Independent consultancy · Nairobi, Kenya
ICT & AI consulting

AI governance & responsible AI

Understand how AI is used in your organisation and establish practical rules for its operation. Define acceptable use, information handling, approvals and accountability, with a process for reviewing changes.

How we can help

Staff may use AI to draft correspondence, summarise documents or support analysis before the organisation has agreed common rules. Managers then need to decide what information may be entered, who checks the result and which decisions require approval. These questions become more involved when AI is connected to internal records or operational systems.

Ivany Concepts helps organisations assess AI use and prepare proportionate policies and controls. The work covers an inventory of applications, risk assessment, acceptable-use guidance and human oversight. We review data handling with the relevant internal owners and identify matters requiring specialist input. Responsibilities and review procedures are documented so staff have clear instructions and management can keep the approach current as uses change.

When this may be useful

  • Staff use several AI tools, but the organisation has no consistent record of approved applications or permitted information.
  • A proposed AI system will support decisions or access internal data and needs defined review and approval arrangements.
  • An existing policy is too general for staff to apply and managers need guidance based on actual working situations.

What the work involves

Review AI use and risks

Record current and proposed applications, their users, information inputs and intended outputs. Examine the consequences of errors, inappropriate disclosure or unclear ownership. Prioritise issues according to the context and the controls already in place.

Prepare policies and staff guidance

Draft rules that explain permitted uses, restricted information and approval requirements. Include practical examples drawn from the organisation's work. Clarify what staff should check before relying on an output and where they should raise concerns.

Define oversight and data responsibilities

Set out who approves tools, reviews outputs and owns each application. Work with data and policy owners to examine information handling and record-keeping. Identify questions that require legal, data-protection or other specialist review.

Establish ongoing review

Prepare a process for assessing new tools, material changes and reported incidents. Identify relevant policy or regulatory developments for review with the responsible owners. Set clear triggers for revisiting an application's approval or controls.

How the assignment runs

  1. Establish the current position

    Review applications, existing policies and staff practices. Agree the governance questions and organisational responsibilities within scope.

  2. Draft and review controls

    Prepare policies and oversight arrangements, then test their meaning against real examples with managers and intended users.

  3. Prepare adoption and review

    Finalise guidance through the organisation's approval process. Document ownership, communication needs and the process for reviewing new uses or concerns.

What to prepare

These details will help us understand the starting point and agree a useful scope:

  • A list of known AI tools, intended uses and responsible teams
  • Existing information security, data handling and staff-use policies
  • Access to management, technical and relevant policy or data owners

If some information is still being developed, we can discuss what is available in the first conversation.

Good to know

Questions about this service.

For anything specific to your organisation, get in touch. We can discuss the requirements before you decide on an engagement.

Do we need governance if staff only use AI for drafting?

Drafting still raises practical questions about the information entered, the accuracy of the result and who approves the final text. The guidance can be proportionate to that use, with clear examples staff can follow and a route for asking about unfamiliar situations.

Does this service certify legal compliance?

The service assesses operational practices and helps prepare policies and controls. It does not provide a legal compliance certificate. Questions requiring legal interpretation are identified for the organisation's qualified advisers, and their input can inform the final policy and controls.

How do we keep the policy relevant as tools change?

Assign an owner and define when review is required, including new applications, changes in data access and reported problems. The policy should include a way to record decisions and communicate updates. Relevant external requirements should be checked during those reviews.

Let’s talk about what you need.

Share a little about your project, the challenge you are facing and where you would like some help.

Start a conversation