Envisago
Design · Governance

How to Set Up AI Governance in Your Company

· 6 min read

How to Set Up AI Governance in Your Company

The operational question is not which AI tools are being used, but who approved them, who can change them, who monitors what they do and who can stop them.

A team builds an AI agent to handle part of a workflow. Another configures one inside an existing platform. A third starts using AI that arrived through a software update.

Each use may make sense on its own. The governance issue appears when those questions are not clearly answered.

As AI moves further into the work, these questions become harder. An agent may be operating within a workflow long after the decision that introduced it. Another team may create something similar without knowing the first exists. An embedded AI capability may change without the workflow owner recognising that the operating conditions have changed.

AI governance therefore reaches beyond which tools the organisation allows. It concerns who has authority to make decisions about AI as part of the operation, what oversight applies and what happens when intervention is required.

What does AI governance mean in practice?

An AI policy can establish expectations. It cannot decide what happens inside a particular workflow.

Consider an AI agent performing work within defined boundaries. Someone has to decide what those boundaries are. Someone needs authority to approve changes. The operation needs to know when human intervention is required and where an issue goes when it cannot be resolved within the workflow.

Governance therefore becomes part of operating design.

AIVOM™ is the practical system for redesigning and continuously improving how your operation works with AI. Its four dimensions are Value, Design, Capability and Performance.

Governance sits within the Design dimension. It concerns the decision rights, boundaries, oversight and escalation surrounding AI-enabled work.

The practical test is whether those things are defined for the AI already operating inside the work.

How do you know what AI needs governing?

Start with what is already operating.

AI may be embedded within an existing platform, deliberately configured by a team or custom-built for a particular purpose. It may support an individual task or operate within a wider workflow.

The distinction matters because governance has to reflect what the AI is doing, not simply which technology is being used.

For each AI use, establish its intended purpose, where it sits in the workflow, who owns the work around it and what authority the AI has. Then establish who can approve changes, intervene or retire it.

This turns an inventory of AI into a view of the governance required around the work.

Who should have decision rights over AI?

Ownership becomes meaningful when it carries authority.

For each AI-enabled workflow, the operation needs clarity about who can approve the AI's use, who can change its boundaries and who can decide that it should no longer operate.

The exact allocation will depend on the organisation and the work. The important point is that the decision rights are explicit.

This becomes particularly important where responsibility crosses functions. A technology team may manage the system while an operations team owns the workflow. Data, security or legal responsibilities may sit elsewhere. Each function can fulfil its own responsibility while ownership of the AI-enabled work remains unclear.

Take a live AI use and ask: who has the authority to change this?

If the answer depends on who happens to be involved at the time, the governance design needs attention.

How do you govern AI agents and agent sprawl?

Agents make the ownership question more visible because they can perform work within a workflow.

One team may configure an agent for a particular workflow while another creates an overlapping agent elsewhere. AI may also arrive embedded within platforms already in use. Over time, agents can accumulate with overlapping purposes, different boundaries and unclear ownership.

Governance needs to cover the lifecycle of each agent.

Who can approve it? Who owns it while it is operating? Who can modify its authority or boundaries? What happens when the workflow around it changes? Who decides when the agent should be retired?

These decisions need to remain connected to the work the agent performs. The workflow, systems and operating conditions around an agent can change after its introduction, so governance has to continue through operation, modification and retirement.

What oversight should be designed into an AI-enabled workflow?

Oversight depends on the role AI has been given.

In AI Augmentation, the person performs the work and AI supports them, with human approval before action. In AI Semi-Automation, AI performs the work within defined boundaries while a person supervises and can intervene. In AI Full Automation, AI operates independently within its design envelope.

The appropriate position is an operating-design choice.

For a particular workflow, determine where human judgement is required, what the person needs to see and the conditions under which intervention is required.

Oversight can then be designed into the workflow rather than added around the AI afterwards.

What should happen when AI needs to be escalated?

Oversight has limited value if nobody knows what happens when it identifies a problem.

An AI-enabled workflow needs defined conditions for intervention and a clear route for decisions that cannot be made within the normal flow of work.

The trigger will vary with the workflow. The operation needs to know who receives the issue, who has authority to make the decision and what happens to the AI while that decision is being made.

Repeated exceptions or changes to the workflow or operating conditions may also indicate that the design itself needs attention. Escalation provides the route for making that decision.

How should AI governance connect to existing controls?

AI does not create a separate operation.

The workflows in which it sits may already be subject to data governance, security, legal, regulatory or operational controls. AI governance needs to connect with those responsibilities.

The practical question is what changes when AI begins performing part of the work.

A control previously exercised by a person may need to move. A decision may require a different intervention point. An existing owner may need authority over an AI-generated action that did not previously exist.

The applicable obligations will depend on the organisation, the workflow and the AI involved. The governance design needs to make their ownership visible within the work.

Where should a leader start?

Start with one part of the operation where AI is already active.

Establish what AI and agents are operating there and where they sit in the workflows. Make ownership and decision rights explicit. Identify the oversight already taking place and where human intervention is required. Define where issues escalate. Then examine how agents are approved, modified and retired.

This gives leadership a practical view of whether governance is present in the work itself. It may show unclear ownership, agents operating without defined boundaries or an escalation route that has not been designed into the workflow.

That shows where to begin.

Effective AI governance makes authority, oversight and escalation explicit within AI-enabled work. It connects those decisions to the workflow and keeps them current as the work changes.

The AI Operating Impact Briefing is your first structured reading of where your operation stands with AI.

The AI Operating Impact Roadmap: what to redesign, in what order and why.

Start your free Briefing at aivom.envisago.com.

Share LinkedIn X Email

The Power of AI. The Potential of People™.

AI Operating Model Design, made practical. From AI deployment to operating impact and enterprise value with AIVOM™. Start with the free AI Operating Impact Briefing at envisago.com.

Start your free Briefing