AI Governance Checklist for UK Businesses Using Generative AI
Create a practical system for approving AI use, controlling data and permissions, assessing suppliers, protecting people, validating outputs, monitoring changes and stopping unsafe activity.
Fast answer: UK businesses need an AI-use register, named owners, approved purposes, data and supplier checks, risk-based human review, security controls, testing, monitoring, incident response and an exit plan. Apply deeper assessment when AI uses personal data, affects people, creates content, connects to systems or takes consequential actions.

AI Governance Is an Operating System, Not a Policy Document
A policy is necessary, but it cannot identify shadow AI, assign system ownership, test a supplier or recover from a harmful action. Governance connects leadership decisions with operational records and technical controls.
Inventory
Record every AI service, embedded feature, internal model and agent used for business activity.
Ownership
Assign a senior business owner, operational owner and relevant technical, privacy and security roles.
Purpose
Define the approved outcome, users, inputs, outputs, prohibited uses and success evidence.
Impact
Assess effects on people, data, customers, workers, decisions, intellectual property and regulated activity.
Assurance
Review suppliers, architecture, security, performance evidence and contractual responsibility.
Oversight
Set permission limits, human review, approval thresholds, escalation and individual challenge routes.
Testing
Test normal, incorrect, adversarial, incomplete and high-impact cases before release.
Monitoring
Measure errors, overrides, incidents, drift, supplier changes, access and real outcomes.
Exit
Maintain rollback, manual fallback, data return, deletion, migration and retirement controls.
The UK governmentβs AI Management Essentials work focuses on organisational processes rather than certifying individual AI products. Its guidance describes an AI system record containing technical documentation, impact and risk assessments, model analyses and data records.
Step 1Create an AI-Use Register Before Writing More Rules
A central register is the fastest way to identify approved tools, unapproved use, duplicated subscriptions and high-risk activity. Include features embedded in software already used by the business; an AI assistant inside a CRM, helpdesk or office suite is still an AI use.
| Register Field | What to Record | Why It Matters |
|---|---|---|
| System and supplier | Product, feature, underlying model where known, provider and contract owner | Identifies dependency and responsibility |
| Approved purpose | Specific business task, user group and intended outcome | Prevents uncontrolled purpose expansion |
| Inputs and data | Prompts, documents, personal data, confidential data and retrieval sources | Supports privacy, security and data-quality assessment |
| Outputs and actions | Generated content, recommendations, classifications, decisions and system actions | Shows the consequence of error |
| Affected people | Customers, staff, applicants, suppliers, children or vulnerable groups | Determines rights, fairness and review needs |
| Human boundary | What is reviewed, by whom, with which evidence and authority | Prevents nominal or ineffective oversight |
| Risk and approval | Risk tier, assessment references, approver and approval date | Creates an auditable decision |
| Monitoring | Accuracy, incidents, overrides, complaints, drift and supplier changes | Supports continued approval or withdrawal |
Find shadow AI without creating fear
Ask teams which tools they already use, what information they enter and which outputs they rely upon. Provide an approved route for low-risk experimentation. A blanket prohibition can drive use away from visibility rather than stopping it.
Step 2Assign Owners Who Can Stop the System
The ICOβs governance toolkit expects senior management sign-off, a documented privacy framework and assigned technical, operational and data-protection responsibilities. Ownership should remain inside the organisation even when the system is supplied and hosted externally.
Senior business owner
Owns the purpose, budget, accepted risk and decision to continue, restrict or stop the system.
- Confirms the business need
- Approves material risk
- Receives incident and performance reporting
Operational owner
Owns user access, procedures, exceptions, training, output review and day-to-day results.
- Maintains the use register
- Controls purpose changes
- Coordinates manual fallback
Technical and security owner
Owns architecture, identity, permissions, logging, integrations, testing and incident containment.
- Applies least privilege
- Reviews supplier and model changes
- Maintains rollback and kill controls
Data-protection and legal support
Assesses personal data, lawful basis, transparency, rights, automated decisions, contracts and sector obligations.
- Determines DPIA requirements
- Reviews affected-person safeguards
- Escalates residual high risk
No owner, no approval. An AI system should not move into operational use when nobody has authority to restrict access, investigate harm, challenge the supplier or stop the service.
Map the Applicable UK Duties
AI governance in the UK must connect the use case to existing legal and regulatory duties. The correct assessment depends on the data, people, decision, sector, customer relationship and markets involved.
Automated decisions and the Data (Use and Access) Act 2025
The ICO explains that the 2025 Act changed the UK rules for significant automated decisions using personal data and expanded the lawful bases that may be available when appropriate safeguards are applied. Special-category data remains more protected. Organisations should use current ICO guidance and obtain specialist advice for high-impact decisions.
Check EU AI Act scope before 2 August 2026
The EU AI Act entered into force on 1 August 2024. Some provisions, including AI literacy, already apply, while major additional obligations become applicable from 2 August 2026. UK organisations that provide or deploy systems in the EU, or whose outputs are used there, should establish their role and obligations rather than assuming UK location removes them from scope.
This checklist is not a substitute for legal advice. Use it to identify governance evidence and escalation points, then obtain appropriate advice for significant automated decisions, regulated activity, employment, sensitive personal data, consumer-facing agents and cross-border deployment.
