
AI governance from inventory to assurance — and why the policy is the easy part
Emerging Risk & Transformation Services • 2026
Executive Summary

Most organizations that have written an artificial intelligence (AI) policy in the past two years cannot produce a list of the AI systems operating inside their business. The policy exists. The inventory does not.
This is the central problem of AI governance, and it is not a documentation problem. AI did not arrive through a procurement process. It arrived through software updates that switched on new features, through vendors who added AI to products the organization already used, through platforms bought by individual departments, and through employees who found a tool useful and simply began using it. None of those routes passes through the approval gate that governs ordinary technology.
The 2026 Verizon Data Breach Investigations Report found that 45% of employees are regular users of AI tools at work, up from 15% a year earlier, and that 67% of users accessing AI services on corporate devices were doing so through non-corporate accounts. In most organizations, a majority of AI use is therefore happening outside whatever governance framework exists on paper.
This article sets out what AI governance actually requires — inventory, classification, decision rights, human oversight, data and vendor control, incident handling, evidence and board reporting — and why the organizations that do it well treat it as a continuous operating discipline rather than a policy project with an end date.
1. Governance Arrived After the Technology

Most enterprise technology is governed because it was procured. Someone raised a request, someone assessed it, someone approved a budget, and the approval carried conditions. Governance was a by-product of buying.
AI broke that sequence. A large share of the AI in any given organization was never bought as AI. It was included in something already owned, or adopted by an individual at no cost, or embedded in a service by a supplier who did not think to mention it. There was no purchase decision to attach conditions to.
This explains why AI governance so often feels like retrofitting. It is retrofitting. The organization is attempting to establish control over something that entered without passing any control point, and it is doing so while adoption continues to accelerate. That is an uncomfortable position, but it is a normal one, and recognizing it changes where the work starts.
2. Shadow AI Is an Inventory Problem Before It Is a Risk Problem

Shadow AI is usually discussed as a data-leakage risk, and it is one. But the more immediate consequence is that the organization cannot describe its own exposure.
Every subsequent governance decision depends on the inventory. Which use cases need human oversight? Which vendors need assessment? Which systems touch personal data? Which decisions are being influenced by a model nobody has evaluated? Each of those questions presupposes a list, and most organizations do not have one.
Building it is more archaeology than audit. It means reviewing software already in use for AI features that have been enabled, surveying departments about tools they have adopted, examining expense claims and corporate card transactions, asking vendors directly what AI sits inside the services they provide, and reviewing network and identity logs for AI services being accessed. The first pass is always incomplete. Doing it anyway is what converts governance from aspiration into practice.
3. Why an AI Policy Is Not AI Governance

A policy states what should happen. Governance is the set of arrangements that make it happen and demonstrate that it did.
The gap between the two is where most AI governance programmes fail. An acceptable-use policy that no one is trained on, that no system enforces, that no one monitors compliance with, and that has no consequence attached, changes very little. It does, however, create a documented standard against which the organization can later be measured — which means a policy without supporting controls can increase legal exposure rather than reduce it.
The useful question is not whether the organization has a policy. It is whether, for each statement in that policy, someone can name the control that gives effect to it and the evidence that it operated.
4. Who Approves an AI Use Case?

In most organizations the honest answer is nobody, or everybody, depending on the day.
An effective approval route needs four things: a defined threshold above which approval is required, a named approver appropriate to the risk level, a record of what was approved and on what basis, and a review point at which the approval is revisited. None of this needs to be elaborate. A single register, a simple classification and a standing agenda item will govern more effectively than an elaborate framework nobody uses.
What matters most is that the threshold is set low enough to catch consequential use cases and high enough that routine use does not require permission. Set it too high and governance misses what matters. Set it too low and employees route around it, which returns the organization to Shadow AI by a different path.
5. Not Every Use Case Needs the Same Governance

