In brief
- Governance connects business objectives, law, security, technology and domain accountability.
- The effort should match the impact and risk of the use case.
- An inventory, clear roles and evidence-based approvals form the operational foundation.
- Governance continues after launch through changes, incidents and retirement.
Governance makes decisions repeatable
Without a shared process, each team assesses providers, data and risk differently. Good governance specifies what information is required before a decision, who assesses it and which evidence must remain available later.
- What objectives and boundaries apply to AI in the organisation?
- Which use cases require which depth of review?
- Who owns domain quality, technology and ongoing operation?
- Who may approve, restrict or stop a system?
- How are value, errors and change observed?
Not every AI system needs the same process
A writing assistant for public marketing copy has different consequences from a system that ranks applicants or initiates payments. A risk-based process keeps simple cases light and applies additional review and oversight where impact is higher.
- Step 1
Contextualise
Describe purpose, users, data, affected people and possible consequences.
- Step 2
Set review depth
Choose controls based on risk, novelty, reach and reversibility.
- Step 3
Require evidence
Document tests, data flow, accountabilities and the operating plan.
- Step 4
Decide
Record approval, conditions, pilot, rework or rejection transparently.
Three internal risk tiers make review depth concrete
A practical internal classification translates abstract risk into a clear review path. It is assigned to the specific use case and reassessed when it changes; the same tool can therefore fall into different tiers depending on data, users and impact.
This internal company tier is neither an EU AI Act risk category nor the result of a DPIA screening under Swiss data protection law. The three classifications answer different questions and, where relevant, must be documented separately.
- Standard — short approval path
- Public or non-sensitive internal data, no decisions about people and no autonomous actions. Minimum evidence includes an inventory entry, approved tool, purpose, accountable owner and a short quality and data check.
- Elevated — extended specialist review
- Confidential or personal data, external communication, important recommendations, new integrations or bounded system actions. The review adds data flow, privacy and security, representative tests, human control, operations and approval conditions.
- Critical — formal decision
- Significant effects on people, large-scale sensitive data, far-reaching autonomous actions, safety-critical processes or hard-to-reverse harm. This requires in-depth legal, risk and architecture review, documented management approval, strict boundaries, ongoing monitoring and a tested stop and incident plan.
Govern the full lifecycle
Many risks emerge only after a new data source, a model change or expansion to more users. Governance therefore needs explicit control points from idea to retirement.
- Idea and use-case assessment
- Procurement, provider and architecture review
- Pilot with measurement criteria and limited scope
- Production approval with operations and accountable owners
- Monitoring, change and reassessment
- Shutdown, export and verified deletion
A lean governance system starts with five components
A smaller organisation can govern effectively without building a large programme. Visible accountability and a few consistently maintained artefacts matter most.
- A current inventory of AI systems in production and testing
- A practical AI policy for employees
- A tiered assessment and approval process
- Named business, technical, privacy, security and operational roles
- A process for monitoring, incidents, change and exit
Example: Two review paths instead of one marathon
ALESO helps a client establish a fast path for low-risk standard tools and an extended path for uses involving confidential data, people or system actions. Both start with the same short AI inventory entry. Only the extended path adds privacy, security and domain assessments. Governance remains proportionate and traceable.
What to remember
Begin with an inventory, risk tiers, clear roles, an approval point and an operational review. A small system that people consistently use is more valuable than an extensive rulebook disconnected from work.
Sources and further reading
These primary sources provide further detail on definitions, technical foundations or responsible use.
Content reviewed
Reviewed 17 July 2026. General information, not legal advice. The specific legal position and applicable scope must be assessed for each use case.