What belongs in an AI governance framework?
Six things: acceptable use, data handling, human review, vendor review, disclosure, and review cadence. For most organizations of 40 to 500 people the whole thing fits on a few pages, and the shortest version that people actually read beats the thorough one nobody opens.
01
Acceptable use
Name the tools people may use and the work they may use them for. Be specific about what is banned outright, such as client-identifiable information in consumer tools.
Test: A new hire can read it in five minutes and know what to do on day one.
02
Data handling
Classify your data into what can leave the organization, what can go to a contracted vendor, and what never leaves. Map each approved tool to a classification.
Test: Every approved tool has a written data classification beside it.
03
Human in the loop
For each use case, state whether output is advisory, reviewed before use, or auto-applied. Anything touching money, employment, safety or a client commitment stays reviewed.
Test: Someone is named as the reviewer, not a team.
04
Vendor review
Before adopting a tool, record where data is stored, whether it trains on your inputs, the retention period, and how you exit.
Test: You could switch vendors without losing your own data.
05
Disclosure
Decide when clients, candidates and staff are told AI was involved. Write the standard down once rather than deciding case by case.
Test: The rule is the same regardless of who is asking.
06
Review cadence
Set a review date and an owner. Quarterly is enough for most organizations while the regulatory picture keeps moving.
Test: There is a date in a calendar and a name against it.
The most common gap
Staff are usually already using AI before a policy exists. The risk is not future adoption, it is the client and employee data that has quietly left the organization through consumer tools nobody approved. Start there.