AI Governance Guide for UK Organisations
This guide gives UK organisations a practical, step-by-step approach to building an AI governance framework that satisfies board-level accountability requirements, meets current and upcoming regulatory obligations, and can be demonstrated to auditors, insurers, and counterparties. It is not legal advice. For your specific circumstances, seek qualified legal counsel and a professional governance assessment.
Why AI governance matters now
AI governance is no longer a future consideration for UK organisations. Several converging pressures make it an immediate operational and legal requirement:
- EU AI Act (Regulation 2024/1689) applies to any organisation deploying AI systems that affect EU persons — which includes most UK organisations with EU customers, staff, or partners. High-risk AI systems face conformity assessment obligations, and prohibited systems must be identified and decommissioned. The Act is in phased enforcement, with prohibitions from February 2025 and high-risk obligations building through 2026–2027.
- UK GDPR and the Data Protection Act 2018 already impose obligations where AI systems make automated decisions about individuals (Article 22), process special category data, or carry out profiling. The ICO has published specific AI guidance.
- ISO/IEC 42001:2023 provides an internationally recognised standard for AI management systems, increasingly required in supplier questionnaires and enterprise procurement.
- FCA, PRA, and sector regulators have published or are developing AI-specific guidance for financial services, healthcare, and other regulated sectors.
- Board liability for AI-related harm is increasing. Directors who cannot demonstrate active governance oversight of AI risk face personal and corporate reputational and legal exposure.
Regulatory landscape at a glance
UK organisations typically need to consider: UK GDPR (ICO), EU AI Act (if EU nexus), sector-specific AI guidance (FCA, CQC, MHRA), ISO/IEC 42001 (supply chain), and the UK government's AI Assurance framework. The interaction between these is complex — start with your AI inventory before mapping obligations.
Step 1 — AI system inventory
Build a complete, current AI system register
You cannot govern what you have not identified. The AI inventory is the foundation of every subsequent step.
Many organisations underestimate the breadth of their AI estate. AI is embedded in SaaS tools (CRMs, HR platforms, email filtering), third-party APIs, internal ML models, cloud services, and now increasingly in agentic AI tools used informally by staff. Your inventory must capture all of these.
What your AI register should capture
- System name and description — what it does and how it is used
- Type — LLM, ML classifier, recommendation engine, computer vision, NLP, AI agent, generative AI, etc.
- Deployment context — internal tool, customer-facing, automated decision-making, advisory/support
- Data inputs — what personal data or sensitive data does it process?
- Outputs and consequences — what decisions or actions does it influence or make?
- Affected persons — employees, customers, third parties, vulnerable populations?
- System owner — named accountable individual
- Supplier / third-party involvement — is this a vendor-supplied model or API?
- Date deployed and date last reviewed
- Regulatory classification — EU AI Act risk tier (prohibited, high-risk, limited, minimal)
Common gap: Shadow AI — AI tools adopted by individual employees or teams without IT or security awareness. A meaningful inventory requires input from HR, operations, legal, and customer-facing teams, not just IT. Conduct a structured discovery exercise before declaring your inventory complete.
Step 2 — Risk classification
Classify each AI system by risk level
Risk classification determines the governance controls required for each system and your regulatory obligations.
For each AI system in your register, apply a structured risk classification. The EU AI Act provides the most developed regulatory framework for this and is a useful baseline regardless of whether the Act directly applies to you.
EU AI Act risk tiers (summary)
- Prohibited (Article 5): AI systems that pose unacceptable risks — social scoring by public authorities, real-time biometric surveillance in public spaces, manipulation of vulnerable groups. These must be identified and decommissioned.
- High-risk (Annex III): AI used in: critical infrastructure, educational/vocational assessment, employment decisions (CV screening, performance monitoring), essential private and public services (credit scoring, benefits assessment), law enforcement, migration management, justice administration, and AI in safety components of regulated products. These face the most extensive obligations.
- Limited risk: AI systems with specific transparency obligations — chatbots must identify themselves as AI, deepfake content must be labelled.
- Minimal risk: Spam filters, AI in video games, etc. No additional regulatory requirements, but still subject to your own governance standards.
In addition to the EU AI Act tiers, assess each system for: data protection impact (UK GDPR DPIA triggers), business criticality, reputational risk, and sector-specific regulatory requirements.
Step 3 — Governance framework design
Build the policies and controls proportionate to your risk profile
Governance without documentation is unenforceable. Proportionality matters — a 20-person professional services firm needs a different framework to a 500-person financial services company.
A minimum viable AI governance framework for a UK organisation should include:
- AI Use Policy: Defines permitted and prohibited uses of AI by employees, covering personal data handling, output verification, prohibited categories, and escalation procedures for edge cases.
- AI Risk Register: Live document capturing assessed risks for each system, with likelihood/impact ratings, existing controls, residual risk, and review schedule.
- AI System Register: The inventory from Step 1, maintained as a live document with a named owner.
- Data Protection Impact Assessments (DPIAs): Required under UK GDPR for any AI processing that is likely to result in high risk to individuals. Must be completed before deployment.
- Procurement and Vendor Assessment: Standards for evaluating AI tools before adoption — see Step 6.
- Acceptable Use Guidelines: Employee-facing guidance (shorter and more practical than the formal policy) covering day-to-day AI tool use.
