1. Record the system and its owner
Create a record of the purpose, intended users, data sources, providers and permitted actions. Include systems used informally as well as commissioned applications. An employee pasting customer information into a public chat tool can create a data-handling issue even when the organisation has not approved an AI project.
Assign a business owner, a technical maintainer and responsibility for privacy and security review. One person may hold several roles, but the decisions still need to be clear. Define who accepts a residual risk, who approves a change and who can suspend use. A general statement that “the team is responsible” does not resolve an incident.
2. Assess the task’s consequences
Consider what can happen when the system is wrong, unavailable or used outside scope. Drafting an internal paragraph and influencing access to employment are not equivalent tasks. Identify affected people, the opportunity to challenge a result and whether meaningful human review is possible. Keep consequential uses subject to appropriate specialist assessment rather than treating a technical demonstration as approval.
The NIST AI Risk Management Framework organises risk work through Govern, Map, Measure and Manage. ISO/IEC 42001 describes requirements for an AI management system. These references can structure responsibilities and records, but using their language does not establish certification or prove that a particular application is safe.
3. Define an evaluation that fits the task
An evaluation set is a collection of inputs and expected outcomes used to examine system behaviour. Choose examples that reflect the intended work and include difficult cases. For an assistant, assess source support and refusal when evidence is missing. For document extraction, assess each field. For automation, assess the action taken and the handling of failures.
Record error categories and their consequences rather than relying solely on an aggregate score. Check whether different input groups experience different failure patterns where this is relevant and lawful. Do not collect sensitive personal characteristics merely to fill an evaluation table. A proportionate assessment needs a clear purpose, appropriate safeguards and specialist advice where necessary.
4. Address privacy and security together
For UK organisations, UK GDPR and the Data Protection Act 2018 apply where personal data is processed. Determine lawful basis, purpose, minimisation and retention. A data protection impact assessment is required where processing is likely to result in high risk to individuals. Consult the ICO’s AI guidance and obtain qualified advice for the specific use.
Limit permissions, protect credentials and control information sent to external services. Prompt injection occurs when untrusted content attempts to redirect a model’s behaviour. It can arrive through messages, uploaded files or retrieved pages. Do not rely only on instructions telling a model to behave safely; constrain the tools it can call and validate actions independently.
5. Manage changes and incidents
A change to a model, prompt, source collection or connector can alter behaviour. Keep a record of the configuration used, review relevant changes and rerun appropriate evaluations before expanding use. Where a provider controls part of the service, establish how changes are communicated and what fallback is available. Preserve enough information to investigate without retaining unnecessary personal data.
Write an incident procedure that identifies who is contacted, how access is paused and how affected records are located. Distinguish correcting an individual result from fixing the underlying cause. If an event may involve a personal data breach, involve the responsible privacy contact promptly so applicable notification duties can be assessed. Do not wait for a complete technical diagnosis before escalating.
6. Make controls usable in daily work
Give users instructions about permitted inputs, review expectations and reporting errors. Explain the limits relevant to their task, not just a generic warning that AI can be wrong. A reviewer needs time, evidence and authority to reject a result. An approval step that nobody can realistically examine provides little practical protection.
A governance service can help organise system records, acceptance criteria, operating instructions and change review. Agree which controls belong to the service provider and which remain with the organisation. Revisit the controls when the task or consequences change. This guidance is general information; legal compliance and high-consequence decisions require advice from appropriately qualified professionals.
