Up to now the work has been done system by system. Governance is what makes it repeatable when the person who built the inventory leaves. It needs three things: a named owner, a short written policy, and a routine.
One accountable owner
Every framework starts with accountability. NIST's AI RMF puts "Govern" at the centre of its four functions; ISO/IEC 42001 requires top management to assign responsibility and authority. In a ten-person company that is a founder. In a larger one it is a named executive (often legal, risk or the COO) with a working group of product, engineering, HR, security and privacy. Give the role a title in writing: "AI compliance owner". Boards increasingly ask who this is.
A RACI that fits on one page
For each activity, name who is Responsible, Accountable, Consulted and Informed:
- Inventory and risk classification: system owners responsible; AI owner accountable.
- Privacy and data: privacy lead or DPO.
- Fairness testing: HR or product analytics responsible; legal consulted.
- Security: IT/security lead.
- Vendor terms: procurement or whoever signs contracts.
- Incidents: a named on-call person plus the AI owner.
- Training: HR or the AI owner.
The AI policy (two pages, not twenty)
Your policy should say:
- Scope: what counts as AI here and which tools are approved.
- Rules for staff: what may and may not be pasted into tools; when AI output must be reviewed by a person; when disclosure is required.
- Approval: how a new AI use gets registered and classified before go-live.
- Prohibited uses: mirror the EU Article 5 and Texas TRAIGA lists plus anything you choose to rule out.
- Roles: the RACI above.
- Incidents: how to report one, to whom, within what time.
- Review: the policy and the inventory are reviewed at least annually and after material legal change.
Texas TRAIGA makes this concrete: an organisation that maintains a risk-management programme aligned with a recognised framework such as the NIST AI RMF has an affirmative defence to enforcement. A written, followed policy is that programme.
The routine
- Monthly (15 minutes): new tools registered? open incidents? upcoming legal dates?
- Quarterly: inventory review, fairness re-tests due, vendor renewals.
- Annually: policy review, training refresh, management report.
Put these in the calendar. Governance that lives in someone's head is not governance.
Reporting upward
Once a year, send the board or owners a one-page report: systems in use by risk tier, tests run and results, incidents, training completion, legal changes ahead, and the top three gaps. This is also what an insurer, an acquirer or a large customer will ask for in due diligence.
Scale it to your size
Solo founders: the owner is you, the policy is one page, the routine is a monthly calendar reminder. What matters is that it exists and is followed, not its length.