AI governance is the set of policies, roles and controls an organization uses to decide which AI systems it approves, how it monitors them and when it retires them, so that every automated output has a named owner, a known risk level and a path for review.
What AI governance covers
In practice AI governance is a short list of decisions made once and enforced every time a new tool appears.
- Inventory. A register of every AI system in use, including ones bought inside other software.
- Risk tiering. Each system gets a risk level based on what it affects. A tool that drafts meeting notes is low. A tool that ranks job applicants or scores credit is high.
- Ownership. One named person is accountable for each system's outputs.
- Approval. Higher tiers need testing, a bias audit where people are scored, and sign-off before use.
- Oversight in use. Rules for when a person must review an output before it takes effect. See human-in-the-loop.
- Monitoring and records. Logs, performance checks and checks for score drift that make each decision traceable later. This is what gives a system auditability.
- Retirement. Criteria for switching a system off, and what happens to its data.
AI governance frameworks and laws
This section summarises three widely used references. It is not legal advice.
- NIST AI Risk Management Framework. The AI RMF 1.0, released by NIST in January 2023, is voluntary. It organises the work into four functions: Govern, Map, Measure and Manage. Govern is the cross-cutting one: policies, roles, accountability and culture.
- EU AI Act. Regulation (EU) 2024/1689 sorts AI systems by risk. Annex III lists AI used for recruitment or selection, and for decisions about promotion, termination and task allocation, as high-risk. Deployers of high-risk systems must use them according to instructions, assign human oversight to competent people, monitor operation, keep automatically generated logs for at least six months, and, as employers, inform workers' representatives before use at the workplace. The European Commission's AI Act FAQ states that the Digital Omnibus, in force since 27 July 2026, moves the start of the high-risk rules to 2 December 2027.
- OECD AI Principles. The OECD AI Principles set out values that many national policies build on, including transparency and explainability, robustness and safety, and accountability.
Why AI governance matters for funds and hiring teams
Hiring teams face the most direct rules, because automated scoring of people is regulated in several places. Venture and private equity firms meet AI governance from three sides: their own use of AI in sourcing and screening, their portfolio companies' use of AI, and limited partners who increasingly ask how both are controlled. A firm that cannot list its own AI tools and their owners will struggle to answer a diligence questionnaire about a portfolio company's.
Worked example: a fund's AI register
Northwind Ventures, a fictional 12-person fund, writes its first AI register. It takes an afternoon.
| System | Use | Owner | Tier | Control |
|---|---|---|---|---|
| Meeting transcription | Notes from founder calls | Operations lead | Low | Founder consent at call start |
| Company scoring | Ranks inbound and mapped companies against the thesis | Partner, sourcing | Medium | Every score cites evidence; partners review the top and the borderline |
| Applicant screening for a fund analyst role | Ranks applicants | Managing partner | High | Bias check on outcomes, notice to applicants, no auto-rejection |
The hiring tool gets the strictest tier because AI candidate scoring rates people for jobs, which is where the EU AI Act and rules such as New York City's Local Law 144 apply. The company scoring tool sits in the middle: it affects which founders get a meeting, so the fund requires reasons it can check, in line with explainable AI practice.
AI governance vs data governance and model risk management
| AI governance | Data governance | Model risk management | |
|---|---|---|---|
| Scope | Every AI system and its use | Data quality, access, lineage, retention | Quantitative models, often in banking |
| Main question | Should we use this system here, and who answers for it? | Is the data right and properly handled? | Is the model sound and validated? |
| Typical owner | A cross-functional group or named executive | Data or IT leadership | Risk function |
AI governance relies on both. Poor data governance produces biased inputs; weak validation hides model errors. Bias mitigation sits across all three.
Common AI governance mistakes
- A policy with no register. Principles that do not name systems and owners change nothing.
- Missing embedded AI. Many tools add AI features in an update. Review vendor changes, not only new purchases.
- One tier for everything. Treating a note-taker like a hiring screen slows everything; the reverse is a legal risk.
- Oversight on paper only. A reviewer who approves hundreds of outputs an hour is not overseeing them.
- No retirement rule. Old models keep running long after anyone checks them.
How ScoringFactory approaches it
ScoringFactory is built to sit inside a team's governance rather than around it. It ranks and explains, it cites every score to the record behind it, and it never makes the investment or hiring decision; a named person on the team does. Customer data stays separated by customer and does not train models for others. The trust page sets out current security and data-handling practices.
Frequently asked questions
What is an AI governance framework?
An AI governance framework is a structured set of practices for managing AI risk across an organization: who approves systems, how risk is tiered, what testing and oversight each tier needs, and how systems are monitored and retired. The NIST AI Risk Management Framework and ISO/IEC 42001 are two widely used examples.
What does the NIST AI Risk Management Framework require?
Nothing, in a legal sense. The NIST AI RMF is voluntary guidance. It describes four functions (Govern, Map, Measure and Manage) and suggested actions under each, from setting accountability to measuring bias and planning responses to incidents. Organizations use it to structure their own program and to show customers or regulators a recognised approach.
How does the EU AI Act affect AI used in hiring?
It classes AI used for recruitment, selection, promotion, termination and task allocation as high-risk. Providers face design, documentation and testing duties; employers that deploy these systems must assign human oversight, monitor use, keep logs and inform workers' representatives. The European Commission says the high-risk rules apply from 2 December 2027. This is not legal advice.
Who should own AI governance in a small firm?
One named senior person, usually a partner or the chief operating officer, with a short register of every AI system and its owner. Small firms do not need a committee to start. They need the inventory, a simple risk tier for each tool, and a rule that high-tier uses such as hiring get review before use.
Sources
- AI Risk Management Framework, NIST, 2023
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), EUR-Lex, European Union
- Navigating the AI Act (FAQ), European Commission, 2026
- OECD AI Principles, OECD.AI, 2024