Most organisations I speak to have either no AI governance or a lot of it that nobody uses. Both come from the same mistake: treating governance as a document to be written rather than a set of decisions to be owned.
The pattern I keep seeing
An organisation adopts AI in one team. Enthusiasm is high, results are promising, and no one asks who is responsible. Months later a leader wants to extend it, a regulator or customer asks how it works, or it produces a bad output. Suddenly a policy is commissioned.
It is thorough, correct and quickly forgotten, because it describes an organisation that doesn't exist: one where roles are clear and someone is watching.
Three things that matter more than the policy
An owner
One named person accountable for each system: its purpose, its data, its performance and its retirement. Committees advise; owners decide.
A “never do” list
Before asking what a system should do, write down what it must never do, such as give clinical advice, share certain data, or take irreversible actions without approval. Then test against that list. It is the cheapest, most effective governance artefact I know, and in my experience it is the one most often missing.
Meaningful human oversight
A person who can intervene in theory but lacks the time, context or authority to do so is a formality, not a control. Design the workflow so the human decision point is real: visible, interruptible and logged.
What the research and the field agree on
My doctoral work in AI-driven business analytics, and projects in healthcare and large enterprises, point the same way: trust in a system follows from being able to explain and audit it, not from its accuracy alone.
One example: a fraud-detection project for one of Germany's largest health-claims auditing companies, where an AI model screened around 15 million prescription records and surfaced cases such as forged prescriber signatures. The model's accuracy mattered, but what made its output usable was that each flag could be traced back to the records and patterns behind it, and that a trained auditor, not the model, made the final call. Without that, a highly accurate flag is still just an accusation nobody can defend.
Where standards and regulation fit
Frameworks such as ISO/IEC 42001 and regulation such as the EU AI Act give structure and a shared vocabulary, and they are worth understanding. But they work best on top of ownership and oversight, not instead of them. Compliance can be demonstrated on paper; governance has to function on a bad Tuesday.
If you're weighing up the standard itself, I've covered it separately in ISO/IEC 42001 Explained: The New AI Management Standard, and Who Needs It First.
A starting point you can use this week
- List your AI systems and name an owner for each.
- Write a five-line “never do” list for the highest-impact one.
- Identify the human who can stop it, and confirm they know it.
- Check that you could explain its last decision.
If you can do those four things, you're further along than many organisations with far longer policies.