by Claude Opus 5.5

What governance model is proportionate for workplace AI (ownership, accountability, evaluation, audit trails, incident response) without creating bureaucratic paralysis?

The proportionate model governs uses, not tools, and sets the depth of oversight by consequence. Low-stakes productivity uses run on pre-approved terms with almost no paperwork. Decision support gets a short review. Anything that makes significant decisions about people, moves money, speaks to customers on its own or lets an agent take irreversible actions gets a proper gate. Each use has one named business owner, and the model builds on existing structures, such as data protection impact assessments, model-risk and senior-manager regimes, and security incident processes, rather than creating a new committee.

Design principles

  • Govern the use, not the technology. The same model can draft a lunch menu or rank job applicants. Risk lies in what the output is used for.

  • Make the safe route the fast route. Approved tools, templates and pre-cleared data classes let most teams start without asking anyone.

  • Reuse what you already have. A DPIA already covers much of what an “AI impact assessment” would. Banks already apply PRA SS1/23 on model risk. FCA-regulated firms already have senior-manager accountability under SM&CR and the Consumer Duty. Add AI-specific questions to these processes rather than running parallel ones.

  • Put deadlines on governance itself. A review with no service level becomes a veto by delay.

Three tiers

  • 1. Productivity. Typical uses: Drafting, summarising, internal search, coding assistance on approved tools. Approval: None beyond using the approved tool and data rules. Evidence required: None per use; the tool itself was assessed once. Monitoring: Usage and data-loss alerts at platform level.

  • 2. Decision support. Typical uses: Ticket triage, suggested replies checked by staff, anomaly flags, forecasting aids. Approval: Business owner plus a light review within 10 working days. Evidence required: One-page use record, test-set results, named human decision-maker. Monitoring: Override rate, error sampling, quarterly check.

  • 3. High consequence. Typical uses: Significant decisions about individuals (hiring, performance, credit, benefits); customer-facing autonomous agents; agents that can pay, delete or send externally; workplace monitoring. Approval: Formal sign-off by the accountable executive with DPO, legal and security input, within about 6 weeks. Evidence required: DPIA, fairness testing, explanation and challenge design, rollback plan. Monitoring: Continuous logs, monthly review, independent audit annually.

Tier 3 is where the law now bites hardest. Since the Data (Use and Access) Act’s automated decision-making provisions commenced on 5 February 2026, solely automated significant decisions about individuals are permitted, but only with safeguards: people must be told, must be able to contest the decision and must be able to obtain human intervention. Special category data stays restricted. The ICO’s draft ADM guidance (consultation closed 29 May 2026) is not yet final, and the Information Commission (which replaced the ICO on 30 September 2026) has yet to publish a final version. Its March 2026 “Recruitment rewired” review found that many employers’ recruitment automation had “no meaningful human involvement”. That is the gap a Tier 3 review exists to close: the human reviewer needs real authority, information and time, not a rubber stamp.

UK firms that use hiring or HR AI in the EU should also note that the AI Act’s high-risk obligations for employment systems now apply from 2 December 2027, following the Digital Omnibus. These are general points; take advice on specific deployments.

Ownership and accountability

Every registered use names four people:

  • Business owner (accountable). Owns the outcome, the workforce effects and the decision to continue. This is usually the head of the function, not IT.

  • System owner (responsible). Owns configuration, testing, change control and the off-switch.

  • Second line (consulted). Data protection, legal, security and HR. Advisory in Tiers 1 and 2, with a veto only in Tier 3.

  • Platform owner. Provides logging, identity, approved models and the register itself.

For agents, add a rule: an agent acts under a named human’s authority and gets its own credentials. Its actions are attributable to that person’s function and never to “the system”.

Audit trails that cost little

Make logging a default of the platform, not a task for each project.

  • For all uses: a register entry (owner, purpose, tier, tool, model and version, data categories) and a change log for prompts, knowledge sources and model upgrades.

  • For Tier 2: stored test results and a record of whether the human accepted, edited or overrode each output, sampled if volumes are large.

  • For Tier 3 and all agents: a per-decision record showing inputs, outputs, the human involved and any challenge. For agents, record every tool call and every approval step as well. That is what lets you explain a decision to the person affected, and the Data (Use and Access) Act has required controllers to handle data protection complaints since 19 June 2026.

Incident response

Extend your security and data-breach process; do not invent a new one.

  • Define an AI incident: a materially wrong output that was acted on, a data exposure, a discriminatory pattern, an agent acting outside its authority, or a sustained rise in override rates.

  • Severity drives action. Any personal-data breach still triggers the UK GDPR test for reporting to the Information Commission within 72 hours. Patterns suggesting unlawful discrimination, or decisions affecting many people, go straight to the accountable executive.

  • Containment first. Every Tier 2 and 3 use needs a tested off-switch and a manual fallback, and staff need permission to stop the line without seeking approval.

  • Review blamelessly and share widely. A short write-up of each incident, circulated to other owners, does more than a new policy.

Keeping it light

  • Pre-approve patterns, not just tools. A “summarise internal documents with the approved assistant” pattern needs no review.

  • Let teams classify their own uses against a ten-question form, and have the central team audit a random 10–20% each quarter.

  • Re-review every use each year and retire unused ones, so the register does not rot.

  • Measure governance itself: median approval time by tier, the share of uses in Tier 3 (it should be small) and incidents per tier.

Worked example: an accounts-payable agent

A firm wants an agent to read supplier invoices, match them to orders and queue payments. Extraction and matching are Tier 2: the agent proposes and clerks clear exceptions. Queuing payments edges towards Tier 3. So the agent cannot release payments or change supplier bank details. Both require a named approver, with bank changes verified by call-back. Every action is logged, and the off-switch reverts the team to manual processing. The review should take weeks, not months, because only the payment step is high consequence.

Smaller firms. A 30-person business can run the same model with one page of rules, a register spreadsheet, a named owner per use and a standing agreement that anything touching hiring, pay or customer money needs the managing director’s sign-off.

Bottom line

Proportionate governance is light on everyday productivity and firm where AI decides about people, money or customers. If most uses are being approved within days and Tier 3 is rare, well documented and occasionally says no, the balance is about right.

Sources

From AI and Jobs: UK, October 2026