Assess Data, People and Decision Impact
| Area | Governance Question | Evidence | Escalation Trigger |
|---|---|---|---|
| Purpose | Is the outcome specific, necessary and compatible with the data collected? | Approved purpose statement and alternatives considered | The use expands beyond the original reason |
| Personal data | Which personal data is used, generated, inferred or retained? | Data map, lawful basis, notices and retention | Special-category, children's or large-scale data |
| People affected | Who may gain, lose, be profiled, excluded or treated differently? | Stakeholder and impact analysis | Legal, employment, financial or similarly significant effect |
| Fairness | Does performance differ across relevant groups or operating contexts? | Representative tests, complaints and outcome monitoring | Unexplained disparity or harmful feedback loop |
| Accuracy | What does accuracy mean for personal data and for system performance? | Source quality, validation, corrections and confidence | Incorrect records or decisions persist |
| Rights and challenge | Can people obtain information, correct data and challenge an outcome? | Notice, request process, review route and response records | The system cannot support applicable rights |
Complete the DPIA early when high risk is likely
The ICO says a DPIA must be completed before high-risk processing begins. Use it to document purpose, necessity, proportionality, risks, training and the technical and organisational controls applied. If residual high risk cannot be mitigated sufficiently, consultation with the ICO may be required before processing starts.
Step 5Review the Supplier and the Full AI Supply Chain
A familiar brand or paid licence does not answer how business data is used, which model is involved, where processing occurs or how a material change will be communicated.
| Question | Required Evidence | Unacceptable Gap |
|---|---|---|
| What service and model are supplied? | Product architecture, versions, subprocessors and dependencies | The supplier cannot identify material components |
| How is submitted data used? | Contractual terms for processing, retention, training and deletion | Confidential inputs may be reused without control |
| Where is data processed? | Locations, transfer mechanism and subprocessors | Unknown or unsupported international processing |
| How is access controlled? | Identity, SSO, MFA, roles, API permissions and administrative controls | Shared accounts or unrestricted connectors |
| How is performance evidenced? | Use-case-relevant testing, limitations and error analysis | Only general marketing accuracy claims |
| How are incidents handled? | Notification, investigation, evidence, support and responsibility | No timely route for security or harmful-output incidents |
| How are changes controlled? | Release notices, model changes, deprecation and retesting support | Material behaviour can change without notice |
| How can the business exit? | Export, deletion, portability, continuity and termination terms | Records, prompts or outputs cannot be recovered or deleted |
Where several AI tools, suppliers and existing systems are involved, an AI business systems audit can identify duplicated tools, shadow use, data dependencies, process gaps and priority controls before a procurement decision.
Step 6Control Data, Generated Content and Intellectual Property
Input controls
Define which information may be entered, retrieved or uploaded.
- Prohibit credentials and unnecessary personal data
- Classify confidential and client information
- Use approved retrieval sources
- Apply redaction and minimisation where appropriate
Output controls
Set review and publication requirements according to consequence.
- Verify factual claims against primary sources
- Check names, figures, citations and legal statements
- Review bias, tone and affected groups
- Record approval for sensitive external content
Copyright and licensing
Document how source material and generated output may be used.
- Check licences for source and reference material
- Avoid requests to reproduce protected works improperly
- Record human contribution where ownership matters
- Review supplier indemnities and exclusions
Records and retention
Retain enough evidence for the decision while avoiding uncontrolled archives.
- Set prompt, output and log retention by purpose
- Support correction and deletion obligations
- Separate development data from live business data
- Delete obsolete test and exported datasets
Design Meaningful Human Oversight
Human review is not meaningful when the reviewer sees only a confidence score, lacks authority to disagree or is expected to approve hundreds of outputs without enough time.
| Control | Required Practice | Evidence to Retain |
|---|---|---|
| Competence | Train reviewers on the system, task, data, limits and likely failure modes | Role-based training and assessment |
| Evidence access | Show the information used, missing data and contrary signals | Review interface and source references |
| Authority | Allow the reviewer to reject, correct, escalate and stop the outcome | Permissions and escalation procedure |
| Time and workload | Give reviewers realistic capacity for the consequence involved | Queue size, handling time and backlog |
| Challenge route | Provide affected people with a clear way to question or correct outcomes | Notices, requests, reviews and responses |
| Override monitoring | Record when people disagree with the system and why | Override rate, reason and subsequent outcome |
Add stronger boundaries for AI agents
Agentic systems can plan and act across tools. The NCSCβs 2026 guidance recommends starting small, using agents for low-risk tasks and applying established security controls from the outset.
- Use the minimum tools, data and permissions required.
- Set transaction, time, quantity and destination limits.
- Require confirmation before financial, legal, customer or account changes.
- Validate tool parameters outside the model.
- Log the goal, plan, retrieved data, tool calls, approvals and outcomes.
- Provide a kill switch and tested manual process.
Test Performance, Security and Failure Handling
| Test Group | Examples | Required Outcome |
|---|---|---|
| Normal cases | Representative approved inputs and ordinary users | The intended output is useful and traceable |
| Incomplete and ambiguous cases | Missing fields, contradictory documents and uncertain instructions | The system asks, abstains or routes to review |
| Incorrect and harmful cases | False claims, biased examples and unsafe recommendations | Controls detect, prevent or contain harm |
| Adversarial cases | Prompt injection, malicious files, manipulated retrieval and excessive requests | Instructions, data and tools remain protected |
| Rights and complaint cases | Correction, access, objection and challenge requests | The organisation can locate evidence and respond |
| Failure and outage cases | Unavailable model, broken connector, timeout and partial transaction | The process fails safely and uses the fallback |
UK AI Governance Readiness Checker
Assess the organisational controls around one AI system or use case. The checker does not determine legal compliance or certify the product.
