HOLSTER holstersecurity.com
Resource Guide · Free

AI Governance Guide for UK Organisations

Published: July 2026
Reading time: ~20 min
Jurisdiction: United Kingdom
Frameworks: EU AI Act · ISO/IEC 42001 · NIST AI RMF

This guide gives UK organisations a practical, step-by-step approach to building an AI governance framework that satisfies board-level accountability requirements, meets current and upcoming regulatory obligations, and can be demonstrated to auditors, insurers, and counterparties. It is not legal advice. For your specific circumstances, seek qualified legal counsel and a professional governance assessment.

Why AI governance matters now

AI governance is no longer a future consideration for UK organisations. Several converging pressures make it an immediate operational and legal requirement:

Regulatory landscape at a glance

UK organisations typically need to consider: UK GDPR (ICO), EU AI Act (if EU nexus), sector-specific AI guidance (FCA, CQC, MHRA), ISO/IEC 42001 (supply chain), and the UK government's AI Assurance framework. The interaction between these is complex — start with your AI inventory before mapping obligations.

Step 1 — AI system inventory

STEP 01

Build a complete, current AI system register

You cannot govern what you have not identified. The AI inventory is the foundation of every subsequent step.

Many organisations underestimate the breadth of their AI estate. AI is embedded in SaaS tools (CRMs, HR platforms, email filtering), third-party APIs, internal ML models, cloud services, and now increasingly in agentic AI tools used informally by staff. Your inventory must capture all of these.

What your AI register should capture

Common gap: Shadow AI — AI tools adopted by individual employees or teams without IT or security awareness. A meaningful inventory requires input from HR, operations, legal, and customer-facing teams, not just IT. Conduct a structured discovery exercise before declaring your inventory complete.

Step 2 — Risk classification

STEP 02

Classify each AI system by risk level

Risk classification determines the governance controls required for each system and your regulatory obligations.

For each AI system in your register, apply a structured risk classification. The EU AI Act provides the most developed regulatory framework for this and is a useful baseline regardless of whether the Act directly applies to you.

EU AI Act risk tiers (summary)

In addition to the EU AI Act tiers, assess each system for: data protection impact (UK GDPR DPIA triggers), business criticality, reputational risk, and sector-specific regulatory requirements.

Step 3 — Governance framework design

STEP 03

Build the policies and controls proportionate to your risk profile

Governance without documentation is unenforceable. Proportionality matters — a 20-person professional services firm needs a different framework to a 500-person financial services company.

A minimum viable AI governance framework for a UK organisation should include:

ISO/IEC 42001 alignment: If you are targeting ISO/IEC 42001 certification or need to demonstrate alignment to customers or auditors, your governance framework should follow the AI Management System (AIMS) structure specified in the standard, including: context of the organisation (Clause 4), leadership and commitment (Clause 5), planning (Clause 6), support (Clause 7), operations (Clause 8), performance evaluation (Clause 9), and improvement (Clause 10).

Step 4 — Board and senior management accountability

STEP 04

Assign clear accountability at the top

AI governance without board-level accountability is a compliance exercise that will not survive scrutiny.

Effective AI governance requires accountability to be assigned at senior management and board level, not delegated entirely to IT or data teams.

Accountability structure essentials

Step 5 — Human oversight and intervention capability

STEP 05

Ensure humans can understand, override, and stop AI systems

Both the EU AI Act and UK GDPR require that humans retain meaningful oversight of AI decision-making, particularly for high-risk and automated-decision systems.

Step 6 — Vendor and third-party AI risk

STEP 06

Apply governance standards to AI in your supply chain

Most organisations use far more vendor-supplied AI than internal models. Your governance obligations follow the function, not the source.

Your organisation is responsible for AI systems it deploys even when they are provided by third parties. Key areas to assess for vendor-supplied AI:

Step 7 — Incident management for AI

STEP 07

Plan for AI-specific failures and misuse scenarios

AI incidents have characteristics that differ from traditional IT incidents — bias emergence, adversarial attacks, data poisoning, and output manipulation require their own playbooks.

AI-specific incidents to plan for include:

For each incident type, your AI incident response plan should specify: detection mechanisms, initial triage steps, escalation path (including board notification thresholds), containment actions, regulatory notification requirements (UK GDPR breach notification within 72 hours to the ICO where applicable), and post-incident review process.

Step 8 — Regulatory mapping

STEP 08

Map your AI systems to current and forthcoming obligations

Regulatory requirements are evolving rapidly. Map your systems now so you are not starting from scratch when enforcement intensifies.

EU AI Act 2024/1689
Phased enforcement from August 2024

Prohibitions in force Feb 2025. GPAI model rules August 2025. High-risk obligations building through 2026–2027. Applies where AI affects EU persons.

UK GDPR / DPA 2018
In force — ICO enforcement active

Article 22 (automated decisions), DPIAs for high-risk processing, accuracy obligations, data minimisation. ICO AI auditing programme is active.

ISO/IEC 42001:2023
Supply chain standard — growing uptake

AI Management System standard increasingly required by enterprise buyers in procurement questionnaires. Certification available via accredited bodies.

NIST AI RMF
US framework — internationally referenced

GOVERN, MAP, MEASURE, MANAGE framework. Often required by US counterparties and increasingly referenced in UK AI assurance conversations.

Need a governance assessment?

This guide gives you the framework. Holster's AI Governance Assessment translates it into a gap analysis, risk register, and prioritised remediation plan specific to your AI estate — with deliverables your board, auditors, and regulators can rely on.

Book a free consultation →