The framework beneath the work

AI Governance

Most of what an organisation runs on AI is below the cloud line. Governance is knowing what is down there, who authorised it, and what stops it.

What a governance engagement produces

A policy nobody follows is not governance. These are the artefacts that decide whether a control exists in practice.

An AI use policy

Written around how your organisation actually works, not adapted from a template. It names which uses are permitted, which are restricted, and which are barred.

A risk register that is owned

Every live and planned AI use, rated by blast radius, with a named owner against each entry rather than a department.

Decision rights

Who approves an AI use case, who monitors it, and who can switch it off. The last one is the question most organisations cannot answer.

Governance is not a document, it is a set of controls that fire. The test is not whether a policy exists. It is whether anything happens when the policy is breached.

Written for South African conditions

The control catalogue cites POPIA where POPIA applies, including section 71 on automated decision-making, rather than retrofitting an international framework after the fact.

For organisations serving EU customers, the EU AI Act reaches you whether or not you are established there. Article 50 transparency duties have applied since 2 August 2026.

Where it sits in the method

  • The assessment comes first. You cannot govern what has not been inventoried.
  • The programme implements it. Controls are built alongside the system, not after it.
  • The run phase keeps it true. Regulatory ground moves, so the register is re-edition-dated rather than frozen.

Start where you actually are

Two hours, scored against the catalogue, and a written scorecard you keep.

Book the two-hour diagnostic