Governance intensity should follow consequence. An employee using AI to rephrase an internal email and an automated system influencing credit decisions are both AI use cases, and treating them identically wastes effort on the first and under-protects the second.
A workable classification considers who is affected and how severely, whether the output influences a decision about a person, whether money or contractual obligation is involved, how sensitive the data is, whether the action is reversible, whether the output reaches anyone outside the organization, and whether a regulator would take an interest.
Three tiers are usually enough. Lower-risk use cases need disclosure and general awareness. Moderate-risk use cases need documented human review and a named owner. Higher-risk use cases need formal approval, evaluation before deployment, mandatory human decision points, retained evidence and board visibility.
6. Decision Rights and Human Oversight
The phrase “human in the loop” is used more often than it is specified. A loop with a human in it who cannot realistically intervene is not oversight.
Meaningful oversight requires that the reviewer has the information needed to disagree, the time to consider it, the authority to overrule, and no incentive structure that punishes them for doing so. A reviewer processing outputs at a rate that makes genuine consideration impossible is providing the appearance of control, and the appearance is worse than the absence, because the organization believes it is protected.
Where an AI system materially influences a decision about a person — employment, credit, eligibility, pricing, service — the organization should be able to say who made the final decision, what they saw, and what they were able to change.
7. Data: What the Organization Is Actually Handing Over

Every AI interaction involves supplying information to a system, and organizations are frequently unclear about what is being supplied, where it goes, how long it is retained, and whether it contributes to the improvement of a model outside their control.
The governance requirements are not exotic. Classify what may and may not be provided to which categories of tool. Ensure that enterprise arrangements with appropriate data terms exist for the tools employees actually need, because prohibition without provision produces Shadow AI. Understand the retention and training terms of each significant vendor. And check that existing privacy obligations — notice, lawful basis, data subject rights, cross-border transfer — have actually been considered for AI processing, rather than assumed to be covered by policies written before it.
8. Vendor and Third-Party AI Governance

A significant share of an organization’s AI exposure sits inside services provided by others, and much of it arrived without notification.
Vendor governance for AI means knowing which suppliers use AI in delivering services to the organization, what data those systems process, what the contract says about AI use and data handling, whether the vendor will notify the organization of material changes to its AI functionality, and what happens to the organization’s data if the relationship ends.
Existing vendor assessments frequently predate the AI functionality now embedded in the service. The question is not whether the vendor was assessed. It is whether the vendor was assessed for what it does now.
9. Cybersecurity and AI

AI changes the security picture in both directions, and governance must address both.
AI systems create new attack surface: credentials and access granted to AI tools and agents, data flowing to external services, integrations between AI platforms and core systems, and the risk of manipulation through crafted inputs. At the same time, attackers use AI to improve the quality and volume of social engineering, which raises the baseline threat against every organization regardless of its own AI adoption.
The governance implication is that AI risk and cyber risk cannot be managed in separate registers by separate teams that meet quarterly. In organizations of Caribbean scale, they are frequently the same small group of people, which is an advantage if the reporting structure recognizes it.
10. Employee Practice Is the Layer Policy Cannot Reach

Most AI use in most organizations is individual, informal and well-intentioned. An employee uses a tool because it helps them do their job. They are not circumventing governance; in most cases they are unaware that governance applies.
This is a training and enablement problem as much as a control problem. Employees need to know which tools are approved and why, what may never be entered into any AI system, when human verification is mandatory, how to recognize an AI-related incident, and who to ask. They also need approved tools that are good enough to use, because the most reliable driver of Shadow AI is an official option that is worse than the unofficial one.
11. Incidents: What Counts, and Who Hears About It

Most organizations have no definition of an AI incident, which means they have no incident reports, which is frequently mistaken for having no incidents.
A workable definition covers confidential or personal information provided to an unapproved system; a materially incorrect AI output that reached a decision, a customer or a published document; an AI system operating outside its approved scope; a vendor AI change that altered the risk profile without notice; and any AI-related matter that would embarrass the organization if it became public.
The reporting route should be the existing one. A separate AI incident process will not be used. What is needed is for the existing process to recognize AI incidents as reportable, and for someone to be accountable for the pattern across them.
12. Regulation: The Existing Law Already Applies

Discussion of AI regulation tends to focus on what is coming. That focus can obscure a more immediate point: existing law applies to AI-supported activity now.
Privacy and data protection obligations apply to personal data processed by AI. Consumer protection law applies to AI-generated customer communications. Employment law applies to AI-influenced hiring and performance decisions. Financial services regulation applies to AI-influenced credit, pricing and advice. Professional standards apply to AI-assisted professional work. Sector regulators can ask how an AI-influenced decision was reached, and “the system produced it” is not an answer.
Preparing for future AI-specific regulation is prudent. Complying with current law is not optional, and the governance structures needed for the first are largely the ones needed for the second.
13. Evidence: The Difference Between Policy and Control

