Security Quotient
Blog/How to Draft an Effective AI Governance Policy
AI Governance

How to Draft an Effective AI Governance Policy

Learn how to build a practical AI governance policy that defines ownership, controls risk, and guides responsible AI use โ€” section by section, with sample language you can adapt.

Featured Image
Indu Krishnaยทยท5 min read

If you've been told to write your organization's AI governance policy, you've probably discovered there's no shortage of articles explaining why AI governance matters and what a policy should cover. What's harder to find is something that actually walks you through writing the document โ€” section by section, with language you can adapt rather than a concept to admire from a distance.

This is that guide. It follows the actual sequence you'd work through when drafting an AI governance policy, from your first meeting to a published document, with sample wording along the way.

Step 1: Find Out What You're Actually Governing

Before writing a single line of your AI governance policy, build an inventory. You cannot govern what you haven't identified, and most companies have more AI in use than anyone realizes โ€” a spreadsheet plug-in, a hiring tool, a chatbot embedded in customer support software nobody flagged as "AI" when it was purchased.

How to do this in practice:

  • Send a short survey to every department: "What AI tools do you use day to day, even informally?" Ask this without blame โ€” you'll get more honest answers.
  • Check recent software purchases and subscriptions for anything AI-related.
  • Ask IT what's been connected via browser extensions or single sign-on in the last year.
  • Note, for each tool: what it does, what data it touches, and who uses it.

You're not writing anything yet. You're building the raw material your AI governance policy will be built on. Skipping this step is the single most common reason AI policies end up disconnected from what employees are actually doing.

Step 2: Set Your Risk Tiers Before You Write Anything Else

Once you have your list, sort each use case into a tier. This single decision shapes almost everything else in your AI governance policy, so do it early.

A simple three-tier structure works for most organizations:

Blog image

If you operate in the EU, or serve customers there, the EU AI Act already defines specific high-risk domains โ€” employment, credit, education, law enforcement among them โ€” that require stricter testing and documentation (EU AI Act, Annex III). Borrowing that list is a reasonable starting point for your own AI governance policy, even outside the EU.

Sample policy language you can adapt:

"AI use cases are classified as Low, Medium, or High risk based on their potential impact on individuals and the business. Medium and High risk use cases require sign-off from [role] before deployment. High risk use cases require a documented risk assessment, updated annually."

Step 3: Write Principles That Actually Do Something

Most AI governance policies list values โ€” fairness, transparency, accountability โ€” and stop there. The problem is a principle with no rule attached doesn't change anyone's Tuesday afternoon.

For each principle, force yourself to answer: what does this actually require someone to do?

Blog image

Write your principles section as a two-column working draft โ€” principle on one side, the rule it enforces on the other โ€” even if you rewrite it into prose later. Every principle in your AI governance policy should be paired with an enforceable rule, not left as an aspiration.

Step 4: Assign Real Owners - By Name or Role, Not by Department

"The AI team" is not an owner. Ownership needs to survive a reorganization and a Friday afternoon incident.

For every tool in your Step 1 inventory, fill in:

  • Owner: who is accountable if this tool causes a problem
  • Approver: who signed off before it went live
  • Reviewer cadence: how often this gets reassessed (monthly for High risk, annually for Low)
  • Escalation path: who this owner calls if something goes wrong

Sample policy language:

"Each AI tool in active use must have a designated Owner, recorded in the AI Tool Inventory. The Owner is responsible for monitoring the tool's performance, ensuring compliance with this policy, and reporting incidents to [Governance Lead / Committee] within [X] hours of discovery."

Step 5: Write Data Rules a Non-Technical Employee Can Actually Follow

This is the section of your AI governance policy that prevents your most common real-world incident: someone pasting something sensitive into a public AI tool because nobody told them not to.

Keep this section short and concrete rather than legally exhaustive. A few lines employees can remember beat ten pages they won't read.

Sample policy language:

"The following must never be entered into a public or free-tier AI tool: customer personal data, financial records, unreleased financial results, source code, or any information marked Confidential. Approved AI tools for handling this data are listed at [link]. If you are unsure whether a tool is approved, ask [contact] before using it."

Pair this with a short, current list of approved vs. prohibited tools. That list will need updating more often than the rest of your AI governance policy โ€” treat it as a living appendix, not a locked-in section.

Step 6: Decide Where a Human Has to Be in the Loop

For every Medium and High risk use case from Step 2, your AI governance policy should answer one question directly: can this tool act without a person checking it first, or not?

Write this as a simple rule per use case, not a philosophical statement.

Sample policy language:

"AI-generated content sent externally (customer emails, marketing copy, public statements) must be reviewed and approved by a human before sending. AI-assisted decisions affecting employment, credit, or access to services must include a documented human review step and may not be fully automated."

