Follow us on LinkedInfor the latest from Zavior
Zavior
For Business

What is AI governance and how do you start?

AI governance keeps an organisation's use of AI lawful and accountable. Start with four artefacts: an AI inventory, an acceptable-use policy, a risk process and vendor checks.

By Sean Teh · Head Of Growth, Zavior

6 min readInsight
What is AI governance and how do you start?

AI governance is the set of policies, roles and controls that keep an organisation's use of AI lawful and accountable. It covers the tools staff use, the models you build and the vendors you buy. A minimum programme has four artefacts: an AI inventory, an acceptable-use policy, a risk-assessment process, and vendor checks.

What does AI governance actually cover?

Three surfaces. The AI your staff use day to day (chat assistants, coding copilots, meeting summarisers, the transcription tool marketing signed up for without telling anyone), the models your own teams build or fine-tune, and the AI embedded in products you buy from vendors. A programme that covers one surface and ignores the other two is paperwork about a corner of the problem, not governance.

Most organisations fixate on the second surface, because "AI governance" sounds like something for companies that train models. In practice the first surface is the widest exposure. Staff adopt tools faster than any policy cycle can keep up with, and every prompt pasted into a free consumer tool is data leaving your control without a contract behind it. The third surface is the quietest. Your HR platform and your CRM have both added AI features somewhere along the way, mostly without asking you first, which means your vendor risk changed while your vendor list did not. An applicant-screening feature inside an HR platform is making calls about people on your behalf; if it appears on no list anywhere, nobody is accountable for what it does.

The transcription tool nobody procured is still processing your client calls.

Which frameworks exist?

The anchor is ISO/IEC 42001, published in December 2023, the first certifiable AI standard. Certifiable is the operative word. An accredited auditor can examine your AI management system and attest to it, rather than taking your word for it. Almost everything else in the field is guidance you apply to yourself and mark your own homework against.

That split matters more than the content of any individual framework. Voluntary guidance shapes how your organisation thinks about AI risk. A certifiable standard produces proof a customer can rely on without inspecting you personally. Which you need first depends entirely on who is asking. If nobody outside the organisation is asking yet, start with guidance and keep the audit fees in your pocket. If enterprise or government buyers are already sending questionnaires, the calculus flips. The two families are not rivals, either. Guidance now and a standard later is the normal path, and the work transfers.

Our companion pieces AI·02 and AI·03 cover ISO 42001 in detail and compare it with NIST's framework.

What are SG and AU regulators doing?

Publishing guidance rather than passing AI statutes. Singapore's IMDA maintains the Model AI Governance Framework. Australia's Department of Industry, Science and Resources released the Voluntary AI Safety Standard in September 2024. Neither instrument binds anyone, and both are free to download.

Voluntary does not mean ignorable. Each document tells you what its government considers responsible AI practice, which is also the benchmark tender evaluators and enterprise procurement teams in that country will reach for when they need something to assess you against. Aligning early is cheaper than retrofitting after a flagship customer sends the questionnaire, because retrofitting always happens on the customer's timeline rather than yours.

Whether either government converts voluntary guidance into binding law is the live planning question, and it is worth tracking rather than assuming either way.

What do you do first?

Build four artefacts, in this order.

  1. An AI inventory. One list of every AI tool, model and vendor across all three surfaces, with a named owner for each entry. This is the artefact everything else depends on.
  2. An acceptable-use policy. What staff may and may not put into which tools, kept to a page staff will actually read. Client data and anything commercially sensitive get named explicitly, with the approved alternatives listed next to the bans.
  3. A risk-assessment process. A repeatable way to look at each new AI use case before it goes live, proportionate to what the use case touches. A chatbot drafting internal memos and a model screening job applicants should not get the same form.
  4. Vendor checks. A short set of questions you ask before buying AI, or before renewing with a vendor that has quietly added it: what data is processed, where it is stored, who can access it, and whether it trains anyone's model.

The order is deliberate. You cannot write an honest acceptable-use policy for tools you do not know exist, and you cannot assess risk on systems missing from the inventory. Start with the list. It almost always names tools nobody signed off on, which is exactly the point.

Expect the inventory to be wrong within a month. That is normal. It is also why the fourth artefact matters: vendor checks are how new entries reach the list before they reach production, instead of eighteen months afterwards.

Resist the urge to write more than this in year one. A register nobody maintains and a policy nobody reads are worse than absence, because they record what you claimed to be doing and were not.

Zavior keeps all four artefacts in one register, so the inventory and everything hanging off it stays current instead of dying in a shared drive.

Frequently asked questions

Is AI governance legally required?

Not as a standalone obligation in Singapore or Australia; both governments currently steer through voluntary instruments, the Model AI Governance Framework and the Voluntary AI Safety Standard. Existing law still applies to what your AI does, though. A hiring decision or a credit decision does not stop being regulated because a model made it.

Who should own it?

One named senior person with the authority to say no to a use case. In many organisations that is whoever already owns security or data protection, supported by legal and by the teams actually building with AI. Committees without a single accountable owner produce minutes, not governance.

Does it apply if we only use ChatGPT?

Yes. Staff tools are the first of the three surfaces and usually the leakiest one. You still need the inventory entry, acceptable-use rules for what can be pasted in, and a basic vendor check on how the tool handles your data.

Zavior · AI Governance

The inventory is the artefact everything else hangs off, and the one most organisations get wrong, because they cannot see the shadow tools. Zavior finds the AI your staff already use, the transcription tool and the vendor features nobody logged, then puts guardrails, a readable policy and usage analytics around it. That keeps the list true as tools change, which is the part that fails when it is done by hand.

Book a free 30-minute business assessment →

This is general information, not legal advice.

Sources: ISO/IEC 42001:2023 (ISO); Model AI Governance Framework (IMDA); Voluntary AI Safety Standard, September 2024 (Department of Industry, Science and Resources).

Written by

Sean Teh

Head Of Growth, Zavior

Share

Let us be your Zavior.

Zavior helps Singapore organizations build cyber resilience aligned to SG Cyber Safe, the PDPA, and ISO 27001.

Continue reading