05 · AI capability

Responsible AI & Governance

Create proportionate controls for AI use through clear ownership, risk classification, evaluation, transparency, oversight, and change management.

The context

Begin with the work, evidence, and consequence.

Responsible AI governance should help teams make better decisions, not merely produce policy. Controls need to reflect how an AI capability is used, who may be affected, what can go wrong, and who has the authority and evidence to approve, monitor, pause, or change it.

01

No shared inventory

Models, embedded provider features, experiments, and automated decisions are adopted without a current view of their purpose, data, owners, and status.

02

One control level for every use

Low-impact assistance and consequential automated decisions follow the same process, creating either unnecessary friction or insufficient scrutiny.

03

Approval ends at launch

Initial review exists, but model, data, prompts, providers, integrations, user behaviour, and operating context can change without a reassessment trigger.

Areas of attention

Connect AI behaviour to a dependable product and operation.

The appropriate techniques, controls, and delivery depth follow the use case. These areas keep the technical work connected to the people and decisions around it.

01

Inventory and accountability

Record AI capabilities, intended uses, providers, data, affected people, lifecycle state, and accountable business and technical owners.

02

Risk and control model

Classify use cases by consequence and context, then connect them to proportionate evidence, approval, access, oversight, and documentation.

03

Evaluation and transparency

Define quality, safety, fairness, robustness, disclosure, explanation, challenge, and record-keeping needs for the specific use.

04

Lifecycle governance

Establish monitoring, incidents, user feedback, provider change, reassessment triggers, retirement, and evidence retention responsibilities.

Potential outputs

Create evidence and artefacts the team can use.

Outputs are shaped around the decision and engagement stage. Each should have a clear audience, purpose, owner, review criteria, and stated limitation.

  1. 01AI use-case inventory and ownership map
  2. 02Risk classification and proportionate control framework
  3. 03Evaluation, documentation, and approval templates
  4. 04Human oversight, escalation, incident, and change procedures
  5. 05Governance implementation roadmap and review rhythm

Evaluation and responsibility

Make inputs, useful evidence, and boundaries explicit.

AI quality cannot be separated from its context of use. Representative inputs, subject expertise, realistic scenarios, and accountable owners are part of the engineering work.

01

What we need to understand

  • Current and planned AI uses, owners, providers, users, and affected groups
  • Data categories, access, retention, location, and security requirements
  • Applicable internal policies, contractual duties, sector obligations, and legal advice
  • Existing product, security, privacy, risk, quality, procurement, and incident processes
02

Evidence of a useful direction

  • AI uses have an intended purpose, accountable owner, lifecycle status, and known boundaries
  • Control depth follows the consequence and context of the use
  • Approval decisions can trace the evidence, assumptions, limitations, and responsible reviewers
  • Changes, incidents, complaints, and monitoring findings lead to defined review actions
03

Important boundary

Governance design and technical implementation do not replace legal, regulatory, privacy, security, employment, or sector-specific advice. Appropriate specialists should interpret applicable obligations.

Working path

Reduce uncertainty before expanding commitment.

The exact sequence depends on the use case and current evidence. Each stage should leave a reviewable result and an informed choice about the next step.

01

Inventory

Identify AI uses, intended purposes, owners, providers, data, affected people, status, and existing controls.

02

Classify

Assess consequence, uncertainty, sensitivity, autonomy, scale, and relevant organisational or external requirements.

03

Implement controls

Define proportionate evaluation, documentation, approval, access, oversight, transparency, and escalation.

04

Govern change

Monitor operation and establish incident, feedback, provider-change, reassessment, and retirement processes.

AI capability questions

Important details to clarify.

Early questions should expose the task, evidence, uncertainty, and responsibilities that shape a safe and useful implementation.

Do we need governance for low-risk AI tools?+

Proportionate governance is still useful, but the control depth should match the use. A bounded drafting aid should not necessarily follow the same process as a system influencing an important eligibility decision.

Can you certify that an AI system is compliant?+

No. We can help implement technical and operating controls and prepare evidence, but compliance conclusions require the relevant legal, regulatory, contractual, and organisational authority.

What should an AI inventory contain?+

At minimum it should make the intended use, owner, users, affected people, provider or model, data context, lifecycle status, dependencies, material risks, controls, and review history discoverable.

How often should an AI system be reviewed?+

Review timing should follow consequence, rate of change, monitoring signals, incidents, complaints, provider updates, data shifts, and explicit reassessment triggers rather than one universal schedule.

Start a conversation

Let's discuss responsible ai and governance.

Share the workflow, evidence, people affected, and the outcome you want. We can help frame a responsible first question and bounded next step.

Talk to Floatger