What is AI governance?

I describe AI governance as the decisions, responsibilities and controls that guide how an organization uses AI. My starting questions are simple: who owns the outcome, what data may be used, who checks the result, and what happens when something goes wrong? A written policy helps only when people can apply it in their daily work.

Where should an Indonesian business start?

I would begin with one workflow and a clear business problem. For a manufacturer, that might be finding an approved procedure; for an HR team, preparing a first draft of learning materials. I would map existing AI use before purchasing another tool, including employee use of public services. That reveals where useful experiments already exist and where confidential information may be exposed.

What should an AI use policy cover?

I recommend a short, usable policy covering approved tools, permitted data, restricted uses, output review, accountability and incident reporting. I would give employees concrete examples of information they may and may not enter. I would also identify who can approve exceptions and when the rules will be reviewed. I involve the relevant legal and security specialists when an application raises privacy or regulatory questions.

Who should be accountable?

I look for a named business owner who is responsible for the result, supported by technical, HR, security and compliance colleagues. I would make human review meaningful: the reviewer needs enough knowledge, time and authority to challenge an AI output. For decisions affecting recruitment, performance or employment, I would examine potential unfairness and the route for a person to question the outcome before considering deployment.

A practical example: an internal policy assistant

Consider an illustrative HR assistant that answers questions from approved policies. I would first limit it to current, authorized documents and suitable access permissions. I would test whether answers point to the right source, distinguish uncertainty and escalate questions requiring judgment. I would keep sensitive personnel records outside the pilot unless the necessary approvals and controls were in place. This is a planning example, not a reported client result.

How would I structure the first 90 days?

In the first 30 days, I would clarify the business objective, map data and risks, appoint an owner and record a baseline. During days 31–60, I would support a limited pilot with trained users, agreed controls and a way to report errors. During days 61–90, I would review benefits, failures, user feedback and ongoing costs with the owner. I would recommend expansion only when the evidence supports it; the schedule and scope depend on organizational readiness.

How do I measure value without overlooking risk?

I compare time saved with the time spent checking and correcting outputs. I also consider quality, adoption, errors, incidents and total operating costs. In the policy-assistant example, I would track whether users can find a correct answer faster, whether the cited policy is current and how often a human must intervene. I do not treat more usage alone as evidence of better performance.

When can an AI consultant or advisor help?

I can help leadership clarify priorities, define responsibilities, assess people readiness and shape a practical implementation roadmap. My background in human capital, operations-related governance, compliance and sustainability informs this perspective. My focus is business strategy and organizational adoption; I work alongside the appropriate specialists for system development, integration and legal review.

Further reading

For further reading, I recommend the NIST AI Risk Management Framework, a voluntary resource for managing AI risks. I would adapt its use to the organization’s context rather than treat it as a certification or a substitute for local legal requirements.

I have earned the AWS Certified AI Business Strategist certification.

Explore my AI governance and implementation advisory →

Discuss your AI priorities with me