AI Governance Control Assessment
Select the current state of the organisation. The result identifies whether the system is ready for approval, needs a controlled pilot or should remain blocked.
AI Governance Checklist for UK Businesses
| Control | Minimum Evidence Before Approval | Review Trigger |
|---|---|---|
| AI-use register | System, supplier, purpose, owner, data, users, actions, risk and status | New tool, feature, model or expanded use |
| Purpose and necessity | Defined outcome, alternatives considered and prohibited uses | New decision, team, customer or data source |
| Ownership | Senior, operational, technical, security and privacy responsibilities | Role, supplier or organisational change |
| Data protection | Data map, lawful basis, notices, minimisation, retention and DPIA decision | New personal data, profiling or affected group |
| People and fairness | Affected-person analysis, representative tests and challenge route | Complaints, disparity or material outcome change |
| Supplier assurance | Contract, data use, security, subprocessors, changes, incidents and exit | Model, terms, hosting or subprocessor change |
| Security | Identity, least privilege, connector scope, logging and threat testing | New integration, permission, vulnerability or incident |
| Human oversight | Reviewer competence, evidence, authority, workload and override records | High approval rate, backlog or reduced review time |
| Testing | Normal, edge, harmful, adversarial and failure-case results | Model, prompt, retrieval, workflow or user change |
| Monitoring | Performance, errors, overrides, complaints, incidents and business outcomes | Threshold breach or unexplained drift |
| Incident response | Containment, evidence, notification, correction and restart procedure | Harmful output, data event or unauthorised action |
| Exit and retirement | Manual fallback, export, deletion, migration and access revocation | Supplier failure, unacceptable risk or contract termination |
Use simple risk tiers
| Tier | Typical Use | Approval Level | Examples of Additional Control |
|---|---|---|---|
| Low | Internal drafting using non-sensitive information with no decision or system action | Approved tool and manager-owned procedure | Accuracy review and prohibited-data rules |
| Moderate | Customer content, internal knowledge retrieval, classification or recommendations | Business owner plus security, data or compliance review as relevant | Representative testing, logs and meaningful human review |
| High | Personal data, significant decisions, vulnerable groups, regulated activity or connected actions | Senior approval with specialist legal, privacy, security and technical assessment | DPIA, impact assessment, strict permissions, assurance and formal monitoring |
Monitor the System After Approval
Approval is time-limited. Models, terms, prompts, data, users and connected systems change. The organisation should be able to identify when the approved evidence no longer represents current operation.
- Review output accuracy and business usefulness.
- Track human overrides, disagreements and abstentions.
- Record complaints, corrections and affected-person challenges.
- Monitor unusual access, prompt injection and unauthorised tool use.
- Review supplier, model, terms, retention and subprocessor changes.
- Reassess when purpose, permissions, data or user groups expand.
- Stop the system when residual risk exceeds the approved boundary.
Define AI-specific incident categories
| Incident | First Action | Evidence to Preserve |
|---|---|---|
| Personal or confidential data exposure | Contain access and follow the data or security incident process | Input, output, account, model, recipient and retention information |
| Harmful or materially incorrect output | Stop the affected use and correct downstream records or communications | Prompt, sources, output, reviewer and affected outcome |
| Unauthorised system action | Disable tools or credentials and verify destination systems | Goal, plan, tool calls, parameters, approvals and results |
| Prompt injection or manipulated retrieval | Isolate the content source and restrict connected actions | Malicious content, model response and control bypass |
| Performance drift or unfair outcome | Pause the decision route and reassess data and affected groups | Current and baseline outcomes, overrides and complaints |
| Supplier change or outage | Switch to the fallback and assess continued approval | Change notice, unavailable functions, affected records and recovery |
Discover
Identify tools, embedded features, owners, users, data and connected systems.
Classify
Define purpose, affected people, permissions, actions and initial risk tier.
Assess
Review data protection, supplier, security, fairness and cross-border obligations.
Control
Set access, human review, testing, logging, fallback and incident procedures.
Pilot
Test representative, harmful, adversarial and failure cases with limited users.
Approve
Record evidence, residual risk, conditions, review date and stop criteria.
After the organisation has identified its systems, use cases and priority risks, BhavProβs AI integration advisory can help assess architecture, supplier dependencies, governance controls and implementation sequencing.
Need to turn scattered AI use into an owned operating model?
BhavPro can help map the AI estate, define approval routes, assess data and system dependencies, establish controls and create a practical implementation roadmap.
AI Governance FAQs for UK Businesses
What is AI governance for a UK business?
AI governance is the system of ownership, policies, records, controls, testing, monitoring and review used to keep AI use aligned with business objectives, legal duties, security requirements and acceptable risk. It covers purchased tools as well as systems developed internally.
Does every business need an AI-use register?
A central register is a practical starting point for any organisation using AI. It should record the tool, purpose, owner, supplier, data, affected people, permissions, decisions, risk tier, review date and current status. Without it, shadow AI and duplicated tools are difficult to control.
