What AI governance means for outsourced operations

- AI governance is the set of policies, controls, and accountability structures that decide how an organisation uses AI: which tools are allowed, what data they touch, who owns AI-driven decisions, and how those decisions are recorded.
- It matters now because regulation is arriving and most companies have no visibility over the AI their staff already use every day.
- The honest limitation: AI is opaque and probabilistic by nature, so governance is about accountability and traceability, not perfect control.
- To start, write a policy, document how AI is actually used, then layer in access controls, a human in the loop, and audit trails.
AI is being adopted inside businesses far faster than anyone is governing it. Teams run sensitive work through personal ChatGPT and Claude accounts, tools make decisions no one is tracking, and regulation is arriving to meet all of it.
For companies that outsource, the exposure is shared, because a provider’s AI use quickly becomes the client’s risk too.
Andy Schachtel, founder and president/CEO of Sourcefit, raised this on the Outsource Accelerator Podcast, arguing that most companies are simply not ready.
His experience, along with the emerging rules, informs the guide below on what AI governance is, why it matters now, and how to start.
What is AI governance?
AI governance is how an organisation decides and controls the way AI is used across its operations. In practice it covers which tools are approved, what data and systems those tools can access, who is accountable for decisions AI influences, and how everything is documented.
It applies as much to the artificial intelligence embedded in your vendors’ workflows as to the tools your own teams run.
The reason it needs formal structure is that AI does not behave like traditional software. As Andy puts it:
“AI is not transparent by nature. It’s not even deterministic by nature. It’s like probabilistic and it’s opaque. So you don’t really know what went into a decision.”

Established frameworks now exist to bring order to this, including the intergovernmental OECD AI Principles, which set out expectations for trustworthy, accountable AI that governance programs can build on.
Why does AI governance matter now?
The rules are no longer theoretical. The EU AI Act, the first comprehensive AI law, is phasing in with real obligations for high-risk systems, and standards like ISO/IEC 42001 give organisations a certifiable way to manage AI.
Andy’s warning is blunt.
“Regulation is here already, and it’s real… companies, enterprises, they need to be thinking about AI governance and compliance, and they’re not.”
The bigger blind spot is “shadow AI,” the tools employees adopt on their own. Most organisations cannot say what their people are feeding into AI or what those tools can reach.
“Does the company have visibility and understanding of how everyone’s using the AI and what it’s accessing? Are there any controls or guidelines in place for that usage? In a lot of cases, probably not.”
For outsourced operations, this compounds. If a provider uses an AI recruitment or AI-augmented BPO tool on your behalf, you can be accountable for how it treats candidates or customer data, even if you never chose the tool.
The 4 pillars of AI governance
Andy frames a practical AI governance program around four pillars. Each maps to a question a regulator or client could ask.
1. Visibility over every AI touchpoint
You cannot govern what you cannot see, so the starting point is a map and inventory of where AI is used. That means recording what each tool does, what data it sees, and what decisions it makes at each step.
“Every AI touchpoint needs to be mapped. What is AI doing? What does it see? And what decisions is it making at each step?”

2. A human in the loop
Every consequential decision needs a named person with authority over it, not an agent operating unsupervised. This is what makes accountability real when something is questioned.
“There has to be someone in authority at every decision point. So if a regulator or a client comes in and says, ‘Well, AI made this decision,’ who is responsible for AI making this decision?”
3. An audit trail
Because AI decisions are opaque after the fact, you need a record of what happened. A history of inputs, outputs, and approvals is what lets you answer an audit or investigation months later rather than guessing.
4. Escalation protocols
When AI makes a mistake or exposes data it should not, there has to be a defined path to catch it and act. Knowing in advance who is alerted and how the issue is contained is the difference between a contained incident and a compliance failure.
How to build an AI governance framework
Building AI governance does not require a full program on day one. Andy’s advice is to start small and layer it up, in three practical stages.
Start with a policy
A written policy is the cheapest, fastest first move, and it does not need to be perfect. It sets out what staff can and cannot do with AI, and it gives you a foundation to build on.
“Just make a policy, which you can have Claude make. That’s a good first step. And then after you have a policy, start with documentation.”
Document how AI is actually used
Next, get an honest inventory of reality. Have every team list the tools they use, what data those tools touch, and for what tasks, so shadow AI comes into the open. Only once you can see the real usage can you judge which parts carry the most risk.
Build in controls and oversight
With visibility in place, add the guardrails: consistent security settings, clear rules on which systems and data AI may access, a human in the loop at key decision points, and audit trails.
Frameworks such as the NIST AI Risk Management Framework treat human oversight as a core control and give you a structured backbone. Built into the architecture of every automation, these controls make AI adoption defensible rather than slowing it down.
FAQs
Who is responsible when AI makes a wrong decision?
The organisation using the tool, not the vendor that built it. That is why a human in the loop and a clear owner at each decision point are central to AI governance.
What is shadow AI, and why is it a risk?
Shadow AI is the unapproved AI tools employees use on their own, often with sensitive data. It is a risk because the organisation has no visibility or controls over what those tools access or produce.
Does the EU AI Act apply to my outsourcing provider?
It can apply across the chain. If AI is used in high-risk processes tied to the EU market, both the deployer and the client can carry obligations, so a provider’s compliance becomes your concern.
How do I start an AI governance program?
Begin with a written policy, then document how AI is actually used across the business. Once you can see the usage, add access controls, human oversight, audit trails, and escalation paths.
Key takeaways
- AI governance is about accountability and traceability across every tool your organisation and its vendors use.
- Regulation like the EU AI Act and standards like ISO/IEC 42001 make this a near-term compliance issue, not a future one.
- Shadow AI is the most common blind spot, especially in outsourced operations where a provider’s tools become your risk.
- Start with a policy and documentation, then build in visibility, a human in the loop, audit trails, and escalation.







Independent




