Asked to sort out AI governance? Before you pick a framework or write a policy, know what each one is trying to pin down.
What Is AI Governance? A Plain Definition for UK Organisations
By James Cotton · Last updated · 9 min read
Part of our topic guides on AI Governance & Data Strategy and AI Skills for Business.
By James Cotton, Founder, iO-Sphere
Why this guide starts from decisions
Someone asked to "sort out AI governance" is usually handed nouns: a policy, a framework, a committee, a risk register. Published definitions are built from nouns of the same kind. IBM describes "the processes, standards and guardrails that help ensure that AI systems are safe and ethical", and Salesforce "the system of policies, rules, accountability structures, and oversight processes" that guide AI use.
Those definitions name what governance is built from. This guide organises the subject by what those parts have to settle. A manager can start on a decision this week, and a policy drafted before the decisions are made has nothing to record.
A UK government definition pointed the same way. In DSIT's Introduction to AI assurance (February 2024), AI governance was "a range of mechanisms including laws, regulations, policies, institutions, and norms that can all be used to outline processes for making decisions about AI". This guide takes three of those decisions: the ones an organisation has to make for itself.
Decision one: where AI is used
A housing association's repairs desk is a fair test. Tenants report problems by email and web form, and a coordinator starts pasting each report into a general AI assistant to sort it into urgent or routine and draft a note for the contractor. It saves an hour every morning. Nobody signed it off.
Deciding "where" means somebody knowing this happens, knowing what goes into the tool (names, addresses, descriptions of people's homes) and agreeing that the organisation accepts the use. Uses like this start without a meeting, so the first job is to find them.
Written rules for uses like this looked rare when DSIT's researchers asked. In the 100 interviews behind its AI Adoption Research, published in January 2026, "very few businesses said they had any internal guidelines or specific policies around using AI responsibly or ethically".
Personal data raises the stakes. The Information Commissioner's Office, in guidance last updated in March 2023 and now under review (the regulator has been the Information Commission since 30 September 2026), said that "in the vast majority of cases" AI use would involve processing likely to be high risk and so trigger the legal requirement for a data protection impact assessment, a judgement to be made "on a case by case basis".
Rules for staff come after this decision, because a policy can only allow or forbid the uses someone has found. When you reach that point, a staff policy for generative AI tools has its own guide. Until then, the register of what is in use is the work.
Decision two: who answers for each use
Every use needs a named owner: a person who answers for what the AI produces in that setting. On the repairs desk that is the head of repairs, because the outcome that matters is a repair done on time. Where an AI agent acts by itself, the same question is settled agent by agent (governing agentic AI).
At the top of the chain, ISO/IEC 38507:2022, guidance for "members of the governing body of an organization", says the governing body "remains accountable for all activities of an organization" and that "this accountability cannot be delegated" (ISO's page for the standard).
The ICO's chapter makes a narrower point about data protection in AI: "You cannot delegate these issues to data scientists or engineering teams". Senior management, it said, are "also accountable for understanding and addressing them appropriately and promptly", with overall accountability for compliance resting with the organisation as controller.
Both sources put accountability at the top. The other half is this guide's argument: each use still needs someone close to it who owns the result, because the governing body will never see a misfiled repair. How the roles divide between board, senior owner and team is worked through in who is responsible for AI governance.
Decision three: catching a wrong output and putting it right
This is the decision that depends on people. Suppose the assistant files a report of black mould spreading across a child's bedroom wall as routine decoration. No policy catches that. The coordinator who reads it and knows what that mould means for the family catches it, or nobody does.
So the people closest to the work have to be able to tell when the output is wrong. They need to know what a good answer looks like in their job, and they need to know they are expected to question the tool. A checker who cannot judge the answer adds a signature and little else.
Checking itself is common. In the survey strand of DSIT's AI Adoption Research, a telephone survey of 3,500 UK private sector businesses from 12 February to 2 May 2025, 84% of the 700 that used AI reported at least some human input or checking of its output, 67% significant input or checking, and 2% none. Whether the checker could spot the error is the open question.
On training, the Office for National Statistics reported in July 2026 that only 11% of businesses with 10 or more employees said more than half their workforce had received AI-related training.
European law touches the same ground. As amended in July 2026, the EU AI Act requires providers and deployers to "take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf". Whether that reaches a UK organisation is a question for the guide to AI regulation in the UK.
Putting it right is the second half of the decision. The urgent repair is re-booked and the tenant told; then someone asks why the tool misjudged it, and whether to change how it is used, add a rule, or stop. Skip that step and the same error comes back next week.