Is an AI policy enough?
No. A policy establishes rules, but governance also requires an inventory, accountable owners, approval routes, supplier checks, technical controls, staff training, monitoring, incident handling and evidence that the rules are followed.
When is a data protection impact assessment required?
A DPIA is required before processing that is likely to create high risk to people. AI projects using personal data, profiling, large-scale processing or significant decisions often require early DPIA assessment. Unmitigated high risk may require consultation with the ICO.
Can employees enter personal data into a public AI tool?
Only when the tool and use are approved, the organisation has a lawful and transparent basis, data minimisation is applied, contractual and security controls are acceptable and individuals' rights can be supported. Public consumer tools should not receive confidential or personal data by default.
Who should own an AI system?
Each system should have a senior business owner accountable for purpose and risk, an operational owner responsible for day-to-day use, and named technical, security, data protection and supplier contacts where relevant. Ownership should not sit only with the vendor.
How should human review be designed?
Reviewers need access to the underlying evidence, enough knowledge and authority to disagree, a clear escalation route and time to make a genuine decision. Record overrides and disagreements so the organisation can evaluate both the AI and the review process.
What should be checked before buying an AI tool?
Review the supplier, hosting, data use, retention, model training, subcontractors, security, permissions, audit logs, accuracy evidence, incident terms, portability, termination, intellectual property, support and ability to meet data-subject or consumer obligations.
How should generative AI output be checked?
Use source-linked verification for factual claims, approved templates for sensitive outputs, deterministic validation for required fields and human review proportional to consequence. Never treat fluent language as evidence of correctness.
What extra controls are needed for AI agents?
Agents need tightly bounded goals, minimum permissions, approved tools, independent policy checks, transaction limits, confirmation before material actions, complete logs, monitoring, a kill switch and a manual fallback. Start with low-risk tasks.
Does the EU AI Act affect UK businesses?
It may affect UK organisations that provide, deploy, import or distribute AI systems in the EU or whose AI output is used there. Scope depends on the role, system and market. Obtain current specialist advice for cross-border activity.
How often should an AI system be reviewed?
Review frequency should reflect risk and change. Trigger a new review after supplier or model changes, new data, expanded permissions, a new user group, significant incidents, material performance drift or a change in law or business purpose.
What should happen when an AI tool fails?
Stop or contain the affected function, preserve evidence, prevent repeated harmful output, notify the owner, switch to the manual process, assess affected people or transactions, correct records and decide whether the system can safely resume.
How can a small business start AI governance without creating bureaucracy?
Begin with one register, one approval form, three risk tiers, a short acceptable-use policy, named owners and a monthly review. Apply deeper assessment only to systems that use sensitive data, affect people, take actions or create material business consequences.
Executive Decision Summary
- Build the AI-use register first. Governance cannot control systems, embedded features and shadow use it cannot see.
- Assign accountable owners. Each system needs business, operational and technical authority, including the ability to stop it.
- Assess the use case. Purpose, data, affected people, decisions, permissions and markets determine the control depth.
- Review the supplier and architecture. Contract, data use, security, changes, incidents and exit must be understood.
- Make human review meaningful. Reviewers need evidence, competence, authority, capacity and a challenge route.
- Monitor and retain an exit. Track errors, overrides, incidents and changes, with tested rollback and manual fallback.
Make AI Use Visible, Owned and Reversible
BhavPro can help UK businesses move from informal AI experimentation to a practical governance model covering inventory, ownership, data, suppliers, testing, oversight and operational controls.
Official Sources Used in This Guide
The references below support the organisational governance, data-protection, automated-decision, consumer, security, assurance and cross-border guidance used throughout this page.
- UK Government β AI Management Essentials Guidance describes organisational practices for responsible AI management.
- UK Government β AI Management Essentials Tool defines AI system records and governance evidence.
- ICO β Governance and Accountability in AI covers senior sign-off, privacy frameworks, policies and assigned responsibilities.
- ICO β Accountability and Governance Implications of AI explains DPIAs, training, safeguards and residual risk.
- ICO β Data (Use and Access) Act 2025 summarises changes affecting automated decisions and safeguards.
- Competition and Markets Authority β Using AI Agents and Consumer Law covers transparency, accountability, monitoring and human oversight.
- National Cyber Security Centre β Secure AI System Development covers secure design, development, deployment and operation.
- NCSC β Careful Adoption of Agentic AI recommends narrow, low-risk starting points and established cyber controls.
- UK Government β Introduction to AI Assurance explains techniques for measuring and communicating whether AI meets required criteria.
- European Commission β EU AI Act provides the current application timetable and cross-border regulatory framework.
Continue With the Governance Stage You Reached
Use the resource that matches the current need: discover the AI estate, assess integration and governance dependencies or discuss one defined system.

Bhav Giva
Founder, AI-Assisted Business Systems Consultant
Bhav is a UK-based consultant in Leicester with 15+ years of hands-on experience across business systems, CRM workflows, telecom operations, IT infrastructure, websites and AI-assisted process design. His work focuses on connecting technology adoption with accountable ownership, controlled data use, measurable outcomes and practical recovery.
