Fixed fee · Phase 02, Decide

One page of ground rules, a named owner, and a fast route to approve the next use

Last reviewed 21 September 2026

AI Governance and Controls gives a COO or CFO one page of ground rules they can hand to a customer or a board. It states what data may go where, which decisions still need a person, and who approves a new AI use and how fast. It comes with a review checklist and a quarterly review cadence.

Who this is for

  • A customer's security questionnaire asks what your AI policy is and the honest answer is that you do not have one.

  • The board has asked who is accountable for AI use in the business and nobody could point to a name.

  • Staff are already using AI on their own, with customer data, and you would rather have rules than find out later.

  • You have a policy that says no to everything, and people have started working around it.

What you get

A list you can check you received.

  • One page of ground rules: what data may go where, which decisions still need a person, and what is off limits.
  • A named owner for AI use in the business, with what the role does and how much time it takes.
  • An approval route for a new AI use, with who decides and how fast, so the fast lane is written down.
  • A review checklist for anything AI produces before it reaches a customer, a regulator or the board.
  • A quarterly review cadence: what gets looked at, by whom, and what would cause a rule to change.
  • Answers, in your own words, to the AI section of a typical customer security questionnaire.

How it runs

  1. 01

    Inventory: where AI is already used in the business, officially and otherwise, and what data it touches.

    One week

  2. 02

    Drafting with the COO or CFO and the named owner: the one page, the approval route, the checklist.

    Two working sessions, week two

  3. 03

    Test the draft against real AI requests the business has received. If the route cannot approve a good one in days, it is rewritten.

    Week two to three

  4. 04

    Sign-off with the leadership team and the first quarterly review date set.

    One hour, week three

What we will not do in this programme

Governance that is only a gate gets routed around. If your policy has no fast lane for approving a good use, we write one before we write a single rule.

The questionnaire arrives before the policy

The usual way a business of 50 to 500 people discovers it needs AI governance is a customer’s security questionnaire. Somewhere in the middle it asks what your policy on AI use is, what customer data reaches AI services, and who is accountable. The honest answer, in most businesses, is that staff have been using whatever they like for a year and nobody has written anything down. The second usual way is a board member asking the same question in fewer words.

This programme exists to give the COO or CFO a true answer to both, in a form they can hand over.

Why one page

Long policies are not read and are therefore not followed. Ours has to do three things: say what data may go where, say which decisions still need a person, and say who approves a new use and how fast.

The named owner matters as much as the page. A rule without someone accountable for it is a suggestion. The owner is usually the COO or a head of function, and part of the drafting work is writing down what the role actually does and how much of a week it takes.

What the page has to answer

What data may go where is the part the questionnaire cares about. Which decisions still need a person is the part the board cares about. Anything that changes a price, refuses a customer, touches payroll or goes to a regulator keeps a person in the chair, and the page says so. Who approves a new use, and how fast, is the part your staff care about, and it is the part most policies leave out.

A gate without a fast lane is a detour

A business writes a policy that says no to everything without approval, then never approves anything. Within a quarter the staff who wanted to use AI for something sensible are doing it anyway, from personal accounts, with company data, and the policy has made the business less safe than having none.

So we write the fast lane before we write a single rule. A good request from a head of function should be approved in days, by a named person, against written criteria. We test the draft against real requests the business has received recently. If the route cannot approve the good ones quickly, the route is wrong and we rewrite it.

The three weeks

Week one is inventory: where AI is already in use, officially and otherwise, and what data it touches. Expect the list to be longer than the leadership team thinks. Week two is two working sessions drafting the page, the route and the checklist. Week three is the test against real requests, then an hour for sign-off and the first quarterly review goes in the diary.

Where governance efforts stall

They stall when written by someone outside the business who has never seen the actual requests, so the rules are generic and the exceptions are everything. They stall when the checklist for reviewing AI output is so long nobody uses it. They stall when there is no review cadence, so the page is accurate on the day it is signed and wrong by the following spring. The inventory, the one-page limit and the quarterly date are the answers to those three.

After sign-off

Your named owner runs the first quarterly review without us: what has been approved, what was refused, what the checklist caught, whether a rule needs changing. If the inventory turned up recurring work worth costing, some businesses go on to the AI Strategy Roadmap, but the governance programme itself is complete when the page is signed. The approving, the refusing and the quarterly look remain jobs for people in your business.

What usually comes next

Usually the first quarterly review, run by your named owner without us. Where the inventory turns up recurring work, some businesses go on to the AI Strategy Roadmap.

Where this programme applies

The one ask on this page

Ninety seconds now. Thirty minutes if it is worth it.

Take the check, see your score with no email asked for, and decide whether the thirty-minute review is worth your time. If you already know the process, skip the check and tell us.