There is a growing gap between organizations that can say they govern AI responsibly and organizations that can show it.
Demonstrating it requires artefacts that exist as a by-product of the governance operating: a current inventory with owners, classification records, approval records with the basis of approval, evidence of human review at the points where it was required, training records, vendor assessments, incident records and their resolution, testing results, exception registers, and board reporting with what was reported and when.
The distinguishing feature of these artefacts is that they cannot be produced retrospectively. An organization that decides in month eleven to evidence a year of governance will find the evidence was never created. This is the strongest practical argument for building evidence into the design rather than adding it before an assessment.
14. Board Oversight

Directors are increasingly expected to demonstrate oversight of AI risk, and most boards currently receive either nothing about AI or a technology update that does not address governance.
Useful board reporting is short and consistent: what AI is in use and what has changed; where the highest-consequence use cases sit and who owns them; what incidents or exceptions occurred; what the regulatory position is; what evidence exists that key controls operate; and what management is asking the board to decide. A single page reported consistently is worth more than a substantial paper delivered once.
15. The Caribbean Context
Caribbean organizations face the same AI governance requirements as larger institutions, with four differences.
Specialist capacity is scarce, so governance must be designed for a small team rather than a dedicated function. Cross-border operations mean a group may face several regulatory regimes and different data-protection regimes across territories where it operates as one business. Shared service providers create concentration: a single regional technology vendor may sit behind many institutions, so its AI decisions propagate widely. And organizational proximity cuts both ways — informal culture makes Shadow AI easier, and it also makes a genuine inventory achievable in weeks rather than quarters, because there are fewer people to ask.
Proportionate governance is not weaker governance. It is governance designed for the organization that has to operate it.
16. Composite Caribbean Case Study
A composite Caribbean financial-services organization had an AI policy approved by its board and believed its position was reasonable.
An inventory exercise identified substantially more AI in use than management expected: several generative tools adopted by individual departments, AI functionality enabled by default within platforms already licensed, two vendor services with AI components that predated any assessment, and a number of employee-led use cases with no formal approval. Some involved customer information.
The programme that followed introduced an enterprise inventory with named owners, a three-tier use-case classification, an acceptable-use policy paired with approved enterprise tooling, vendor reassessment for AI functionality, defined human-review requirements for higher-risk cases, approval workflows, staff training, AI incident reporting through the existing channel, and quarterly board reporting.
The organization did not reduce its use of AI. It gained the ability to describe it.
This is an anonymized composite illustration drawn from patterns commonly observed in the region. It does not describe any specific Dawgen Global client.
17. A Practical AI Governance Lifecycle

Governance is not a project with a completion date, because the technology, the regulation and the organization’s own use of AI all continue to change. The five stages below run continuously on a governance calendar.
ASSESS. Establish the inventory, maturity position and exposure — including Shadow AI.
DESIGN. Set the framework, decision rights, classification, policies, oversight rules and vendor standards.
IMPLEMENT. Put approval workflows, controls, training, incident procedures and registers into operation.
MONITOR. Review the inventory, exceptions, incidents, vendor changes and regulatory developments on a defined cycle.
ASSURE. Test whether the controls operate, and hold the evidence that shows it.
18. What Management and Boards Should See

Ten measures, reported on the same basis each period.
19. Questions Boards and Executives Should Ask

Twelve questions that reveal whether governance exists in practice or only on paper.
20. The Dawgen Global Perspective

AI governance is frequently presented as a compliance burden that slows adoption. In our experience the opposite is closer to the truth: the organizations that can describe their AI environment are the ones able to expand it with confidence, because they can answer the questions that would otherwise stop a deployment at the executive committee.
The objective is not to constrain AI. It is to reach the point where the organization can say what it is using, who approved it, what it can access, who is accountable for it, and how it knows the controls work. An organization that can answer those five questions can scale. One that cannot is expanding an exposure it has not measured.
21. How Dawgen Global Can Help

