Software & AI · 7 min read
A practical AI governance framework for mid-sized companies
You do not need a large compliance team to govern AI responsibly. A lightweight framework built on NIST AI RMF and ISO/IEC 42001 that fits a mid-sized business.
· Bhargava Group
AI is already in your business, whether it arrived through a Copilot licence, a vendor’s new feature or an employee’s browser tab. Governance is how you make sure it is used deliberately: with clear ownership, known risks and evidence that it works.
Two frameworks give useful structure without requiring an enterprise budget:
- NIST AI Risk Management Framework (AI RMF 1.0) organises the work into four functions: Govern, Map, Measure and Manage.
- ISO/IEC 42001:2023 defines an AI management system, the policies, roles and continual improvement cycle an organisation uses to run AI responsibly. It can be certified, but its structure is useful even if you never pursue certification.
Here is how we translate them for a company of 50 to 1,000 people.
Govern: decide who decides
- Appoint an AI owner, usually the CIO, CTO or COO, with authority to approve and stop AI use.
- Publish a one-page acceptable use policy: which tools are approved, what data may never be entered, and how to request something new.
- Keep an AI register, a simple list of every AI system in use, its owner, its purpose and the data it touches.
Map: understand each use case
For each entry in the register, answer five questions:
- What decision or task does it support?
- What personal or confidential data does it use?
- Who could be harmed if it is wrong, and how?
- Is a human in the loop before the output takes effect?
- Which laws apply? In Canada that means privacy law at minimum (PIPEDA, and Quebec’s Law 25 for Quebec residents).
Rank use cases as low, medium or high risk. Only high-risk ones need the full treatment below.
Measure: prove it works
- Define success metrics and acceptable error rates before deployment.
- Test on representative data, including edge cases and the groups most likely to be affected.
- Re-test when the model, prompt or data changes.
Manage: control and improve
- Apply access controls and logging proportional to risk.
- Set a review date for every high-risk use case, quarterly or at least annually.
- Keep an incident path: how staff report an AI problem, and who investigates.
Start small
A workable first version is three documents (policy, register and risk rubric) and a quarterly 60-minute review. It can be in place in a month and grown as your AI use grows.
Our teams help organisations set up exactly this, including the register, the policy and the first round of risk assessments, and connect it to the security and privacy controls you already run.
