CertAI
AI governance in your company: where to start (even without a Chief AI Officer)
D

Domenico Ruggiano

updated on

AI Governance

AI governance in your company: where to start (even without a Chief AI Officer)

Large companies are hiring to govern AI: according to the IAPP, dedicated AI governance roles grew 156% in one year, and the Chief AI Officer is now a common figure in multinationals.

Then there's everyone else: SMEs, scaleups, software houses. No Chief AI Officer, no internal ethics committee, no budget for a governance team. And yet exactly the same problems: AI tools entering the company through every door, customers demanding guarantees, a European regulation in its operational phase.

The good news: AI governance is not an org-chart question. It's a question of clear responsibilities and proportionate processes. Here's how to set it up without creating a dedicated function.

In short
AI governance roles are growing (+156% in a year according to the IAPP), but for an SME the point is not hiring: it is assigning existing responsibilities.
The minimal framework rests on 6 elements: ownership, inventory, policy, risk assessment, training, monitoring.
Two symmetrical mistakes to avoid: the committee that blocks everything and the free-for-all with no rules.
Management system standards (ISO/IEC 42001) turn governance from a voluntary initiative into evidence you can spend with customers and regulators.

#Why "we don't have a CAIO" is no excuse

The AI Act doesn't ask for a Chief AI Officer. It asks for far more concrete things: that staff using AI systems are trained (already mandatory), that users know when they are interacting with an AI, that systems are classified by risk and, for high-risk from 2027, that risk management, documentation and human oversight exist (see our AI Act deadlines guide).

Enterprise customers don't ask for an org chart either: they ask for answers in vendor questionnaires. "Who is responsible for AI use in your company?" is a question to which "nobody in particular" is the only wrong answer.

Governance, in the end, means this: someone is accountable, a process exists, evidence remains.

#The minimal framework: 6 elements

1. Ownership: a name, not a new role

You need one person accountable for AI use in the company. In SMEs it's typically the CTO, the IT/security lead or the COO, with an explicit, written mandate. Relevant decisions (adopting a new tool, exposing AI to customers) go through them. They don't need to do everything: nothing should happen without them knowing.

2. AI system inventory

You can't govern what you can't see. A census of everything: internally developed models, third-party APIs embedded in products, SaaS tools with AI features, autonomous agents, individual employee usage. It's the same inventory needed for AI Act classification, and it surfaces shadow AI (see our shadow AI article). Keep it alive: a six-month-old inventory is archaeology.

3. Usage policy: one page people actually read

What is allowed, with which data, on which tools; what requires approval; who to ask. The quality test for an AI policy: a new hire understands it in five minutes and knows what to do on Monday morning. Thirty pages of ethical principles fail the test.

4. Proportionate risk assessment

Not every AI use deserves the same attention. An internal proofreader and a system evaluating credit applications are not on the same scale. For each system in the inventory: what data it handles, what decisions it influences, who it impacts, what happens if it fails. The AI Act risk categories (prohibited / high / limited / minimal) are a free, ready-made grid.

5. Training: the obligation that is also an investment

AI literacy has been required by the AI Act since February 2025, for any company using AI systems. But the real return is operational: most shadow AI incidents stem from good faith plus ignorance of the risks. A trained team is the first line of defence, and it uses AI better, not less.

6. Monitoring and review

Governance is not a project with an end date: it's a cycle. Periodically review the inventory, incidents and near-misses, new tools requested by teams, regulatory changes. A quarterly one-hour review with management beats a grand audit every two years, every time.

#The two symmetrical mistakes

The committee that blocks everything. Governance perceived as a brake: every AI request waits weeks, teams stop asking and go back underground. Governance that generates shadow AI is failed governance.

The enlightened free-for-all. "We trust our people": works until the first vendor questionnaire, the first incident, the first request from an authority. At that point, trust without evidence is worth zero.

The balance point: fast tracks for low-risk uses, real scrutiny concentrated where risk is high.

#From internal framework to spendable evidence

A framework like this works, but it remains a self-declaration. The next step is anchoring it to a recognised standard: ISO/IEC 42001 takes exactly these elements (roles, inventory, risks, controls, monitoring) and structures them into a certifiable management system (see our ISO/IEC 42001 guide).

The difference is commercial before it is formal: "we have an internal policy" and "we comply with the international standard for AI management" produce very different effects in an enterprise negotiation. And whoever already runs an ISO 27001 management system starts halfway there (see our ISO 27001 + ISO 42001 article).

#How CertAI helps

CertAI builds the governance framework with you (inventory, classification, policy, risk assessment) and takes it all the way to compliance with the AI Act and certifiable standards, with documentation generated and maintained by our AI systems. Without hiring a dedicated team.

Want an AI governance framework without hiring a dedicated team? CertAI builds it with you.

Book a demo

Main sources: IAPP AI Governance Profession Report (2025); Regulation (EU) 2024/1689 (AI Act). Last updated: July 2026.