AI governance & responsible use

Adopt AI on terms you can defend.

Governance is what turns an AI ambition into a decision somebody is willing to sign: who may deploy what, on which data, under what oversight, and on what evidence.

Concentric governance rings around an AI core, with approval gates on the outer ring and a marked human-oversight node linked to the centre.

Perspective

Most organizations do not need a longer AI policy. They need a working answer to a narrower question — which uses of AI are acceptable here, who decides, and what has to be true before a model influences a regulated outcome. Governance that answers it is short, specific, and enforceable. Governance that does not is decoration, and an inspector will read it that way.

Governance principle

Govern the use, not the technology.

The same model can be inconsequential in one context and decisive in another. Risk sits in the intended use — the decision it informs, the data it touches, and the harm that follows if it is wrong. Classify uses, not tools.

Capabilities

Specialist support, connected to the whole system.

Scope is tailored to the engagement; these are the core areas in which QA4Tech can contribute.

01

Policy & standards

Write policy people can actually apply: permitted and prohibited uses, approval routes, documentation expectations, and the standards beneath them.

02

Decision rights

Name who approves, owns, operates, and reviews each AI use, and make the escalation path explicit before it is needed.

03

AI register & classification

Establish an inventory of AI in use, classified by intended use and consequence, and keep it current as tools spread through the organization.

04

Risk assessment method

Provide a proportionate method that separates assistive use from decisions carrying regulatory, data-integrity, or patient impact.

05

Responsible-use controls

Set expectations for confidentiality, data handling, transparency to users, disclosure, and acceptable reliance on generated output.

06

Framework alignment

Map governance to ISO/IEC 42001, the NIST AI Risk Management Framework, and EU AI Act obligations without building a parallel quality system.

Proportionality

Four tiers of AI use, four levels of control.

A single control set applied to every use of AI either strangles the trivial cases or under-controls the serious ones. Tiering the uses is what makes the rest of the governance proportionate.

01

Assistive

Drafting, summarizing, or reformatting, where a competent person reviews the whole output before use. Controls focus on confidentiality, competence, and disclosure.

02

Analytical

AI organizes, ranks, or highlights information that a person then interprets. Controls focus on data suitability, reproducibility, and reviewer competence.

03

Decision-influencing

Output materially shapes a regulated decision. Controls focus on validation, evaluation evidence, monitoring, and documented human review.

04

Autonomous

The system acts without a person in the loop. Controls focus on constraints, fail-safe behaviour, monitoring, and the ability to reverse what was done.

Governance artefacts

What a working AI governance framework contains.

The set below is the practical minimum for a regulated organization. Each item exists because a specific question has to be answerable — by an owner, an auditor, or an inspector — without a project archaeology exercise.

  • An AI use policy and an acceptable-use standard written for the people who will follow them
  • An AI register recording intended use, owner, data, model or service, and risk class
  • An assessment and approval workflow that plugs into existing governance rather than beside it
  • Third-party expectations covering supplier AI, subprocessors, model substitution, and notice of change
  • Human oversight requirements proportionate to the decision, with the reviewer competence to match
  • Incident, escalation, and withdrawal routes for AI behaving outside its intended envelope
  • Metrics and management-review inputs, so oversight is visible above the project level

Approach

Context first. Evidence throughout.

A clear sequence keeps the work rigorous while avoiding unnecessary process.

  1. 01

    Start from the use

    Inventory what is already happening, including the tools that arrived without an approval, and describe each use in terms of the decision it touches.

  2. 02

    Set the threshold

    Agree where control has to tighten, and say so in language that a project lead can apply without asking for an interpretation.

  3. 03

    Build the route

    Design the assessment, approval, and oversight path so the compliant option is also the fastest one available.

  4. 04

    Make it survive contact

    Pilot the framework on live use cases, fix what proves unworkable, and connect the outputs to management review.

Deliverables

What the engagement leaves behind.

Documents that are owned, adopted, and usable — not a framework that has to be translated before anyone can act on it.

  • AI policy and supporting standards, sized to the organization rather than to a template
  • A populated AI register with agreed risk classification and named owners
  • An assessment template and approval workflow integrated with existing governance
  • A RACI covering AI approval, ownership, operation, and oversight
  • A gap analysis against ISO/IEC 42001 and applicable regulatory expectations
  • A prioritized implementation plan with owners, sequencing, and realistic effort

Reference frameworks

What each framework is actually used for.

Frameworks are selected for the job they do in your context. None of them is adopted wholesale simply because it exists.

ISO/IEC 42001
Management-system structure for AI, used where a formal AI management system or certification is the goal.
NIST AI Risk Management Framework
Vocabulary and functions for characterizing AI risk where a lighter, non-certifiable structure is the better fit.
EU AI Act
Obligation mapping by role and risk class, including how it interacts with medical device and clinical regulation.
ICH Q9(R1)
Quality risk management principles applied to AI-specific failure modes and to the formality of the assessment itself.
Existing GxP quality system
The anchor point. AI governance extends the quality system already in place instead of running alongside it.

These are examples, not a complete list. The frameworks and criteria that apply to a particular engagement are identified and agreed as part of defining its scope.

Typical applications

Where this work can apply.

  • A first AI policy for a regulated organization
  • AI use spreading faster than oversight
  • ISO/IEC 42001 readiness and gap analysis
  • EU AI Act role and obligation mapping
  • Supplier and partner AI governance expectations
  • Board and management-review reporting on AI

Start a conversation

Bring the right level of assurance to the next decision.

Begin with a focused discussion about context, risk, evidence, and the outcome you need.

Discuss AI Governance