Share This Guide
- Facebook: BhavPro On Facebook
- Instagram: @bhavpro
- Medium: @BhavPro
AI Governance Checklist for UK Businesses Using Generative AI
Create a practical system for approving AI use, controlling data and permissions, assessing suppliers, protecting people, validating outputs, monitoring changes and stopping unsafe activity.
Fast answer: UK businesses need an AI-use register, named owners, approved purposes, data and supplier checks, risk-based human review, security controls, testing, monitoring, incident response and an exit plan. Apply deeper assessment when AI uses personal data, affects people, creates content, connects to systems or takes consequential actions.

AI Governance Is an Operating System, Not a Policy Document
A policy is necessary, but it cannot identify shadow AI, assign system ownership, test a supplier or recover from a harmful action. Governance connects leadership decisions with operational records and technical controls.
Inventory
Record every AI service, embedded feature, internal model and agent used for business activity.
Ownership
Assign a senior business owner, operational owner and relevant technical, privacy and security roles.
Purpose
Define the approved outcome, users, inputs, outputs, prohibited uses and success evidence.
Impact
Assess effects on people, data, customers, workers, decisions, intellectual property and regulated activity.
Assurance
Review suppliers, architecture, security, performance evidence and contractual responsibility.
Oversight
Set permission limits, human review, approval thresholds, escalation and individual challenge routes.
Testing
Test normal, incorrect, adversarial, incomplete and high-impact cases before release.
Monitoring
Measure errors, overrides, incidents, drift, supplier changes, access and real outcomes.
Exit
Maintain rollback, manual fallback, data return, deletion, migration and retirement controls.
The UK governmentβs AI Management Essentials work focuses on organisational processes rather than certifying individual AI products. Its guidance describes an AI system record containing technical documentation, impact and risk assessments, model analyses and data records.
Step 1Create an AI-Use Register Before Writing More Rules
A central register is the fastest way to identify approved tools, unapproved use, duplicated subscriptions and high-risk activity. Include features embedded in software already used by the business; an AI assistant inside a CRM, helpdesk or office suite is still an AI use.
| Register Field | What to Record | Why It Matters |
|---|---|---|
| System and supplier | Product, feature, underlying model where known, provider and contract owner | Identifies dependency and responsibility |
| Approved purpose | Specific business task, user group and intended outcome | Prevents uncontrolled purpose expansion |
| Inputs and data | Prompts, documents, personal data, confidential data and retrieval sources | Supports privacy, security and data-quality assessment |
| Outputs and actions | Generated content, recommendations, classifications, decisions and system actions | Shows the consequence of error |
| Affected people | Customers, staff, applicants, suppliers, children or vulnerable groups | Determines rights, fairness and review needs |
| Human boundary | What is reviewed, by whom, with which evidence and authority | Prevents nominal or ineffective oversight |
| Risk and approval | Risk tier, assessment references, approver and approval date | Creates an auditable decision |
| Monitoring | Accuracy, incidents, overrides, complaints, drift and supplier changes | Supports continued approval or withdrawal |
Find shadow AI without creating fear
Ask teams which tools they already use, what information they enter and which outputs they rely upon. Provide an approved route for low-risk experimentation. A blanket prohibition can drive use away from visibility rather than stopping it.
Step 2Assign Owners Who Can Stop the System
The ICOβs governance toolkit expects senior management sign-off, a documented privacy framework and assigned technical, operational and data-protection responsibilities. Ownership should remain inside the organisation even when the system is supplied and hosted externally.
Senior business owner
Owns the purpose, budget, accepted risk and decision to continue, restrict or stop the system.
- Confirms the business need
- Approves material risk
- Receives incident and performance reporting
Operational owner
Owns user access, procedures, exceptions, training, output review and day-to-day results.
- Maintains the use register
- Controls purpose changes
- Coordinates manual fallback
Technical and security owner
Owns architecture, identity, permissions, logging, integrations, testing and incident containment.
- Applies least privilege
- Reviews supplier and model changes
- Maintains rollback and kill controls
Data-protection and legal support
Assesses personal data, lawful basis, transparency, rights, automated decisions, contracts and sector obligations.
- Determines DPIA requirements
- Reviews affected-person safeguards
- Escalates residual high risk
No owner, no approval. An AI system should not move into operational use when nobody has authority to restrict access, investigate harm, challenge the supplier or stop the service.
Map the Applicable UK Duties
AI governance in the UK must connect the use case to existing legal and regulatory duties. The correct assessment depends on the data, people, decision, sector, customer relationship and markets involved.
Automated decisions and the Data (Use and Access) Act 2025
The ICO explains that the 2025 Act changed the UK rules for significant automated decisions using personal data and expanded the lawful bases that may be available when appropriate safeguards are applied. Special-category data remains more protected. Organisations should use current ICO guidance and obtain specialist advice for high-impact decisions.
Check EU AI Act scope before 2 August 2026
The EU AI Act entered into force on 1 August 2024. Some provisions, including AI literacy, already apply, while major additional obligations become applicable from 2 August 2026. UK organisations that provide or deploy systems in the EU, or whose outputs are used there, should establish their role and obligations rather than assuming UK location removes them from scope.
This checklist is not a substitute for legal advice. Use it to identify governance evidence and escalation points, then obtain appropriate advice for significant automated decisions, regulated activity, employment, sensitive personal data, consumer-facing agents and cross-border deployment.
