Skip to content
Go to homepageDrova logo

AI governance, in plain English

Who decides, what gets checked, and who answers when it goes wrong. The whole discipline without the jargon.

Most writing about AI governance starts with a framework and ends with a committee. This page starts somewhere more useful: the four working parts a business actually runs, each small enough to fit on a page, together strong enough to satisfy anyone who asks how you govern AI.

Simple feature visual

TL;DR

  • AI governance is how a business stays in charge of the AI it uses: which tools are allowed and on what terms, what may go into them, who verifies what comes out, and who answers when it goes wrong.
  • It is not a framework purchase or a committee name. The working parts are a policy, a register, an assessment rhythm and safeguards, and each fits on a page.
  • You almost certainly govern spending this way already: rules, records, review, an accountable owner. AI governance applies the same shape to a new subject.
  • The formal frameworks, NIST's AI Risk Management Framework and ISO/IEC 42001, describe the same working parts in formal language. They earn their keep when customers or regulators ask for them.
  • Start with the register question, not the org chart: which risks is AI driving against your objectives, and who owns each one?

What is AI governance?

AI governance is the set of decisions, rules and checks a business uses to stay in charge of the AI it relies on: which tools are approved and on what terms, what data may go into them, who verifies what comes out before it ships, and who is accountable when something goes wrong. In a large enterprise that becomes committees, charters and certified frameworks. In most businesses it is four working parts, each of which fits on a page.

The reason it has its own name, rather than folding invisibly into IT policy, is that AI cuts across everything at once: the same tool touches customer data, published output, hiring decisions and financial analysis in the same week. Governance is what keeps those uses inside boundaries someone actually chose.

This page is the map. Our series on the real risks of AI for a business is the territory: each risk the governance exists to hold, one page at a time.

The four working parts

Accountability, sized to fit

Who owns what

Governance fails as a committee and works as a set of names. The minimum viable version is three roles, which in a fifty-person business might be three people and in a five-person business might be two. One accountable owner for AI overall, who need not be technical: the qualities that matter are authority and follow-through. They own the policy and the tool list. An owner per register entry, because a risk without a name attached is a risk nobody re-scores. Whoever signs the output, because the person whose name goes on AI-drafted work owns its accuracy, a rule that scales from an email to an annual report.

Leadership's part is a question set, asked on a rhythm: which risks is AI driving against our objectives, who owns each one, when were they last re-scored, and what changed since. If those four questions get real answers each quarter, governance is working, whatever it is called internally.

Formality on demand

Do you need a framework?

Eventually, possibly; first, no. The two names worth knowing: NIST's AI Risk Management Framework, the free, voluntary reference that other guidance aligns with, and ISO/IEC 42001, the certifiable AI management system standard. Both describe the same working parts this page does, in the formal language that procurement teams and regulators recognise.

A framework earns its keep when someone you answer to asks for it: a customer's due diligence questionnaire, a regulated industry, a tender that scores certifications. Adopting one before then adds vocabulary, not safety, because a framework describes governance rather than creating it. A business running the four working parts honestly can map them to either framework in days; a business with a certificate and no working parts has paperwork.

For the operational side of using AI safely, the joint Engaging with AI guidance from the Australian, UK and US cyber agencies is the plain companion piece.

AI governance FAQs

What is AI governance?

The decisions, rules and checks a business uses to stay in charge of the AI it relies on: which tools are approved and on what terms, what data may go in, who verifies what comes out, and who is accountable when it goes wrong. In most businesses it runs as four working parts: a policy, a register, an assessment rhythm and safeguards.

What is the difference between AI governance and AI risk management?

Risk management is one working part of governance: the register and the assessment rhythm that keep the risks scored and owned. Governance is the whole structure around it, adding the rules (policy), the machinery (safeguards) and the accountability for all of it.

Do small businesses need AI governance?

Yes, in proportion: two or three named owners and four short documents, not a committee. It becomes necessary the first time AI output ships to a customer, a regulator or a court, which for most businesses happened some time ago, with or without the governance.

What is the best AI governance framework?

NIST's AI Risk Management Framework is the free reference; ISO/IEC 42001 is the certifiable standard. But a framework describes governance rather than creating it. Run the working parts first, and adopt a framework when a customer, regulator or tender asks for one; the mapping is quick if the parts are real.

Where should a business start with AI governance?

With the register question: which risks is AI driving against your objectives, and who owns each one? Everything else, the policy, the rhythm, the safeguards, follows from that list. Starting with the org chart instead produces committees with nothing to govern.

The AI Disruption Index scores the risks AI is driving against your objectives, with a safeguard drafted for each. Free, in about ten minutes.

Governance starts with the register. See yours in minutes.

AI risk series

Explore related topics

The real risks of AI for a business

The series hub: what counts as an AI risk, the four families, and where to start.

The AI policy your business actually needs

The full template, free on the page, and how to make it yours.

The AI risk register

What every entry carries, with worked examples.

How to run an AI risk assessment

Three ways to do it, compared, and the five steps.

Guardrails, safeguards, controls: what AI actually needs

Three words untangled, and the four families of AI-era safeguards.

AI in risk management: what it can genuinely do

The four jobs AI does well, and the three things it must never own.

AI data leakage: what your people paste into AI

The fastest breach is a paste: the four ways out, and the rules that keep the tools without the leak.

AI hallucinations at work: examples and what they cost

Three documented cases with price tags, and the verification safeguards that catch fabrication before it ships.

AI phishing: the email with perfect grammar

Why the spot-the-typo era is over, and the safeguards that work without spotting the fake.

AI scams targeting businesses

Old cons, industrialised: the four branches, the tells that remain, and what to do if you're hit.

Fraud no longer needs a forger

Deepfakes, voice clones, invoice fraud, and the safeguards that still hold.

AI cyber attacks: when the attack is automated

Familiar attacks at a new tempo: the real uplift, the hype, and the fundamentals that still hold.

Prompt injection: the attack your register hasn't heard of

Instructions hidden in ordinary content, and the safeguards that limit the damage.

What is AI disruption?

A plain definition: the change is in your risks and plans, not just your tools.

See your own AI risk picture

The risks AI is driving against your objectives, scored for your business.