AI Governance and Policy
Your staff are already using AI, whether or not anyone approved it. The governance question is not whether to allow it but on what terms, with which data, and who carries the decision. King IV puts technology and information governance with the governing body, and POPIA applies the moment personal information reaches a model.
1
Discover
What is already in use
2
Classify
What data may go where
3
Draft
Policy and standards
4
Approve
Board adoption and training
5
Monitor
Register and review cycle
How We Build the Framework
01
Discovery of Current Use
Before writing policy we establish what is actually happening. Staff surveys and system logs usually reveal a longer list of tools in use than management expects, along with the data that has already been pasted into them.
- Survey of tools in current use across departments
- Review of what data has already been shared externally
- Identification of AI features inside existing software
- Assessment of exposure already created
02
Risk and Data Classification
The useful policy question is not which tool but which data. We classify your information so staff have a clear rule about what may be entered into an external service and what must never leave the organisation.
- Data classification tiers with worked examples
- Rules per tier for external AI services
- Special personal information and client confidential data
- Practical guidance staff can apply without asking
03
Policy and Standards Drafting
We draft the policy in language people will actually read, mapped to King IV and POPIA, covering approved tools, prohibited uses, disclosure obligations and who signs off on new tools.
- AI use policy aligned to King IV and POPIA
- Approved and prohibited use cases
- Tool approval and onboarding process
- Disclosure requirements for AI assisted work
04
Approval and Rollout
A policy nobody has read changes nothing. We take it through the approval structure, then run the training that makes it operational, aimed at the departments most exposed rather than at everyone equally.
- Board or committee approval pack
- Role based training sessions
- Acknowledgement and acceptance records
- Communication plan and quick reference guidance
05
Monitoring and Review
AI capability changes faster than an annual policy cycle. We set up the register, the review rhythm and the reporting so the board can see what is in use and what changed.
- AI use register maintained per tool and use case
- Periodic review cycle with defined triggers
- Reporting to the board and audit committee
- Reassessment when a tool materially changes
What You Receive
- Register of AI tools and use cases already in the organisation
- Data classification tiers with rules per tier
- Approved AI use policy ready for board adoption
- Tool approval and onboarding process
- Training material and acknowledgement records
- Board reporting template and review calendar
Indicative Timeline
A governance framework normally takes three to five weeks. Discovery is the variable, because the honest answer about what staff are already using takes longer to surface in some organisations than others.
- Discovery and survey: one week
- Classification and drafting: two weeks
- Review and approval cycle: one to two weeks
- Training and rollout: scheduled after adoption
What We Align To
Governance is mapped to the frameworks your board and regulator already recognise rather than to a generic AI checklist.
King IV
Principle 12 places technology and information governance with the governing body, which is where AI accountability lands.
POPIA
Personal information entering a model is processing, with all the conditions and operator obligations that follow.
ISO/IEC 42001
The AI management system standard, useful where a structured and certifiable baseline is wanted.
NIST AI RMF
A practical risk management framework for identifying, measuring and managing AI risk.
Information Regulator
South African guidance on automated decision making and the rights that attach to it.
Internal Controls
The approval, logging and review controls that make the policy demonstrable rather than merely stated.
Frequently Asked Questions
Our staff already use ChatGPT. Is that a problem?
It depends entirely on what they put into it. Drafting a generic email is low risk. Pasting a client trial balance or employee records into a public tool is a POPIA issue and potentially a confidentiality breach. The policy exists to make that line obvious rather than to ban the tools.
Do we need an AI policy if we do not build AI?
Yes, and arguably more so. Organisations that build AI think about governance by default. Organisations that only consume it through everyday software are the ones where data leaves quietly.
Does POPIA actually apply to AI?
POPIA applies to processing personal information, and entering personal information into a model is processing. If the tool is operated by a third party, that provider is an operator and the obligations that come with that apply.
Who should own AI governance?
Accountability sits with the governing body under King IV. Day to day ownership usually sits with the Information Officer or a designated executive, with a small cross functional group approving new tools.
Will a policy slow everyone down?
A bad one will. We write approval paths that are proportionate, so low risk use of an approved tool needs no permission at all and only new tools or sensitive data trigger a decision.
How does this relate to auditing AI systems?
Governance sets the rules. Assurance tests whether they are followed and whether a model behaves as claimed. Both are offered, and organisations that build or rely on models materially usually need each.
Related Services
This sits inside our AI Services practice. Related work: POPIA Readiness, which covers the wider personal information obligations, and ICT Audit for the governance controls AI policy depends on.