- AI Incident Response Plan: Procedures for identifying, containing, and reporting AI-related incidents — see Step 7.
ISO/IEC 42001 alignment: If you are targeting ISO/IEC 42001 certification or need to demonstrate alignment to customers or auditors, your governance framework should follow the AI Management System (AIMS) structure specified in the standard, including: context of the organisation (Clause 4), leadership and commitment (Clause 5), planning (Clause 6), support (Clause 7), operations (Clause 8), performance evaluation (Clause 9), and improvement (Clause 10).
Step 4 — Board and senior management accountability
Assign clear accountability at the top
AI governance without board-level accountability is a compliance exercise that will not survive scrutiny.
Effective AI governance requires accountability to be assigned at senior management and board level, not delegated entirely to IT or data teams.
Accountability structure essentials
- Designated AI lead: A named senior individual (CISO, CTO, CDO, or equivalent) with formal responsibility for the AI governance programme and reporting line to the board.
- Board AI oversight: AI risk should appear on the board risk register and be reported on at least annually. For organisations with significant AI exposure, quarterly reporting is appropriate.
- System owners: Each AI system in the register should have a named individual owner responsible for its governance, DPIA, and compliance with applicable policies.
- Three lines of defence: Apply standard risk management structure — operational teams (first line), risk/governance function (second line), internal audit (third line) — to AI risk.
Step 5 — Human oversight and intervention capability
Ensure humans can understand, override, and stop AI systems
Both the EU AI Act and UK GDPR require that humans retain meaningful oversight of AI decision-making, particularly for high-risk and automated-decision systems.
- Human review mechanisms: For AI systems influencing decisions about individuals, document how human review is carried out, who is responsible, and how decisions can be overridden.
- Kill switches and disable capability: All AI systems should be capable of being suspended without loss of core business function. Document shutdown procedures for each system.
- Staff awareness and capability: Staff operating or reviewing AI outputs must have sufficient training to meaningfully assess those outputs — "human in the loop" is meaningless if the human cannot evaluate what they are reviewing.
- Audit trails: Maintain logs of AI-influenced decisions sufficient to support challenge, review, and regulatory inquiry. Retention periods should align with your business context and legal obligations.
- UK GDPR Article 22: Where AI is used in fully automated decision-making producing legal or similarly significant effects on individuals, you must provide a mechanism for human intervention, and the right to contest the decision.
Step 6 — Vendor and third-party AI risk
Apply governance standards to AI in your supply chain
Most organisations use far more vendor-supplied AI than internal models. Your governance obligations follow the function, not the source.
Your organisation is responsible for AI systems it deploys even when they are provided by third parties. Key areas to assess for vendor-supplied AI:
- Model transparency: Can the vendor explain how the model works, what data it was trained on, and what bias testing has been conducted?
- Data processing: Is your data (including personal data) used to train the vendor's models? Is it shared with third parties?
- Contractual protections: Does your contract include appropriate AI-specific provisions covering accuracy, bias, data use, audit rights, and liability?
- EU AI Act compliance: For high-risk AI systems, providers should be able to supply EU AI Act technical documentation and a declaration of conformity (from August 2026).
- Security posture: What are the security controls around the vendor's AI infrastructure? Can they demonstrate compliance with relevant standards?
- Continuity and dependency: What is your contingency if the vendor changes, withdraws, or significantly modifies the AI system?
Step 7 — Incident management for AI
Plan for AI-specific failures and misuse scenarios
AI incidents have characteristics that differ from traditional IT incidents — bias emergence, adversarial attacks, data poisoning, and output manipulation require their own playbooks.
AI-specific incidents to plan for include:
- Biased or discriminatory output — systematic errors affecting protected characteristics
- Prompt injection attacks — adversarial inputs causing AI to act outside its intended scope
- Data exfiltration via AI systems — sensitive data leaking through model outputs or logs
- Model drift — performance degrading over time as real-world data diverges from training data
- AI impersonation — deepfakes, synthetic voice, or AI-generated content used in fraud or social engineering targeting your organisation
- Regulatory enforcement action — ICO investigation, EU AI Act supervisory authority inquiry
For each incident type, your AI incident response plan should specify: detection mechanisms, initial triage steps, escalation path (including board notification thresholds), containment actions, regulatory notification requirements (UK GDPR breach notification within 72 hours to the ICO where applicable), and post-incident review process.
Step 8 — Regulatory mapping
Map your AI systems to current and forthcoming obligations
Regulatory requirements are evolving rapidly. Map your systems now so you are not starting from scratch when enforcement intensifies.
Prohibitions in force Feb 2025. GPAI model rules August 2025. High-risk obligations building through 2026–2027. Applies where AI affects EU persons.
Article 22 (automated decisions), DPIAs for high-risk processing, accuracy obligations, data minimisation. ICO AI auditing programme is active.
AI Management System standard increasingly required by enterprise buyers in procurement questionnaires. Certification available via accredited bodies.
GOVERN, MAP, MEASURE, MANAGE framework. Often required by US counterparties and increasingly referenced in UK AI assurance conversations.
Need a governance assessment?
This guide gives you the framework. Holster's AI Governance Assessment translates it into a gap analysis, risk register, and prioritised remediation plan specific to your AI estate — with deliverables your board, auditors, and regulators can rely on.
Book a free consultation →