Assess Data, People and Decision Impact
| Area | Governance Question | Evidence | Escalation Trigger |
|---|---|---|---|
| Purpose | Is the outcome specific, necessary and compatible with the data collected? | Approved purpose statement and alternatives considered | The use expands beyond the original reason |
| Personal data | Which personal data is used, generated, inferred or retained? | Data map, lawful basis, notices and retention | Special-category, children's or large-scale data |
| People affected | Who may gain, lose, be profiled, excluded or treated differently? | Stakeholder and impact analysis | Legal, employment, financial or similarly significant effect |
| Fairness | Does performance differ across relevant groups or operating contexts? | Representative tests, complaints and outcome monitoring | Unexplained disparity or harmful feedback loop |
| Accuracy | What does accuracy mean for personal data and for system performance? | Source quality, validation, corrections and confidence | Incorrect records or decisions persist |
| Rights and challenge | Can people obtain information, correct data and challenge an outcome? | Notice, request process, review route and response records | The system cannot support applicable rights |
Complete the DPIA early when high risk is likely
The ICO says a DPIA must be completed before high-risk processing begins. Use it to document purpose, necessity, proportionality, risks, training and the technical and organisational controls applied. If residual high risk cannot be mitigated sufficiently, consultation with the ICO may be required before processing starts.
Step 5Review the Supplier and the Full AI Supply Chain
A familiar brand or paid licence does not answer how business data is used, which model is involved, where processing occurs or how a material change will be communicated.
| Question | Required Evidence | Unacceptable Gap |
|---|---|---|
| What service and model are supplied? | Product architecture, versions, subprocessors and dependencies | The supplier cannot identify material components |
| How is submitted data used? | Contractual terms for processing, retention, training and deletion | Confidential inputs may be reused without control |
| Where is data processed? | Locations, transfer mechanism and subprocessors | Unknown or unsupported international processing |
| How is access controlled? | Identity, SSO, MFA, roles, API permissions and administrative controls | Shared accounts or unrestricted connectors |
| How is performance evidenced? | Use-case-relevant testing, limitations and error analysis | Only general marketing accuracy claims |
| How are incidents handled? | Notification, investigation, evidence, support and responsibility | No timely route for security or harmful-output incidents |
| How are changes controlled? | Release notices, model changes, deprecation and retesting support | Material behaviour can change without notice |
| How can the business exit? | Export, deletion, portability, continuity and termination terms | Records, prompts or outputs cannot be recovered or deleted |
Where several AI tools, suppliers and existing systems are involved, an AI business systems audit can identify duplicated tools, shadow use, data dependencies, process gaps and priority controls before a procurement decision.
Step 6Control Data, Generated Content and Intellectual Property
Input controls
Define which information may be entered, retrieved or uploaded.
- Prohibit credentials and unnecessary personal data
- Classify confidential and client information
- Use approved retrieval sources
- Apply redaction and minimisation where appropriate
Output controls
Set review and publication requirements according to consequence.
- Verify factual claims against primary sources
- Check names, figures, citations and legal statements
- Review bias, tone and affected groups
- Record approval for sensitive external content
Copyright and licensing
Document how source material and generated output may be used.
- Check licences for source and reference material
- Avoid requests to reproduce protected works improperly
- Record human contribution where ownership matters
- Review supplier indemnities and exclusions
Records and retention
Retain enough evidence for the decision while avoiding uncontrolled archives.
- Set prompt, output and log retention by purpose
- Support correction and deletion obligations
- Separate development data from live business data
- Delete obsolete test and exported datasets
Design Meaningful Human Oversight
Human review is not meaningful when the reviewer sees only a confidence score, lacks authority to disagree or is expected to approve hundreds of outputs without enough time.
| Control | Required Practice | Evidence to Retain |
|---|---|---|
| Competence | Train reviewers on the system, task, data, limits and likely failure modes | Role-based training and assessment |
| Evidence access | Show the information used, missing data and contrary signals | Review interface and source references |
| Authority | Allow the reviewer to reject, correct, escalate and stop the outcome | Permissions and escalation procedure |
| Time and workload | Give reviewers realistic capacity for the consequence involved | Queue size, handling time and backlog |
| Challenge route | Provide affected people with a clear way to question or correct outcomes | Notices, requests, reviews and responses |
| Override monitoring | Record when people disagree with the system and why | Override rate, reason and subsequent outcome |
Add stronger boundaries for AI agents
Agentic systems can plan and act across tools. The NCSCβs 2026 guidance recommends starting small, using agents for low-risk tasks and applying established security controls from the outset.
- Use the minimum tools, data and permissions required.
- Set transaction, time, quantity and destination limits.
- Require confirmation before financial, legal, customer or account changes.
- Validate tool parameters outside the model.
- Log the goal, plan, retrieved data, tool calls, approvals and outcomes.
- Provide a kill switch and tested manual process.
Test Performance, Security and Failure Handling
| Test Group | Examples | Required Outcome |
|---|---|---|
| Normal cases | Representative approved inputs and ordinary users | The intended output is useful and traceable |
| Incomplete and ambiguous cases | Missing fields, contradictory documents and uncertain instructions | The system asks, abstains or routes to review |
| Incorrect and harmful cases | False claims, biased examples and unsafe recommendations | Controls detect, prevent or contain harm |
| Adversarial cases | Prompt injection, malicious files, manipulated retrieval and excessive requests | Instructions, data and tools remain protected |
| Rights and complaint cases | Correction, access, objection and challenge requests | The organisation can locate evidence and respond |
| Failure and outage cases | Unavailable model, broken connector, timeout and partial transaction | The process fails safely and uses the fallback |
UK AI Governance Readiness Checker
Assess the organisational controls around one AI system or use case. The checker does not determine legal compliance or certify the product.