Step 7: Build the Monitoring and Incident Section Around Your Existing Process

Don't invent a new incident response process from scratch for your AI governance policy โ€” attach AI incidents to whatever process already exists for security or compliance incidents, so people don't have to learn two systems.

What to specify:

  • What counts as an AI incident (a wrong, biased, or harmful output that reached a real user or decision)
  • Who gets notified, and how fast
  • Whether the tool gets paused automatically or requires a manual decision
  • Where incidents get logged, so patterns are visible over time

Sample policy language:

"Any AI-related incident โ€” including biased, harmful, or clearly incorrect output that reached a customer, employee, or business decision โ€” must be reported to [Governance Lead] within 24 hours using [existing incident process]. The Owner of the relevant tool determines whether it should be paused pending review."

Step 8: Plan the Rollout Before You Publish

A policy nobody has read isn't an AI governance policy โ€” it's a document sitting in a shared drive. Before you publish, decide:

  • Who needs full training (anyone using Medium/High risk tools) vs. who needs a summary (everyone else)
  • How you'll confirm people actually read it โ€” a short quiz or acknowledgment works better than an email nobody opens
  • When you'll revisit it โ€” quarterly is realistic for most companies given how fast AI tools change; annually is too slow

This step matters more than it might seem. The World Economic Forum's 2025 Future of Jobs report estimates that roughly 39% of core workplace skills are expected to change by 2030, largely driven by AI adoption (WEF, 2025) โ€” an AI governance policy trained once at launch will be stale well before your next planned review.

Putting It Together: A Simple Table of Contents

Once you've worked through the steps above, your actual document can follow a short, standard structure:

  1. Purpose and scope
  2. Definitions (what counts as "AI" under this policy)
  3. Principles and the rules attached to each
  4. Risk tiers and classification criteria
  5. Roles, ownership, and approval process
  6. Data handling rules
  7. Human oversight requirements by risk tier
  8. Monitoring and incident response
  9. Training and review cycle
  10. Appendix: current AI tool inventory and approved-tools list (kept separate, updated more frequently)

Keep the appendix genuinely separate from the core AI governance policy. Tools and approvals will change monthly; your principles and process shouldn't need to.

Why This Approach to an AI Governance Policy Works

Most AI governance policies fail not because the principles are wrong, but because nobody translated them into something a person could actually act on in the moment they're using the tool. Skipping straight to prose about "responsible AI" produces a document people nod along to and then ignore.

Working through inventory, risk tiers, and rule-per-principle first โ€” even in rough table form โ€” forces every abstract value into something checkable. That's what turns an AI governance policy from an aspiration into something your organization can actually be audited against, and something an employee can actually follow without calling legal first.

Start with Step 1 this week. You likely already have more AI in use than your current documentation reflects โ€” one widely cited industry survey found that even among companies who prioritize data governance, most had only partially implemented the basic controls needed to manage AI risk responsibly (Stanford HAI, AI Index 2024). You're not behind by starting now โ€” you're behind if you keep waiting for a perfect draft of your AI governance policy before you begin.

Frequently Asked Questions

What is AI governance?

AI governance refers to the policies, processes, standards, and oversight mechanisms that determine how AI systems are developed, deployed, monitored, and retired within an organisation. It covers accountability, risk management, fairness, transparency, and compliance with applicable laws and ethical principles.

What should be included in an AI governance policy?

A solid policy covers: the types of AI your company uses, how AI decisions are made and reviewed, data handling and privacy rules, how bias is detected and addressed, escalation procedures when AI causes harm, and how employees are trained on responsible AI use.

Who in our organization should be responsible for AI governance?

It's a shared responsibility โ€” but someone needs to own it. Typically, a Chief AI Officer, Chief Risk Officer, or a dedicated AI Ethics Committee leads the effort, with input from legal, compliance, IT, HR, and business units. AI governance can't live in just one silo.

How does AI governance apply to ChatGPT and other generative AI tools our employees use?

When employees use generative AI tools at work, companies need policies covering what data can be shared with these tools, how outputs should be reviewed before use, and what tasks are off-limits. Without a policy, sensitive company or customer data can be inadvertently exposed.

Is there a global AI governance standard we can follow?

Not a single universal law yet, but several widely respected frameworks exist โ€” including the OECD AI Principles, UNESCO's AI Ethics Recommendation, NIST's AI Risk Management Framework, and ISO/IEC standards on AI governance. Many organisations use these as a baseline even without legal obligation.

Where do we start if we've never thought about AI governance before?

Start with an inventory: list every AI tool your organisation uses and what it's being used for. Then assess the risk level of each. Focus your first governance efforts on the highest-risk systems โ€” those that affect hiring, lending, safety, or customer rights โ€” before expanding from there.

Request a demo

Reduce human cyber and compliance risks with targeted training.
Get a guided walkthrough โ€” at a time that suits your timezone.

Request a demo โ†’