The operating problem
AI adoption often begins as a small experiment: a drafting assistant, a document search tool or a model that helps classify requests. The risk changes when that experiment starts influencing customer communication, operational decisions or access to services. At that point, the organisation is no longer testing a tool. It is operating a system that needs ownership, controls and evidence.
Many organisations try to govern AI through a policy alone. A policy is useful, but it cannot decide who approves a use case, which data may enter a model, how performance is measured or what happens when the output is wrong. Those are operating decisions.
The South African National AI Policy Framework emphasises responsible development, transparency, accountability, safety and the protection of human rights. NIST's AI Risk Management Framework provides a complementary structure through four functions: Govern, Map, Measure and Manage. Together, they point to an important principle: governance must be part of the delivery system, not an approval performed at the end.
Start with a register, not a committee
Create a simple register of AI use cases. Include the business owner, users, affected people, data used, provider, intended decision, failure consequences and current status. Record informal tools as well as formally procured platforms. Shadow use is still organisational risk.
Then assign each use case a risk tier. A low-risk drafting assistant with human review should not carry the same controls as a model that recommends credit, employment or supplier decisions. A useful tiering discussion considers:
- the consequence of a wrong or misleading output;
- whether personal, confidential or regulated data is involved;
- whether an individual can challenge the outcome;
- how much human review exists in practice;
- the difficulty of detecting drift or misuse; and
- the organisation's ability to stop or reverse the process.
Define accountability across the lifecycle
Every use case needs a named business owner. Technology, legal, information security and data teams may advise, but the business owner remains accountable for the outcome. The delivery team should document the intended use, prohibited use, evaluation method, release decision and monitoring plan.
Procurement must also examine the provider's data handling, model-change process, subcontractors, retention terms, incident response and exit arrangements. A vendor statement that a product is secure or responsible is not evidence on its own.
Make measurement operational
Accuracy is rarely one number. Measure performance on representative South African data and real operating scenarios. Include difficult cases, language variation, incomplete records and situations in which the right answer is to abstain.
Monitor more than model quality. Track override rates, complaints, exception volumes, processing time, cost per useful outcome and incidents. Define thresholds that trigger review or suspension. Keep enough evidence to reconstruct why a material decision was made.
Boundaries matter
Not every process benefits from AI. Deterministic rules are often better where requirements are stable and explainability must be exact. Human judgement remains necessary where context, fairness or material consequence cannot be reduced to a score.
AI governance is also not a substitute for legal advice. POPIA, sector requirements and contractual duties may create obligations that need qualified interpretation.
A practical first 30 days
- Inventory current and proposed AI use cases.
- Assign an owner and risk tier to each one.
- Pause uses with unclear data rights or unacceptable consequences.
- Define minimum evidence for design, evaluation and release.
- Add monitoring, incident and retirement responsibilities.
- Review the register monthly while adoption is changing quickly.
A good operating model makes responsible delivery easier. It gives teams a clear path to experiment, while ensuring that material decisions remain reviewable and accountable.
If you are mapping AI use cases or designing approval and monitoring controls, Algoza can help turn the governance intent into a workable delivery process.