AI Governance Control Assessment
Select the current state of the organisation. The result identifies whether the system is ready for approval, needs a controlled pilot or should remain blocked.
AI Governance Checklist for UK Businesses
| Control | Minimum Evidence Before Approval | Review Trigger |
|---|---|---|
| AI-use register | System, supplier, purpose, owner, data, users, actions, risk and status | New tool, feature, model or expanded use |
| Purpose and necessity | Defined outcome, alternatives considered and prohibited uses | New decision, team, customer or data source |
| Ownership | Senior, operational, technical, security and privacy responsibilities | Role, supplier or organisational change |
| Data protection | Data map, lawful basis, notices, minimisation, retention and DPIA decision | New personal data, profiling or affected group |
| People and fairness | Affected-person analysis, representative tests and challenge route | Complaints, disparity or material outcome change |
| Supplier assurance | Contract, data use, security, subprocessors, changes, incidents and exit | Model, terms, hosting or subprocessor change |
| Security | Identity, least privilege, connector scope, logging and threat testing | New integration, permission, vulnerability or incident |
| Human oversight | Reviewer competence, evidence, authority, workload and override records | High approval rate, backlog or reduced review time |
| Testing | Normal, edge, harmful, adversarial and failure-case results | Model, prompt, retrieval, workflow or user change |
| Monitoring | Performance, errors, overrides, complaints, incidents and business outcomes | Threshold breach or unexplained drift |
| Incident response | Containment, evidence, notification, correction and restart procedure | Harmful output, data event or unauthorised action |
| Exit and retirement | Manual fallback, export, deletion, migration and access revocation | Supplier failure, unacceptable risk or contract termination |
Use simple risk tiers
| Tier | Typical Use | Approval Level | Examples of Additional Control |
|---|---|---|---|
| Low | Internal drafting using non-sensitive information with no decision or system action | Approved tool and manager-owned procedure | Accuracy review and prohibited-data rules |
| Moderate | Customer content, internal knowledge retrieval, classification or recommendations | Business owner plus security, data or compliance review as relevant | Representative testing, logs and meaningful human review |
| High | Personal data, significant decisions, vulnerable groups, regulated activity or connected actions | Senior approval with specialist legal, privacy, security and technical assessment | DPIA, impact assessment, strict permissions, assurance and formal monitoring |
Monitor the System After Approval
Approval is time-limited. Models, terms, prompts, data, users and connected systems change. The organisation should be able to identify when the approved evidence no longer represents current operation.
- Review output accuracy and business usefulness.
- Track human overrides, disagreements and abstentions.
- Record complaints, corrections and affected-person challenges.
- Monitor unusual access, prompt injection and unauthorised tool use.
- Review supplier, model, terms, retention and subprocessor changes.
- Reassess when purpose, permissions, data or user groups expand.
- Stop the system when residual risk exceeds the approved boundary.
Define AI-specific incident categories
| Incident | First Action | Evidence to Preserve |
|---|---|---|
| Personal or confidential data exposure | Contain access and follow the data or security incident process | Input, output, account, model, recipient and retention information |
| Harmful or materially incorrect output | Stop the affected use and correct downstream records or communications | Prompt, sources, output, reviewer and affected outcome |
| Unauthorised system action | Disable tools or credentials and verify destination systems | Goal, plan, tool calls, parameters, approvals and results |
| Prompt injection or manipulated retrieval | Isolate the content source and restrict connected actions | Malicious content, model response and control bypass |
| Performance drift or unfair outcome | Pause the decision route and reassess data and affected groups | Current and baseline outcomes, overrides and complaints |
| Supplier change or outage | Switch to the fallback and assess continued approval | Change notice, unavailable functions, affected records and recovery |
Discover
Identify tools, embedded features, owners, users, data and connected systems.
Classify
Define purpose, affected people, permissions, actions and initial risk tier.
Assess
Review data protection, supplier, security, fairness and cross-border obligations.
Control
Set access, human review, testing, logging, fallback and incident procedures.
Pilot
Test representative, harmful, adversarial and failure cases with limited users.
Approve
Record evidence, residual risk, conditions, review date and stop criteria.
After the organisation has identified its systems, use cases and priority risks, BhavProβs AI integration advisory can help assess architecture, supplier dependencies, governance controls and implementation sequencing.
Need to turn scattered AI use into an owned operating model?
BhavPro can help map the AI estate, define approval routes, assess data and system dependencies, establish controls and create a practical implementation roadmap.
AI Governance FAQs for UK Businesses
What is AI governance for a UK business?
AI governance is the system of ownership, policies, records, controls, testing, monitoring and review used to keep AI use aligned with business objectives, legal duties, security requirements and acceptable risk. It covers purchased tools as well as systems developed internally.
Does every business need an AI-use register?
A central register is a practical starting point for any organisation using AI. It should record the tool, purpose, owner, supplier, data, affected people, permissions, decisions, risk tier, review date and current status. Without it, shadow AI and duplicated tools are difficult to control.
