Most of what an organisation runs on AI is below the cloud line. Governance is knowing what is down there, who authorised it, and what stops it.
A policy nobody follows is not governance. These are the artefacts that decide whether a control exists in practice.
Written around how your organisation actually works, not adapted from a template. It names which uses are permitted, which are restricted, and which are barred.
Every live and planned AI use, rated by blast radius, with a named owner against each entry rather than a department.
Who approves an AI use case, who monitors it, and who can switch it off. The last one is the question most organisations cannot answer.
Governance is not a document, it is a set of controls that fire. The test is not whether a policy exists. It is whether anything happens when the policy is breached.
The control catalogue cites POPIA where POPIA applies, including section 71 on automated decision-making, rather than retrofitting an international framework after the fact.
For organisations serving EU customers, the EU AI Act reaches you whether or not you are established there. Article 50 transparency duties have applied since 2 August 2026.
Two hours, scored against the catalogue, and a written scorecard you keep.