← All lessons
Level 4 · Managed6 min read

Governance structure and roles

Up to now the work has been done system by system. Governance is what makes it repeatable when the person who built the inventory leaves. It needs three things: a named owner, a short written policy, and a routine.

One accountable owner

Every framework starts with accountability. NIST's AI RMF puts "Govern" at the centre of its four functions; ISO/IEC 42001 requires top management to assign responsibility and authority. In a ten-person company that is a founder. In a larger one it is a named executive (often legal, risk or the COO) with a working group of product, engineering, HR, security and privacy. Give the role a title in writing: "AI compliance owner". Boards increasingly ask who this is.

A RACI that fits on one page

For each activity, name who is Responsible, Accountable, Consulted and Informed:

  • Inventory and risk classification: system owners responsible; AI owner accountable.
  • Privacy and data: privacy lead or DPO.
  • Fairness testing: HR or product analytics responsible; legal consulted.
  • Security: IT/security lead.
  • Vendor terms: procurement or whoever signs contracts.
  • Incidents: a named on-call person plus the AI owner.
  • Training: HR or the AI owner.

The AI policy (two pages, not twenty)

Your policy should say:

  • Scope: what counts as AI here and which tools are approved.
  • Rules for staff: what may and may not be pasted into tools; when AI output must be reviewed by a person; when disclosure is required.
  • Approval: how a new AI use gets registered and classified before go-live.
  • Prohibited uses: mirror the EU Article 5 and Texas TRAIGA lists plus anything you choose to rule out.
  • Roles: the RACI above.
  • Incidents: how to report one, to whom, within what time.
  • Review: the policy and the inventory are reviewed at least annually and after material legal change.

Texas TRAIGA makes this concrete: an organisation that maintains a risk-management programme aligned with a recognised framework such as the NIST AI RMF has an affirmative defence to enforcement. A written, followed policy is that programme.

The routine

  • Monthly (15 minutes): new tools registered? open incidents? upcoming legal dates?
  • Quarterly: inventory review, fairness re-tests due, vendor renewals.
  • Annually: policy review, training refresh, management report.

Put these in the calendar. Governance that lives in someone's head is not governance.

Reporting upward

Once a year, send the board or owners a one-page report: systems in use by risk tier, tests run and results, incidents, training completion, legal changes ahead, and the top three gaps. This is also what an insurer, an acquirer or a large customer will ask for in due diligence.

Scale it to your size

Solo founders: the owner is you, the policy is one page, the routine is a monthly calendar reminder. What matters is that it exists and is followed, not its length.

What this means for you

Name the AI compliance owner in writing this week, then draft the two-page policy from the headings above. Put the monthly, quarterly and annual routine in the shared calendar. That alone moves you from ad-hoc to managed.

Related laws

Quick check · 3 questions

  1. 1.Which function sits at the centre of the NIST AI Risk Management Framework?

  2. 2.What does Texas TRAIGA offer organisations that follow a recognised risk framework such as the NIST AI RMF?

  3. 3.How long should an AI policy be for most small and mid-sized organisations?

0 of 3 answered

Sources

Last reviewed Sep 25, 2026.

Educational information, not legal advice. Laws change and details depend on your situation — check the linked sources and talk to a qualified lawyer before acting. Last content review: 2026-09-25.

Spotted an error? Ask the tutor or email hello@myaiguide.pro.