AI adoption and governance
How to set up an AI governance group that helps work move
Give the forum decisions to make, evidence to examine and clear thresholds for escalation.
Give the group a precise mandate
State which decisions belong to the forum and which do not. Its job may include approving higher-risk use cases, maintaining policy, resolving cross-functional issues, reviewing incidents and deciding whether initiatives should scale. It should not become a weekly demonstration club or a route through which every employee prompt must pass. Publish the mandate, decision rights and escalation thresholds so teams can move without waiting when work falls inside agreed boundaries. Governance creates value when ordinary safe activity becomes easier and consequential activity receives the scrutiny it deserves.
Choose members around consequences
A small core normally needs business ownership, technology, information security or data, risk or legal judgement, and people or operational change. Membership should reflect the organisation and its active use cases. Invite specialists for relevant decisions rather than making every expert a permanent attendee. Name a chair with authority to close decisions and an owner who maintains the portfolio and evidence between meetings. Seniority alone is not enough: the room needs people who understand how work happens, how customers or employees may be affected and what controls are realistic in daily operations.
Use risk tiers to protect pace
Define simple tiers based on data sensitivity, autonomy, affected people, reversibility, regulatory exposure and commercial consequence. Low-risk internal assistance using approved tools may require only local ownership and published rules. Customer-facing recommendations, employment decisions, sensitive data or automated actions deserve stronger review and specialist assurance. The tier should determine the evidence, approvals, monitoring and human oversight required. This avoids applying enterprise-level ceremony to harmless experiments while preventing a superficially small pilot from bypassing scrutiny when its consequence is significant. Review the tiers as capability and regulation change.
Bring decision-ready evidence
Each proposal should state the business job, users, expected value, data involved, model or supplier, human role, failure modes, security considerations, success measures and accountable owner. The forum should receive the material early enough to interrogate it rather than hearing a narrated update in the meeting. Require the proposer to state the decision needed and their recommendation. When evidence is missing, record precisely what must be learned and who will return with it. Governance becomes slow when vague concerns circulate without a route to resolution, or when teams arrive with a finished solution and ask for retrospective approval.
Review value and adoption beside risk
A safe initiative that nobody uses is still a poor investment. Maintain one portfolio view showing status, owner, spend, intended outcome, adoption, performance, incidents and the next decision date. Review whether the workflow changed, whether users trust the result and whether time, quality, revenue, cost or resilience moved. Include retired and paused initiatives so the organisation learns from work that did not scale. This shifts governance away from tool approval towards active stewardship of business value. It also exposes duplicated licences and parallel experiments before they become unmanaged infrastructure.
Prepare for incidents before they occur
Define how people report an unsafe output, data concern, unexpected action or material error. State who can pause the system, who investigates, how affected people are supported and when senior leaders or external advisers must be involved. Keep the route easy to find and psychologically safe to use. Run a short scenario exercise for higher-consequence systems so the first real incident is not the first time responsibilities are discussed. After an event, capture the cause, response and control change without reducing the exercise to blame. The purpose is faster containment and better future decisions. Agree what must be preserved for investigation, including prompts, outputs, source material, system actions, approvals and affected records. Define communication responsibility before an incident creates pressure to reassure too quickly. The group should also review near misses: they often expose unclear ownership or brittle controls before a material event occurs.
Put the answer to work
Use this guidance against one live decision rather than treating it as a general checklist. Name the outcome, owner, evidence and next review point, then record what the business will do differently. Where the choice carries material legal, technical, financial, security or people consequences, bring the relevant specialist into the decision while keeping business ownership explicit.
What to carry into the work
- Give the forum a narrow decision-led mandate
- Scale controls with consequence
- Review commercial value and adoption beside risk
- Define the incident route in advance