Knowledge base

AI at the table, people at the helm: governance that works

AI governance is nothing more than agreeing up front who decides what, where the numbers come from and who signs off. Six agreements are enough for most executive teams in midsize companies: data owners, traceable sources, human approval, privacy and retention periods, periodic review, and a separation between flagging, advising and deciding. Put them on paper before the first application goes live, not afterward.

What is AI governance at the leadership table?

AI governance is the set of agreements that determines what AI is allowed to do in your company, with which data, under whose responsibility and with what oversight. Not a forty page policy document, but a set of decisions your leadership team can make in two hours and record on a single page.

The reason is simple. As long as AI summarizes a presentation, the risk is small. The moment AI has a say in pricing, capacity, credit limits or staffing, it is about money and people. That is when you want to know where a number comes from and who carries the decision.

Agreement 1: record who owns which data

One name per source. Payroll belongs to HR, accounts receivable to finance, project costing to operations. That owner decides who gets access and whether a source may be used for an application.

Without ownership you get the familiar situation: everyone may see everything because nobody says no. Work with roles, not with individuals, and record access rights in the same table where you name the sources. Review that table with every new application.

Agreement 2: every analysis traces back to the source

For every number that reaches the table, you should be able to see within one click which system it came from, from which date, and which operation was applied to it. An outcome without a trail back is not management information, it is an opinion with a number in front of it.

Toets dit hard. Neem drie willekeurige uitkomsten uit een rapportage en vraag om de bron. Lukt dat niet binnen een minuut, dan is de toepassing niet klaar voor besluitvorming. In de 45-day pilot is herleidbaarheid daarom een van de vier meetpunten.

Agreement 3: people approve what is sensitive or material

Set two thresholds up front. An amount threshold: above which amount is a human signature always required? For example, everything above € 10.000 in revenue effect or cost. And a topic threshold: which subjects always require human approval, regardless of amount?

That second category covers at least staffing, customer creditworthiness, pricing agreements, supplier selection and anything that goes out to a customer. AI may flag and prepare there. A person signs.

Agreement 4: privacy, security and retention periods are on paper

Three questions you answer before a single source is connected.

  • Which personal data do we touch? Time tracking and absence almost always fall under the GDPR. Determine whether anonymized or aggregated data will do. Often it will.
  • Where is the data held and who can reach it? Record in which region data is processed, whether data is used to train models (the answer should be no), and who has technical access.
  • How long do we keep what? Signals, analyses and intermediate files need a retention period, just like your financial records. Without one, a shadow archive starts to grow.

Agreement 5: check periodically whether it still holds

An application that was reliable in January can be off by June. A system has been replaced, a field is filled in differently, a customer group has been restructured. So put a thirty minute review on the calendar every quarter, with three fixed parts.

  1. Accuracy sample. Trace five signals by hand. Was the number right, was the conclusion right?
  2. Data quality. How complete and how current were the sources? Hours that come in an average of nine days late make every signal nine days older than it looks.
  3. False alarms. How many alerts turned out to be empty? Above 20% the leadership team stops paying attention and the bandwidth gets tightened.

Agreement 6: separate flagging, advice and decision

This is the most important agreement and the easiest one to let blur. Three roles, explicitly separated.

  • Flagging. The AI reports what deviates, factually, with source and size. No recommendation.
  • Advice. A person reads the signal, weighs the context and lays out options with their consequences. That can be a controller, a manager or an advisor.
  • Decision. The leadership team or the authorized officer chooses, signs and carries the consequences.
The sixth seat has no vote. Let that go and you lose not only control but also the ability to explain afterward why something was decided.

Wat een agent feitelijk wel en niet doet, staat beschreven in What are AI agents.

What does the EU AI Act mean for your leadership team?

The EU AI Act is European legislation that classifies AI applications by risk and attaches obligations to each class. Higher risk applications, such as systems used in recruiting, assessing or promoting staff, carry heavier requirements around documentation, human oversight and transparency. On top of that, there is a general obligation to make sure employees who work with AI know enough about it.

For most management applications in midsize companies, think margin monitoring or project risk, a lighter regime applies. That does not release you from knowing which applications you have and what they do. So keep a simple register: name of the application, purpose, sources used, owner, and whether personnel data is involved. This article is not legal advice. Test your own situation with a lawyer or with your trade association.

Checklist for the leadership team, before you start

Eleven points. Go through them in one session and put a name and a date next to each one.

  • A data owner is named for every source, with name and role.
  • Access rights are recorded per role, not per person.
  • Every outcome traces back to the source within one minute.
  • The amount threshold for human approval is fixed.
  • The subjects that always require human approval are on paper.
  • It is recorded which personal data is touched and whether aggregation is enough.
  • The processing location is known and model training on your own data is ruled out.
  • Retention periods for signals and analyses have been set.
  • The quarterly review is on the calendar, with someone responsible for it.
  • Flagging, advice and decision are assigned to different roles.
  • The application is listed in a register, with purpose, sources and owner.

Deze afspraken maak je aan het begin van the 45-day pilot, en ze schalen mee als je toegroeit naar een Digital Business Twin.

Frequently asked questions

Do we need an AI policy if we run just one application?
Not a forty page policy document. But you do need the eleven points from the checklist above, recorded on one page with names and dates. That is enough to start responsibly, and it grows along as you scale up.
May AI help decide about staff?
Help decide, no. Applications around recruiting, assessment and promotion fall under a heavier regime of the EU AI Act, with requirements for human oversight and transparency. Our own standard is stricter than the law: with personnel, AI flags at most, and a person always assesses and decides.
Who is liable if an AI signal turns out to be wrong?
The person or the body that took the decision. That is exactly why flagging, advice and decision stay separate and why every number has to be traceable. If you cannot reconstruct where a number came from, you cannot defend a decision either.
How do we keep the leadership team from trusting the signals blindly?
By tracing five signals by hand every quarter and keeping track of the false alarm rate. As long as people test the outcomes by sampling, healthy doubt stays intact. Take that check away and within six months the critical conversation disappears with it.

Wil je weten welke besluiten bij jou het eerst om betere onderbouwing vragen? Start the decision scan: 10 vragen, 3 minuten, direct een persoonlijk rapport.