AI Governance Foundations
Policy and Control Design
Set the rules your organisation will use to govern AI
Glare•9 works with leadership and operational teams to decide how AI should be used, approved, reviewed and challenged. Those decisions are turned into policies, controls and responsibilities that fit the organisation and can be put into day-to-day practice.
A Glare•9 service
Governance design, not a bundle of templates
A policy only helps when it reflects real decisions. The work starts by agreeing which uses of AI are acceptable, how much risk the organisation will tolerate, who can approve higher-risk activity and what evidence is needed to show that controls are working.
The result gives leadership, operational teams, technology, risk, procurement and employees a common way to make and record decisions. It can stand alone or provide the governance foundation that Atlas•9 puts into operation across the AI estate.
What the work establishes
Risk appetite and classification
Criteria for deciding what level of risk the organisation will accept, how AI systems are classified and when additional review is required.
Acceptable use and data handling
Rules for permitted, restricted and prohibited uses, including what personal, confidential or commercially sensitive information may be used with AI systems.
Approval and escalation
Decision routes for new systems and material changes, with clear thresholds for business approval, specialist review, escalation and rejection.
Human oversight
Requirements for checking, challenging, approving or overriding AI-supported work, based on the consequence and context of the decision.
Supplier due diligence
Questions and decision criteria for understanding how suppliers develop, operate, secure and govern AI before procurement, deployment or renewal.
Incidents and exceptions
Routes for reporting, containing and learning from AI-related problems, alongside a controlled process for approving and reviewing exceptions.
Roles and decision rights
Accountability across leadership, system owners, technology, risk, compliance, procurement and users, including who may make each governance decision.
Controls and evidence
A control schedule that identifies the owner, purpose, expected evidence, review frequency and response when a control is missing or ineffective.
Built from the organisation’s operating reality
The starting point is a focused discussion about how the organisation uses AI today, where adoption is expected to grow and which existing policies or approval processes already apply. Relevant documents and responsibilities are reviewed so the new material fits the organisation rather than creating a separate layer of governance that nobody follows.
Existing policies, approval routes and assurance processes are retained where they work. Gaps are addressed without creating a parallel governance structure that teams are unlikely to follow. The depth of the work reflects the organisation’s size, sector, AI exposure and level of risk.
From written rules to a working control system
Each policy is supported by the practical detail needed to apply it. Controls identify what must happen, who owns the action, what evidence should be retained and how often the result needs to be reviewed. Decision, escalation and exception routes are designed around recognisable business roles.
- Policies written for the people expected to use them
- A risk classification and approval method
- Named control owners and evidence requirements
- Review dates, exceptions and escalation points
- Implementation priorities and document ownership
Put the governance foundation into operation with Atlas•9
Atlas•9 is the live AI estate inventory and governance registry. It records the systems in use, their owners, providers, data exposure, human oversight, risk classification, governance status and review dates. It replaces the need for a separate static AI register within this service.
The policies and controls define how the organisation intends to govern AI. Atlas•9 shows how those decisions apply to individual systems and where action is still needed. For organisations that do not use Atlas•9, the service can instead provide a register structure and implementation guidance for an existing governance platform.
What you receive
The final scope is agreed at the outset. It can include review-ready policies, a governance roles and decision-rights model, a risk classification method, a control and evidence schedule, supplier questions, incident and exception processes, and a prioritised implementation plan.
Where Atlas•9 is part of the engagement, the initial AI estate can be populated and configured against the agreed governance approach. This turns the work into a maintained operating record rather than leaving it as a set of documents.
AI Governance Foundations provides governance design, documentation and implementation support. It does not provide legal advice, accredited certification or a guarantee of regulatory compliance.
Explore related Glare•9 services
Combine focused assessments, practical governance documentation and ongoing support as your needs develop.