TRUST360™ establishes, operates, monitors and continuously improves AI governance — from the first inventory through framework design and implementation to monitoring and assurance readiness.
Conclusion

The AI policy is the easy part. It can be written in a week, and many have been.
What takes longer, and matters more, is the inventory that tells the organization what it actually has, the classification that directs effort to what matters, the controls that give the policy effect, and the evidence that shows all of it operated. None of that is exotic. It is ordinary governance discipline applied to a technology that arrived without passing through the door where governance usually waits.
Start with the Dawgen AI Governance Maturity Diagnostic

The Diagnostic examines AI strategy, governance and accountability, inventory and Shadow AI, risk classification, data and privacy, cybersecurity, third parties, human oversight, policies and controls, employee practice, incidents, monitoring and reporting, and assurance readiness — across 12 dimensions and 120 scored observations. The result is a maturity score, a prioritized risk profile and a practical roadmap.
Typical duration. 3–4 weeks. Delivery model. Remote, hybrid or on-site across the Caribbean. Fees. Fixed-scope and quoted in writing after a short scoping conversation.
Dawgen Global helps organizations make Smarter and More Effective Decisions.
Contact
Email [email protected]
Web dawgen.global
Enquiries dawgen.global/contact-us
Dawgen Global operates as a borderless practice across more than fifteen Caribbean territories. Enquiries arising from this publication are handled by email and routed to the relevant service line, wherever the client and the specialist happen to sit.
Sources
- 2026 Data Breach Investigations Report. 19 May 2026. Cited for workplace AI adoption (45% of employees regular users, up from 15%) and non-corporate account usage (67%).
Important Notices
Client acceptance. All requests for Dawgen Global services are subject to the firm’s client acceptance procedures, including an independence and conflict-of-interest check, before any engagement is accepted.
Independence and scope of service. Where Dawgen Global or an associated firm provides audit or other assurance services to an entity, the services described in this article are provided only to the extent permitted by applicable ethical and independence requirements, including the International Code of Ethics for Professional Accountants issued by the International Ethics Standards Board for Accountants (IESBA). Dawgen Global does not provide independent assurance over a governance framework the firm itself designed for an assurance client.
Nature of the work. Unless an engagement letter expressly provides otherwise, the services described here are advisory in nature. They are not an audit, review or assurance engagement performed under International Standards on Auditing or International Standard on Assurance Engagements 3000 (Revised), and no assurance opinion or conclusion is expressed.
Not legal advice. Privacy, consumer-protection, employment, financial services and sector-specific obligations differ by jurisdiction and use case. Nothing in this article is legal advice, and legal positions should be confirmed with qualified counsel in each territory.
Third-party research. Statistics attributed to third parties are taken from the sources listed and have not been independently verified by Dawgen Global.
Illustrative material. Case studies are anonymized composite illustrations drawn from patterns commonly observed in the region and do not describe any specific Dawgen Global client.
General information only. This article is general in nature, does not take account of the circumstances of any particular organization, and should not be relied upon as professional advice.
Dawgen Global is an independent, integrated multidisciplinary professional services firm and is not a member of any international network.
© 2026 Dawgen Global. All rights reserved.
About Dawgen Global
Dawgen Global is an independent, integrated multidisciplinary professional services firm headquartered at 47 Trinidad Terrace, New Kingston, Jamaica, serving more than 15 territories across the Caribbean. Founded and led by Dr. Dawkins Brown, Executive Chairman, the firm is independent and not affiliated with any international network. It delivers a full suite of professional services under one roof: audit and assurance; tax advisory; IT and digital transformation; risk management; cybersecurity; actuarial and insurance regulatory advisory; HR advisory; mergers and acquisitions; corporate recovery; business advisory and strategy; accounting BPO and virtual CFO services; and legal process outsourcing.
The proposition is simple: big-firm capability without the big-firm price. Dawgen Global’s integrated approach is built for the specific complexities and opportunities of the Caribbean market, helping organizations make sharper, better-informed decisions that drive measurable progress.
To explore a partnership, reach out:
- Website: dawgen.global
- Email: [email protected]
- WhatsApp (Global): +1 555-795-9071
- Caribbean offices: +1 876-665-5926 | +1 876-929-3670 | +1 876-926-5210

