Govern the decision, not just the tool
AI risk depends on what the system is doing, what information it uses and what happens if it is wrong. A drafting assistant used on public marketing material has a different risk profile from a system influencing employment, credit, safety or regulated decisions.
Assign ownership
Someone should be accountable for the approved use case, source information, quality expectations, human review, supplier relationship and incident escalation. “The AI did it” is not an operating control.
Define approved and prohibited uses
Employees need simple boundaries: which tools are approved, what confidential or personal data may be entered, which outputs require verification and which decisions may not be delegated to AI.
Design human oversight around consequences
Human review should be proportionate to the impact and reversibility of the decision. High-consequence outputs need stronger checking, evidence and escalation than low-risk administrative drafting.
Keep supplier and data questions visible
Understand what happens to prompts and uploaded data, retention, model training terms, access controls and relevant contractual commitments. Governance should be practical enough to influence procurement.
Monitor the workflow after launch
Review accuracy, exceptions, user behaviour, realised benefits and unexpected failure modes. Governance is part of normal management, not a one-time policy document.
Good management does not need more activity. It needs better choices, clearer ownership and evidence about what to do next.
What to do next
If this issue is materially affecting growth, capacity, customer service or management attention, define the business question before choosing the intervention. SBS uses fixed-scope diagnostics where possible so management can obtain a decision-ready view without committing immediately to a large programme.
SBS Ltd