lead's job has its own guide. Whether to grow that lead internally or recruit one is weighed in our build or buy guide.
The toolkit's scope is data protection: the control sits inside a privacy management framework, and the risk it names is a personal data breach.
The Cyber Governance Code, and the same pattern for AI
The Cyber Governance Code of Practice was published on 8 April 2025 by DSIT, the National Cyber Security Centre and DCMS. It exists "to support boards and directors in governing cyber security risks", is designed for medium and large organisations, and sets out "the most critical governance actions that directors are responsible for".
Its one sentence about AI as a technology says cyber resilience lets organisations "take full advantage of digital technologies, like artificial intelligence, to drive the business strategy and improve business performance." It also named the AI Cyber Security Code of Practice: organisations following other DSIT codes, including that one, "should also follow the Cyber Governance Code of Practice".
In a blog post of 14 May 2026, the ICO, as it then was, said it expected "organisations that are using or storing personal data to have in place the five technical controls outlined in the Cyber Essentials scheme and to have implemented the actions in the Cyber Governance Code of Practice." The FRC's September 2026 mythbuster reports the part of that statement about the Cyber Governance Code.
The board actions are written for cyber risk. Carrying them across to AI is our analogy: the left column quotes the Code, the right is how we would read the same move for AI.
| Board action in the Cyber Governance Code | The same move for AI (our analogy) |
|---|---|
| "Agree senior ownership of cyber security risks" | Agree who at senior level owns AI risks, and put them in the risk register |
| "Define and clearly communicate the organisation's cyber security risk appetite" | Decide how much AI risk the company will accept, and in which uses |
| "Undertake training to improve your own cyber literacy" | Directors build their own AI literacy |
| "Require formal reporting on at least a quarterly basis, set suitable metrics to track, and agree tolerances for each" | Ask for regular reporting on AI use and its risks, with agreed metrics and tolerances |
The standard for governing bodies, and certification
ISO/IEC 38507:2022 "provides guidance for members of the governing body of an organization to enable and govern the use of Artificial Intelligence (AI)", and also addresses executive managers. ISO/IEC 42001:2023 "specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS)".
UKAS announced on 15 January 2026 that it had granted BSI the first UKAS accreditation for certifying AI management systems to ISO/IEC 42001. Organisations can be certified against it by a UKAS-accredited certification body, and at least three such bodies list it: BSI Assurance UK, NQA Certification and ISOQAR.
How these standards sit beside other frameworks is set out in our comparison of AI governance frameworks, and the basics in what AI governance is.
What the surveys measured
DSIT's UK Business Data Survey 2026 asked 1,870 UK businesses that use AI, sole traders included, between October 2025 and January 2026. Of all of them, 5% had a formal, written AI policy, 12% informal policy or guidance, and 82% neither (Table 49). Among the 100 large businesses in that group, 56% said they had a formal, written policy; among micro businesses, 8%, and among sole traders, 3%.
DSIT and the Home Office's Cyber Security Breaches Survey 2025/2026, which leaves out sole traders, found board members taking explicit responsibility for cyber security in 31% of businesses and 68% of large businesses, noting that not all businesses have a formal board. It found 16% of businesses and charities had heard of the Cyber Governance Code, and 51% of large businesses.
Of businesses using, adopting or considering AI, the same survey found 24% had security practices to manage its risks, a narrower measure than AI governance.
An Institute of Directors survey of business leaders, run in collaboration with the insurer Hiscox (255 responses, May 2026), found 29% of respondents said their organisation had a formal policy or governance framework for AI usage; the IoD does not publish how respondents were recruited, whether results were weighted, or who was asked the policy question.
In each official survey the figure for large businesses was higher than that survey's overall figure: a formal, written AI policy among businesses that use AI, sole traders included (56% against 5%), and a board member responsible for cyber security among businesses with employees (68% against 31%).
Frequently asked questions
When does the revised Provision 29 first apply to a company with a 31 March year end?
It applies for financial years beginning on or after 1 January 2026, so a company whose year ends on 31 March first applies it in the financial year starting 1 April 2026. Until then, Provision 29 of the 2018 Code applies, which already asked for an annual review of the framework.
Is the regulator's data protection audit framework meant for small businesses?
The framework page says it "is suitable for large businesses and organisations in the public, private and third sectors" and is not directly applicable to small businesses and organisations, "who should use the resources on our web hub, such as the self-assessment toolkit".
Does the AI Cyber Security Code of Practice speak to boards?
It is the AI code the Cyber Governance Code named, and its principles are aimed at developers and system operators. DSIT published the Code of Practice for the Cyber Security of AI on 31 January 2025; for senior leaders it pointed to their "responsibilities to help protect their staff and infrastructure as noted in DSIT's Cyber Governance Code of Practice."
Did the government publish its own AI management tool alongside the ISO standards?
No. DSIT's AI Management Essentials (AIME) tool was not published: in its government response (gov.uk, February 2026), DSIT said it "will not be publishing AIME and therefore will not be making it a requirement of the government procurement process."
Want to own AI governance in your organisation?
Our Level 4 Data & AI Governance programme builds the frameworks that make data trustworthy and AI accountable, funded through the Growth & Skills Levy.