Is an AI policy enough?
No. A policy establishes rules, but governance also requires an inventory, accountable owners, approval routes, supplier checks, technical controls, staff training, monitoring, incident handling and evidence that the rules are followed.
When is a data protection impact assessment required?
A DPIA is required before processing that is likely to create high risk to people. AI projects using personal data, profiling, large-scale processing or significant decisions often require early DPIA assessment. Unmitigated high risk may require consultation with the ICO.
Can employees enter personal data into a public AI tool?
Only when the tool and use are approved, the organisation has a lawful and transparent basis, data minimisation is applied, contractual and security controls are acceptable and individuals' rights can be supported. Public consumer tools should not receive confidential or personal data by default.
Who should own an AI system?
Each system should have a senior business owner accountable for purpose and risk, an operational owner responsible for day-to-day use, and named technical, security, data protection and supplier contacts where relevant. Ownership should not sit only with the vendor.
How should human review be designed?
Reviewers need access to the underlying evidence, enough knowledge and authority to disagree, a clear escalation route and time to make a genuine decision. Record overrides and disagreements so the organisation can evaluate both the AI and the review process.
What should be checked before buying an AI tool?
Review the supplier, hosting, data use, retention, model training, subcontractors, security, permissions, audit logs, accuracy evidence, incident terms, portability, termination, intellectual property, support and ability to meet data-subject or consumer obligations.
How should generative AI output be checked?
Use source-linked verification for factual claims, approved templates for sensitive outputs, deterministic validation for required fields and human review proportional to consequence. Never treat fluent language as evidence of correctness.
What extra controls are needed for AI agents?
Agents need tightly bounded goals, minimum permissions, approved tools, independent policy checks, transaction limits, confirmation before material actions, complete logs, monitoring, a kill switch and a manual fallback. Start with low-risk tasks.
Does the EU AI Act affect UK businesses?
It may affect UK organisations that provide, deploy, import or distribute AI systems in the EU or whose AI output is used there. Scope depends on the role, system and market. Obtain current specialist advice for cross-border activity.
How often should an AI system be reviewed?
Review frequency should reflect risk and change. Trigger a new review after supplier or model changes, new data, expanded permissions, a new user group, significant incidents, material performance drift or a change in law or business purpose.
What should happen when an AI tool fails?
Stop or contain the affected function, preserve evidence, prevent repeated harmful output, notify the owner, switch to the manual process, assess affected people or transactions, correct records and decide whether the system can safely resume.
How can a small business start AI governance without creating bureaucracy?
Begin with one register, one approval form, three risk tiers, a short acceptable-use policy, named owners and a monthly review. Apply deeper assessment only to systems that use sensitive data, affect people, take actions or create material business consequences.
Executive Decision Summary
- Build the AI-use register first. Governance cannot control systems, embedded features and shadow use it cannot see.
- Assign accountable owners. Each system needs business, operational and technical authority, including the ability to stop it.
- Assess the use case. Purpose, data, affected people, decisions, permissions and markets determine the control depth.
- Review the supplier and architecture. Contract, data use, security, changes, incidents and exit must be understood.
- Make human review meaningful. Reviewers need evidence, competence, authority, capacity and a challenge route.
- Monitor and retain an exit. Track errors, overrides, incidents and changes, with tested rollback and manual fallback.
Make AI Use Visible, Owned and Reversible
BhavPro can help UK businesses move from informal AI experimentation to a practical governance model covering inventory, ownership, data, suppliers, testing, oversight and operational controls.
Official Sources Used in This Guide
The references below support the organisational governance, data-protection, automated-decision, consumer, security, assurance and cross-border guidance used throughout this page.
- UK Government β AI Management Essentials Guidance describes organisational practices for responsible AI management.
- UK Government β AI Management Essentials Tool defines AI system records and governance evidence.
- ICO β Governance and Accountability in AI covers senior sign-off, privacy frameworks, policies and assigned responsibilities.
- ICO β Accountability and Governance Implications of AI explains DPIAs, training, safeguards and residual risk.
- ICO β Data (Use and Access) Act 2025 summarises changes affecting automated decisions and safeguards.
- Competition and Markets Authority β Using AI Agents and Consumer Law covers transparency, accountability, monitoring and human oversight.
- National Cyber Security Centre β Secure AI System Development covers secure design, development, deployment and operation.
- NCSC β Careful Adoption of Agentic AI recommends narrow, low-risk starting points and established cyber controls.
- UK Government β Introduction to AI Assurance explains techniques for measuring and communicating whether AI meets required criteria.
- European Commission β EU AI Act provides the current application timetable and cross-border regulatory framework.
Continue With the Governance Stage You Reached
Use the resource that matches the current need: discover the AI estate, assess integration and governance dependencies or discuss one defined system.

Bhav Giva
Founder, AI-Assisted Business Systems Consultant
Bhav is a UK-based consultant in Leicester with 15+ years of hands-on experience across business systems, CRM workflows, telecom operations, IT infrastructure, websites and AI-assisted process design. His work focuses on connecting technology adoption with accountable ownership, controlled data use, measurable outcomes and practical recovery.
Share This Guide
- Facebook: BhavPro On Facebook
- Instagram: @bhavpro
- Medium: @BhavPro

