1. Record the purpose and responsible people
Start with a system inventory that describes each use, its users, information sources, supplier and actions. Distinguish a tool that drafts internal text from one influencing access to employment or services. The consequences determine the depth of review; the same model can be used in very different risk contexts.
Our governance service can help define an inventory, risk assessment, supplier questions and operating procedures. Assign a business owner, a technical owner and escalation contacts. Record who can approve release and who can pause operation. A policy document without these decisions leaves staff uncertain when something goes wrong.
2. Use established guidance appropriately
The NIST AI Risk Management Framework organises risk work around Govern, Map, Measure and Manage. It is a voluntary framework, not a certificate or a substitute for law. Use it to organise questions about context, evidence and controls rather than treating a completed checklist as proof of safety.
The ICO’s AI guidance addresses personal-data responsibilities in the UK. For each system, identify which legal and sector requirements apply. Involve your privacy, security and legal advisers where the use is consequential. Governance support does not replace a qualified legal assessment of a specific deployment.
3. Assess data protection and wider impacts
The UK GDPR and Data Protection Act govern relevant personal-data processing. A data protection impact assessment, or DPIA, is required where processing is likely to result in high risk to individuals’ rights and freedoms. Consider necessity, proportionality, sources, retention, access and how people can exercise their rights.
The EU AI Act establishes obligations based on system type, use and the organisation’s role. A UK organisation should not assume the Act is irrelevant merely because its office is outside the EU. Check its territorial scope, applicable provisions and implementation dates with qualified counsel before making deployment decisions.
4. Review suppliers and permitted uses
Inspect contractual terms covering processing purposes, subprocessors, international transfers, retention and use of inputs for model improvement. Confirm the arrangements for the specific service and account configuration. A supplier’s general marketing statement may not describe the product your organisation intends to use.
Review access controls, incident reporting, change notices and export or deletion arrangements. Record dependencies so a model or hosting change can be assessed properly. Compare a managed service with self-hosting against the team’s actual ability to secure, maintain and monitor it. Keeping infrastructure in-house moves responsibility; it does not remove the underlying risks.
5. Turn risk into practical controls
For each identified failure, specify a control and an accountable owner. Unsupported answers may require source citations and abstention. Unauthorised actions require permission limits and independent validation. Disclosure risks need access enforcement and careful logging. Define what evidence demonstrates that each control works in the intended environment.
Human oversight should include access to the original information and authority to reject the proposed result. Merely putting a person after a model does not establish meaningful review. Explain limitations to users in plain words, and provide a route for corrections, complaints and questions without requiring them to understand the underlying technology.
6. Monitor changes and prepare to stop
Agree what to monitor, who receives alerts and which conditions trigger investigation or suspension. Review significant changes to prompts, sources, permissions and suppliers before treating them as routine maintenance. Preserve enough evidence to investigate incidents while respecting confidentiality and retention limits.
Prepare a fallback process and identify how affected people will be informed where necessary. For an initial governance enquiry, share the intended use, data categories, supplier arrangements and existing approval process. Do not email sensitive incident records at first contact. We can discuss scope before agreeing a secure route and any required processing arrangements.
Discuss AI governance