AI Governance – how companies build step-by-step governance for AI

By Mallbutiken · Facts verified September 30, 2026 · Approx. 9 minutes reading time

AI Governance is an organization's practical control system for AI: who is permitted to introduce an AI tool, how it is registered and classified, which risks must be assessed, who approves its use, and how it is followed up. An AI policy is an important component, but governance begins where the policy ends – in responsibilities, registers, controls, and decisions that can be demonstrated after the fact.

Short answer: Start by inventorying actual AI usage. Then, create an AI register, classify the use cases, conduct the appropriate risk and supplier assessments, document the approval, and establish recurring follow-ups. Avoid treating all AI systems as if they carry the same legal or technical risk.

What is AI Governance?

AI Governance is a collective term for an organization's rules, roles, processes, and documentation regarding AI. The purpose is to make usage controllable. It should be possible to answer questions such as: What AI systems do we use? Who owns them? What data is processed? What is our role under the AI Act? Which risks have been accepted? When should the system be reviewed?

It is therefore useful to distinguish between three levels. Policy describes the overall ground rules. Process describes how a new use case moves from idea to approved operation. Evidence is the documentation showing which assessments and decisions were actually made.

Read the guide on AI policy for companies first if you lack internal ground rules.

A practical 8-step AI Governance model

  1. Inventory. Map tools, integrations, built-in AI features, APIs, and local models already in use.
  2. Register. Assign each use case an ID, system owner, business owner, supplier, purpose, and status.
  3. Classify. Assess the organization's role and whether the usage may be subject to bans, high-risk regulations, transparency requirements, or other regulations.
  4. Assess data and risk. Document personal data, trade secrets, security, risk of error, discrimination, human oversight, and operational impact.
  5. Examine the supplier. Check terms, training on customer data, storage, sub-processors, security, incidents, and exit strategies.
  6. Decide. Define who is authorized to approve, set conditions for, pause, or reject a use case.
  7. Implement and train. Link permissions and training to specific roles and usage.
  8. Follow up. Set dates for review and triggers for earlier examination, such as major version updates, new data sources, or changed areas of use.

What should an AI register contain?

Field Example question
Owner Who is responsible for the system and the business value?
Purpose What is the AI actually to be used for?
Data Is personal data, sensitive information, or trade secrets being processed?
AI Act role Is the organization a provider, deployer, or another actor in this specific situation?
Risk class Which legal and internal risk classification has been made?
Human oversight Who reviews results before an important decision or external use?
Supplier Which terms, sub-processors, and security controls apply?
Status Idea, pilot, approved, conditional, paused, or decommissioned?
Review When should the usage be reassessed?

A register is particularly valuable because AI features often appear inside systems the organization already uses. The inventory should therefore not just ask "do you use ChatGPT?" but also capture, for example, AI in CRM, HR systems, analysis tools, customer service, and coding platforms.

Classification and risk assessment are two different things

A common mistake is creating one's own color scale for risk and treating it as a legal classification according to the AI Act. The internal model can help you prioritize controls, but it does not replace the assessment of the regulation's categories and obligations.

A practical risk assessment can cover data protection, information security, hallucinations and data quality, discrimination, impact on humans, transparency, copyright, supplier dependency, and continuity. When personal data involves a likely high risk, a DPIA according to GDPR Article 35 may also need to be considered.

Examine the AI supplier before usage becomes critical

The supplier review should answer more than just whether the service "is GDPR compliant." Check where data is processed, whether customer data is used for training, how data is deleted, which sub-processors are used, what security functions exist, and what happens in the event of an incident or change of supplier.

If the supplier processes personal data on your behalf, a Data Processing Agreement (DPA) may be required. See the guide on DPA. If the AI feature is included in a cloud service, the SaaS agreement is also part of the governance.

Who should decide on AI?

Avoid the model where "IT is responsible for AI" without clearer accountability. A use case may involve IT, data protection, HR, legal, information security, and business owners simultaneously. Therefore, appoint at least one business owner and one system owner, and define which functions must be involved in cases of elevated risk.

A simple approval model can have three outcomes: approved, approved with conditions, or not approved. Document the conditions, for example, that sensitive personal data may not be entered, that output must be reviewed, or that usage may only occur in a specific enterprise version.

AI literacy must be linked to the role

Article 4 of the AI Act requires providers and deployers to take measures to support the development of AI literacy among staff and others using AI systems on their behalf. Consideration shall be given to, among other things, technical knowledge, experience, education, the context of use, and who is being affected.

This suggests role-based training: basic rules for broad usage, in-depth training for system owners, and specialized training for, for example, HR, developers, or individuals who approve new systems.

Checklist for a functional AI Governance system

  • Is there a responsible owner for AI Governance?
  • Do you have an updated AI system register?
  • Is there a process for new tools and new use cases?
  • Do you distinguish between internal risk classification and legal classification?
  • Are GDPR/DPIA and other relevant requirements screened?
  • Are external AI suppliers reviewed before approval?
  • Are approvals and conditions documented?
  • Is human oversight clearly defined?
  • Is training adapted to role and risk?
  • Are there dates and triggers for review?
AI Governance package with AI policy, register, risk assessment, and governance

Build a cohesive AI Governance flow

Mallbutiken's AI Governance Package 2026 includes AI policy, AI system register, risk assessment, supplier assessment, impact assessment, and governance/approval in Word, PDF, and Excel. Price in store: 199 SEK.

See the AI Governance package

Frequently asked questions

Is AI Governance the same as an AI policy?

No. The policy sets the ground rules. Governance also includes inventory, classification, roles, risk assessments, supplier control, decisions, and follow-up.

Must every AI tool undergo the same review?

No. Controls should be proportionate to usage and risk. A simple low-risk tool generally does not require the same depth of review as a system that affects people or critical processes.

Do small companies need AI Governance?

If AI is used in important workflows, basic governance is valuable even in small companies. The model can be simpler, but it should still be clear which tools are approved and who makes the decisions.

Back to blog