The Modern AnalyticsReturn on Intelligence
Service

Governance and assurance

Governance is not the brake on AI adoption. In every programme I have watched stall at legal review, the absence of governance was the brake.

This is the work that decides whether anything you have built is allowed to go live, stay live, and be defended afterwards to a customer, an insurer, an auditor or a regulator. It is also the gate most organisations reach in week ten, having assumed it was a formality.

What this covers

  • An AI and analytics inventory. What is running, who owns it, what it touches, and what it is allowed to decide. Including the tools people adopted without telling anyone.
  • Model risk, lineage and audit trail. Versioning, provenance, performance monitoring and drift detection, with enough recorded that a decision made eight months ago can still be reconstructed.
  • Authority boundaries for agentic systems. What an agent may do unsupervised, what it must escalate, and how it is stopped. Defined before anything runs, not after something goes wrong.
  • Policy and acceptable use written so people actually read it, and short enough that they do.
  • Regulatory readiness in the markets you operate in, which is rarely only one.
  • Independent assurance of work somebody else delivered, before you sign it off or renew it.

Regulatory readiness, plural

Most guidance on this treats one regime as the whole problem. Organisations working across markets are usually in scope of several at once, and the obligations do not line up neatly.

  • The EU AI Act reaches beyond EU borders the way GDPR does. You are in scope if you place an AI system on the EU market, or if the output of a system you use is relied on within the EU. Its four tiers run from prohibited, through high risk with substantial obligations, to limited risk transparency duties. Employment and worker management, and access to essential services, put more organisations into the high risk tier than any other single use case.
  • India's Digital Personal Data Protection Act changes consent, notice and breach obligations for anyone processing personal data of people in India, which for most of my clients means their own workforce as well as their customers.
  • Sector rules on top. In life sciences, validated systems and data integrity expectations apply to analytics long before anyone mentions AI. In regulated healthcare content, the constraint is not whether an automated step is right but whether the reasoning behind it can be reconstructed months later.

Shadow AI is the usual starting point

Before any of the above, most organisations need to answer a simpler question: what are people already pasting into public AI tools?

An inventory exercise routinely surfaces a dozen systems nobody authorised, and that inventory is the foundation for everything else. It is also the cheapest piece of governance work there is, and the one most often skipped because the answer is embarrassing.

How I approach it

Proportionate, and built from what you already have. A risk register nobody maintains is worse than none, because it creates a record of a control you are not operating.

So the sequence is: inventory first, classify by actual exposure rather than by enthusiasm, write the minimum policy that covers the classification, then instrument the things that need evidence. Six artefacts, most of which you should want anyway.

The organisations that move fastest on AI are not the ones with the least governance. They are the ones who did it early enough that legal review became a formality instead of an ambush.

Where I am careful

I am wary of governance that exists to be shown rather than operated. A forty page policy and a committee that meets quarterly will not survive an actual incident, and it will not satisfy a serious customer questionnaire either.

I am equally wary of classifying everything as high risk to be safe. It sounds prudent and it is expensive, and it trains people to route around the process.

What you get

  • A system inventory and risk classification, documented and dated.
  • An AI policy and acceptable use standard proportionate to that classification.
  • A model risk register with named owners rather than named teams.
  • Human oversight defined as a control, not as a user interface preference.
  • Authority boundaries and rollback for anything that acts without a person in the loop.
  • An audit trail capable of answering a regulator, an insurer or a large customer.

This is general guidance, not legal advice. I work alongside your general counsel or external advisers rather than in place of them. My role is to make the technical and operational reality legible enough for them to advise on, which is usually the part they cannot get from anybody else.

How this connects

This is gate six in the method, and it is the gate that most often stops work that has already been paid for. Running it early costs a fraction of running it late.

It also pairs with AI and agentic transformation, because authority boundaries are an architectural decision and not a policy one. The free gate check will tell you whether this is where you are currently stuck.

Find out where you stand.

A 45 minute call to work out whether you are in scope, and what the first three steps look like.