Say "AI governance" and most people picture something that belongs to somebody else. A bank. A government department. A committee, a compliance floor, a hundred-page framework nobody reads.
That version is real, and if your business needs it we can build it. But most need something lighter, and the underlying job is the same either way: a clear, honest way to stay in control of the AI you use, so it works for you rather than quietly working against you. I am David Perkins, an IIA-certified internal auditor. Governance is, in plain terms, the job I did for fifteen years. Here is the version that fits whatever you are running.
Control, not paperwork
Governance is a means to an end. The end is that you are not surprised by your own tools.
Governance has a bad name because most people have only met the heavy version: the framework that exists to be shown to an auditor, not to change how anyone works. Strip it back and governance is just the answer to a simple question. If someone asked you today what AI your business runs, what it touches, and who is responsible for it, could you tell them?
If you can, you have governance, however informal. If you cannot, you do not, however many tools you use. The goal is not a document. It is a state: you are in control of your AI instead of hoping it behaves.
Governance is just being able to answer what you run, what it touches, and who owns it.Read this first if you have not AI risk: the four things that actually go wrong →
Three people are about to ask
The pressure to govern AI is not theoretical any more. It arrives as questions from people you cannot ignore.
You do not need governance because a textbook says so. You need it because, increasingly, three parties are starting to ask for it, and "we have not really thought about it" is a poor answer to any of them.
Regulators. The UK is applying existing rules to AI rather than waiting for a single new law (there is no UK AI Act, only a private member's bill that has cleared the Lords and moved to the Commons but is not yet law). The Information Commissioner's Office already treats AI decisions and inferences about people as your responsibility. If you are near financial services, the Bank of England and the FCA now watch AI use directly. The expectation of being able to show control is already here.
Clients. Larger customers are adding AI questions to their supplier checks. If a client asks how you use AI on their data and you cannot answer cleanly, that is a lost tender, not a hypothetical.
Insurers. Professional indemnity and cyber policies are beginning to ask about AI use. An honest, evidenced answer protects your cover. A vague one can quietly undermine it.
Four parts, kept light
This is the whole thing. For most small and medium businesses it fits on a page or two, and it is far more than they have now.
One named person
Someone in the business is accountable for AI. Not a committee, not the vendor, a person. They do not have to be technical. They have to be the one who can answer for it and who notices when something changes.
A short statement of what is allowed
A page, not a manual. What AI the team may use, what may never go into it, and where a human must check before anything reaches a customer. Short enough that people actually read it and follow it.
One honest list
Every AI tool and every AI feature you run, what data it touches, and who owns it. The single most useful artefact in AI governance, and the one almost nobody has. You cannot govern what you have never written down.
A regular honest look
A short quarterly check: is the register still true, has anything new been switched on, did anything go wrong we should learn from. Governance decays the moment it is set and forgotten. The review is what keeps it real.
If your governance takes more effort to maintain than the AI it governs, you have overbuilt it. For a small team that can be a single shared document and one recurring meeting; for a larger one, a fuller programme with named owners and a proper review cycle. Same test, different scale. That is not cutting corners, it is fit for purpose.
Governance from someone who did it for a living
The discipline is internal audit. The subject is your AI. The independence is the point.
Setting up proportionate governance is close to the work I spent fifteen years doing: looking at how a business really runs and building the light controls that keep it honest without slowing it down. The difference now is the subject. And because we do not sell you the AI, we have no reason to tell you it is fine when it is not.
If you want help building the register, the policy, and the review, or an independent read on the AI you already run, our AI and Automation Assurance service is exactly that. If you are earlier and just want an honest steer, the free strategy session is the place to start. Either way you leave with control you can show, not just claim.