The AI Risk & Governance Framework

The framework is designed to help organisations move from unclear AI use and unmanaged risk to clearer governance, stronger controls, and systems that can be explained, monitored, and improved over time.

How the Framework Works

01

Classify

Identify where AI is used, what role it plays in decisions and operations, and which risks, responsibilities, or regulatory requirements apply in context.

Govern

02

Put in place the structures needed to manage AI responsibly, including accountability, controls, risk management processes, human oversight, and practical operating rules.

Demonstrate

03

Build the evidence needed to support responsible adoption over time, from documentation and monitoring to traceability, reporting, and ongoing review.

What the Framework Helps With

Where It Can Be Applied

The framework can be applied across different kinds of AI use, from internal experimentation to operational systems and bespoke solutions built around specific business workflows.

Internal AI use across teams and functions.


Decision-support and operational workflows

Bespoke software and AI features built around specific business needs.

Customer-facing or externally deployed AI systems.