What governance looks like on the desk
Made and written down, the three decisions become a few working things:
- a register of uses, one line each, saying what the tool does, what data goes in and who approved it;
- a named owner on every line;
- a check where the output lands, done by someone able to judge it;
- a log of what went wrong and what changed because of it.
On the repairs desk that is one line in the register, the head of repairs as owner, the coordinator reading each triage before it reaches the contractor, and the mould misfile written up with the change it led to.
A large organisation has the same things at greater volume: the register spans departments, owners answer upwards to the governing body, and some of the work becomes roles in their own right. DSIT's interviews found larger businesses "more likely than smaller businesses to have policies in place or were in the process of creating them".
A smaller firm needs the same four things with less paper (AI governance for SMEs).
Two kinds of people make this run: those who keep the register, and those who check what comes out. iO-Sphere delivers the Data & AI Governance apprenticeship (Level 4), which runs on the Level 4 Data Protection and Information Governance Practitioner standard (our guide to the standard), and team training in data and AI fluency for the people who use the tools.
Where the frameworks fit
The frameworks a manager is most likely to be shown each record some of these decisions. Most lean on one or two; NIST's touches all three. Choosing one, and what a working framework contains, is a job of its own (building an AI governance framework in the UK).
| Framework | Issued by | Mostly records |
|---|---|---|
| UK's five principles | UK government response, 2024 | Who answers; putting it right |
| ISO/IEC 42001 | ISO and IEC, 2023 | The system that keeps all three under review |
| NIST AI RMF 1.0 | NIST (US), 2023 | All three, with GOVERN throughout |
| OECD AI Principles | OECD, 2019, amended 2024 | Who answers |
| EU AI Act | European Union, in force 2024 | Where AI is used, by level of risk |
The UK's five principles were set out in the then government's response on AI regulation, presented to Parliament on 6 February 2024, as principles "for existing regulators to interpret and apply within their remits". Two of the five sit close to decisions in this guide: "Accountability and governance" and "Contestability and redress".
ISO/IEC 42001, a joint ISO and IEC standard published in December 2023, "specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS) within organizations", in the words of ISO's page. In this guide's terms, it is the container that keeps the three decisions maintained and reviewed.
NIST released AI RMF 1.0 on 26 January 2023 and says it "is being revised". Its core has four functions: MAP for context and risk, MEASURE and MANAGE for assessing and acting, and GOVERN, which NIST calls "a cross-cutting function that is infused throughout AI risk management and enables the other functions of the process".
The OECD AI Principles, adopted on 22 May 2019 and amended on 3 May 2024, have 47 adherents, and one of the five values-based principles is "Accountability". The EU AI Act, in force since 1 August 2024, sorts AI systems into the four levels the European Commission names: "Unacceptable risk", "High risk", "Transparency risk" and "Minimal or no risk". What applies follows the use.
Two neighbouring terms
AI ethics is about values. A 2019 Alan Turing Institute guide for the public sector defined it as "a set of values, principles, and techniques that employ widely accepted standards of right and wrong to guide moral conduct in the development and use of AI technologies". The same guide has a section titled "Process transparency: Establishing a Process-Based Governance Framework".
Ethics names the values; governance is the process that holds an organisation to them.
AI assurance is a separate term. DSIT's 2024 guide said that "assurance measures, evaluates and communicates the trustworthiness of AI systems". In this guide's terms, it is how an organisation shows someone outside that its third decision works.
Frequently asked questions
Why do companies need AI governance?
Because AI mistakes land on customers, tenants and staff, and an organisation that has not settled where AI is used, who owns it and who checks it learns of an error from the person it hurt. Governance also lets a use that works be kept and widened: DSIT's 2024 guide gave the goal as "to maximise and reap the benefits of AI technologies while mitigating potential risks and harms".
Is there a UK government tool for getting started?
One was drafted and put out to consultation. DSIT consulted from November 2024 to January 2025 on AI Management Essentials, a draft "self-assessment tool that aims to help organisations assess and implement responsible AI management systems and processes", and its February 2026 response said the feedback would inform "any work we undertake on the development of refined guidance focused primarily on supporting SMEs deploying AI solutions to build strong foundational governance practices".
Is AI governance a legal requirement in the UK?
Parts of it already rest on existing law, such as data protection where AI touches personal data. In February 2024 the then government said "a non-statutory approach currently offers critical adaptability", said it would keep this under review, and set out its principles "for existing regulators to interpret and apply within their remits". What applies now, with dates and penalties, is in the guide to AI regulation in the UK; sector rules are in AI governance in regulated sectors.
Want to own AI governance in your organisation?
Our Level 4 Data & AI Governance programme builds the frameworks that make data trustworthy and AI accountable, funded through the Growth & Skills Levy.