Skip to main content

AI Governance

AI governance for listed companies

Listed and regulated enterprises need AI governance that produces evidence, not just policy.

CAPTIVOLT INSIGHTS · Published · Updated · 3 min read

Executive summary

Listed and regulated enterprises need AI governance that produces evidence, not just policy. Effective governance starts with AI system inventory, risk classification, use-case intake, control ownership, monitoring, and leadership oversight. When the board, the auditor, or the regulator asks what AI is running and who owns its risk, a policy document is not an answer; a populated register is.

The problem

AI adoption in most enterprises has outrun oversight. Teams deploy copilots, vendors embed models into platforms, and business units experiment, while governance consists of a policy PDF written eighteen months ago. The gap becomes visible at the worst moments: an audit, a regulatory inquiry, a board question, or an incident. The question is never whether the policy exists; it is whether the organisation can produce evidence of control.

A practical framework

  1. 01

    Start with inventory: a living register of every AI system, its owner, model, data sources, and integrations. You cannot govern what you have not counted.

  2. 02

    Classify risk per system: privacy, safety, fairness, explainability, business impact. Proportionate controls follow classification.

  3. 03

    Operate a use-case intake: new AI initiatives enter through a defined gate with defined questions, not through procurement side doors.

  4. 04

    Assign control ownership: every control has a named owner, a cadence, and an evidence requirement.

  5. 05

    Monitor in operation: governance that ends at approval has governed nothing; behaviour, drift, and incidents need ongoing oversight.

  6. 06

    Report to leadership: a defined cadence that gives boards decision-grade visibility, mapped to frameworks such as ISO 42001 where relevant.

Going further

Who holds which decision

The operating model in brief. The worked version, with decision rights layer by layer, is in the NSE-listed company case study.

Board and audit committee

Oversight of the portfolio and its risk appetite, served by a standing pack rather than a presentation assembled for each meeting.

AI council

Funds, pauses and stops use cases against the classification and the evidence behind it.

Accountable business owner

One per system, accepting residual risk personally, which is precisely what a committee cannot do.

Delivery and run teams

Build, release against the gate, and operate. They propose; they do not accept risk on the organisation’s behalf.

The evidence lifecycle

Governance produces evidence or it produces nothing an auditor can use. Evidence has a lifecycle, and most programmes only manage its first stage.

Create

Produced by the work at the moment the control operates (the evaluation run, the approval, the incident record), rather than written afterwards for the meeting.

Attach

Bound to the system and the decision it evidences. Evidence sitting in a shared drive evidences nothing in particular.

Retain

Kept to the schedule of the decision it supported, not to the lifetime of the platform that produced it.

Review

Given a date. An approval of last year’s system is not an approval of this one, and exceptions expire.

Produce

Retrievable on request and reconstructable by somebody who was not there. This is the test the rest of the lifecycle exists to pass.

Retire

When a system is decommissioned its evidence is not. The record outlives the thing it describes.

Practical implications

  • Evidence, not policy, is the unit of governance.
  • Inventory and risk classification come before everything else.
  • Every control needs a named owner and an evidence trail.
  • Governance must survive an audit, not just a steering committee.

About this article

Author
Captivolt Insights
Published
· updated

References

  1. ISO/IEC 42001:2023 (Artificial intelligence management systems) · International Organization for Standardization