AI Governance
Know what your staff already feed AI
Nobody approved it, but people across your organization are pasting contracts, patient details, and payroll files into chat tools to get through the day. The tools are useful. That is the problem.
Ask a department head how many AI tools their team uses and you will get a low number. The real number includes the note-taker in the meeting platform, the summarizer built into the customer system, the drafting assistant a manager expensed on a personal card, and whatever a vendor switched on in an update without asking. Some of those tools retain what they are given. Some train on it. The contracts vary, and almost nobody has read them.
None of this is an argument against using AI. It is an argument for knowing where your information goes.
IT21 sets the policy and control layer over AI use: what tools are permitted, what data may be put into them, who decides, and what evidence exists that the rules are followed. Building and deploying AI systems is separate work and sits under AI Solutions & Enablement. This page is the oversight, not the engineering.
The harder territory is decisions. When a model contributes to who gets hired, who gets credit, who gets care, or who qualifies for a service, you need to be able to say afterward how the decision was reached and who reviewed it. Regulators in health care, lending and employment are moving toward that expectation. A logged human review step, defined in advance, is worth more than a policy paragraph promising oversight.
What you get:
- An inventory of the AI tools in use, sanctioned and not, including the ones embedded in software you already licensed
- An acceptable use policy written for your business, short enough to actually be followed
- Rules on what data may leave your environment, tied to the regulations you are already under
- A review step for AI-influenced decisions that affect people: hiring, credit, care, eligibility
- A record showing a board, an examiner, or a customer that AI use here is governed rather than tolerated
Assess is the inventory and the exposure question: which tools, which data, which contracts. Transform is putting the policy, the approved tool list, the vendor review, and the decision-review step into place. Optimize is keeping up, because the tools change monthly and a governance program written once is out of date by the next renewal cycle.
This is governance work of a familiar kind applied to a new class of system. Access, data handling, vendor risk, change control, evidence. The vocabulary is new. The control questions are the ones we have been asking since long before anyone called it AI.
The vocabulary is new. The control questions are not.
[PROOF: AI governance engagement — sector, region, scope, what changed — supply]
The IT Risk & Readiness Assessment can include an AI scope. It is measured against a recognized technology-governance framework, and in this case it tells you what is already in use before you write a policy about it.
- Assess
- Transform
- Optimize
Not sure where you stand? Start with the assessment.
Request the AssessmentWhere to go next
AI governance — a brief
An inventory of the AI tools already in use, a usable acceptable-use policy, data boundaries tied to your obligations, and a logged human review step for decisions about people.
Get the PDF — enter your email
HubSpot form — assessment-request — not configured
Set portalId and forms.assessment-request in src/lib/hubspot.ts.
Start with the IT Risk & Readiness Assessment
A defined engagement, measured against a recognized control framework, that shows you which controls exist, which are documented but not operating, and which are absent — before you commit a budget.

