AI Governance Foundations

Policy and Control Design

Set the rules your organisation will use to govern AI

Glare9 works with leadership and operational teams to decide how AI should be used, approved, reviewed and challenged. Those decisions are turned into policies, controls and responsibilities that fit the organisation and can be put into day-to-day practice.

A Glare•9 service

Governance design, not a bundle of templates

A policy only helps when it reflects real decisions. The work starts by agreeing which uses of AI are acceptable, how much risk the organisation will tolerate, who can approve higher-risk activity and what evidence is needed to show that controls are working.

The result gives leadership, operational teams, technology, risk, procurement and employees a common way to make and record decisions. It can stand alone or provide the governance foundation that Atlas9 puts into operation across the AI estate.

What the work establishes

  • Risk appetite and classification

    Criteria for deciding what level of risk the organisation will accept, how AI systems are classified and when additional review is required.

  • Acceptable use and data handling

    Rules for permitted, restricted and prohibited uses, including what personal, confidential or commercially sensitive information may be used with AI systems.

  • Approval and escalation

    Decision routes for new systems and material changes, with clear thresholds for business approval, specialist review, escalation and rejection.

  • Human oversight

    Requirements for checking, challenging, approving or overriding AI-supported work, based on the consequence and context of the decision.

  • Supplier due diligence

    Questions and decision criteria for understanding how suppliers develop, operate, secure and govern AI before procurement, deployment or renewal.

  • Incidents and exceptions

    Routes for reporting, containing and learning from AI-related problems, alongside a controlled process for approving and reviewing exceptions.

  • Roles and decision rights

    Accountability across leadership, system owners, technology, risk, compliance, procurement and users, including who may make each governance decision.

  • Controls and evidence

    A control schedule that identifies the owner, purpose, expected evidence, review frequency and response when a control is missing or ineffective.

Built from the organisation’s operating reality

The starting point is a focused discussion about how the organisation uses AI today, where adoption is expected to grow and which existing policies or approval processes already apply. Relevant documents and responsibilities are reviewed so the new material fits the organisation rather than creating a separate layer of governance that nobody follows.

Existing policies, approval routes and assurance processes are retained where they work. Gaps are addressed without creating a parallel governance structure that teams are unlikely to follow. The depth of the work reflects the organisation’s size, sector, AI exposure and level of risk.

From written rules to a working control system

Each policy is supported by the practical detail needed to apply it. Controls identify what must happen, who owns the action, what evidence should be retained and how often the result needs to be reviewed. Decision, escalation and exception routes are designed around recognisable business roles.

  • Policies written for the people expected to use them
  • A risk classification and approval method
  • Named control owners and evidence requirements
  • Review dates, exceptions and escalation points
  • Implementation priorities and document ownership

Put the governance foundation into operation with Atlas•9

Atlas9 is the live AI estate inventory and governance registry. It records the systems in use, their owners, providers, data exposure, human oversight, risk classification, governance status and review dates. It replaces the need for a separate static AI register within this service.

The policies and controls define how the organisation intends to govern AI. Atlas9 shows how those decisions apply to individual systems and where action is still needed. For organisations that do not use Atlas9, the service can instead provide a register structure and implementation guidance for an existing governance platform.

Explore Atlas9

What you receive

The final scope is agreed at the outset. It can include review-ready policies, a governance roles and decision-rights model, a risk classification method, a control and evidence schedule, supplier questions, incident and exception processes, and a prioritised implementation plan.

Where Atlas9 is part of the engagement, the initial AI estate can be populated and configured against the agreed governance approach. This turns the work into a maintained operating record rather than leaving it as a set of documents.

AI Governance Foundations provides governance design, documentation and implementation support. It does not provide legal advice, accredited certification or a guarantee of regulatory compliance.

Explore related Glare9 services

Combine focused assessments, practical governance documentation and ongoing support as your needs develop.

View all Glare9 services