AI Governance and Policy

Your staff are already using AI, whether or not anyone approved it. The governance question is not whether to allow it but on what terms, with which data, and who carries the decision. King IV puts technology and information governance with the governing body, and POPIA applies the moment personal information reaches a model.

1

Discover

What is already in use

2

Classify

What data may go where

3

Draft

Policy and standards

4

Approve

Board adoption and training

5

Monitor

Register and review cycle

How We Build the Framework

01

Discovery of Current Use

Before writing policy we establish what is actually happening. Staff surveys and system logs usually reveal a longer list of tools in use than management expects, along with the data that has already been pasted into them.

02

Risk and Data Classification

The useful policy question is not which tool but which data. We classify your information so staff have a clear rule about what may be entered into an external service and what must never leave the organisation.

03

Policy and Standards Drafting

We draft the policy in language people will actually read, mapped to King IV and POPIA, covering approved tools, prohibited uses, disclosure obligations and who signs off on new tools.

04

Approval and Rollout

A policy nobody has read changes nothing. We take it through the approval structure, then run the training that makes it operational, aimed at the departments most exposed rather than at everyone equally.

05

Monitoring and Review

AI capability changes faster than an annual policy cycle. We set up the register, the review rhythm and the reporting so the board can see what is in use and what changed.

What You Receive

Indicative Timeline

A governance framework normally takes three to five weeks. Discovery is the variable, because the honest answer about what staff are already using takes longer to surface in some organisations than others.

What We Align To

Governance is mapped to the frameworks your board and regulator already recognise rather than to a generic AI checklist.

King IV

Principle 12 places technology and information governance with the governing body, which is where AI accountability lands.

POPIA

Personal information entering a model is processing, with all the conditions and operator obligations that follow.

ISO/IEC 42001

The AI management system standard, useful where a structured and certifiable baseline is wanted.

NIST AI RMF

A practical risk management framework for identifying, measuring and managing AI risk.

Information Regulator

South African guidance on automated decision making and the rights that attach to it.

Internal Controls

The approval, logging and review controls that make the policy demonstrable rather than merely stated.

Frequently Asked Questions

It depends entirely on what they put into it. Drafting a generic email is low risk. Pasting a client trial balance or employee records into a public tool is a POPIA issue and potentially a confidentiality breach. The policy exists to make that line obvious rather than to ban the tools.

Yes, and arguably more so. Organisations that build AI think about governance by default. Organisations that only consume it through everyday software are the ones where data leaves quietly.

POPIA applies to processing personal information, and entering personal information into a model is processing. If the tool is operated by a third party, that provider is an operator and the obligations that come with that apply.

Accountability sits with the governing body under King IV. Day to day ownership usually sits with the Information Officer or a designated executive, with a small cross functional group approving new tools.

A bad one will. We write approval paths that are proportionate, so low risk use of an approved tool needs no permission at all and only new tools or sensitive data trigger a decision.

Governance sets the rules. Assurance tests whether they are followed and whether a model behaves as claimed. Both are offered, and organisations that build or rely on models materially usually need each.

Related Services

This sits inside our AI Services practice. Related work: POPIA Readiness, which covers the wider personal information obligations, and ICT Audit for the governance controls AI policy depends on.

Discuss AI governance