What Are the Most Common AI Governance Problems?

Staff using AI tools on laptops before an AI policy is in place
The most common AI governance problem is that staff are already using AI tools before any policy exists. Client data gets pasted into public chatbots, and nobody owns the output. The second is confusing AI governance with data or cyber governance: they overlap but they answer different questions.
ISO 27001 and ISO 42001 certifiedNZ based engineers onlyOperating since 2005100+ NZ businesses supported

The Questions We Hear Most Often About AI Governance

Quick Summary: Most owners come to us with the same handful of questions. We’ll answer them here plainly, the way we would on a discovery call.

Most owners come to us with the same handful of questions, so let’s just answer them here the way we would on a discovery call.

One thing worth saying plainly: we won’t build the AI system itself. Our AI Governance work is about getting a use case live and audit ready, step by step. If you need someone to build the model or the automation, that’s a separate conversation, and larger organisations with more complex approval structures usually need more of this groundwork than smaller teams do.

We run this the same way we run our wider security work, starting with a 15 minute founder call and a 45 minute discovery call before anything gets proposed. You can read more about how our AI Governance work fits alongside our broader security services on the main service page.

For cost questions specifically, we keep that on our pricing page rather than guessing here, since the real driver is almost always the size and complexity of the organisation involved.

Call now

Staff Already Using AI Tools Before Any Policy Exists

Most businesses we talk to already have staff using AI tools, whether anyone official knows it or not. Someone in accounts is pasting numbers into ChatGPT to draft a report. A manager is using Copilot to summarise meeting notes. Nobody asked permission, because nobody realised they needed to. This is normal, and we see it in almost every organisation we assess. It’s rarely a sign of recklessness. Staff are just trying to get their work done faster.

The reason it happens before any policy exists is simple: free AI tools are one click away in a browser, and people don’t always stop to think about where their input goes once they hit enter. A client name, a contract clause, or a customer’s personal details can end up inside a public AI tool without anyone actually deciding that should happen. It isn’t a data breach in the traditional sense so much as a line nobody got around to drawing.

What we look at first is what’s being used, by whom, and with what data. That’s part of the Cyber Risk Assessment we run after our 15 minute founder call and 45 minute discovery call, where we map the gaps between what staff are already doing and what a defensible AI use policy needs to cover. From there we build a customised proposal based on what we actually found, not a generic template.

We don’t treat any of this as a reason to lock everything down overnight. Cutting off AI tools cold turkey usually just pushes staff toward using them on personal devices instead, which is worse for oversight, not better. Our AI Governance work is about building rules staff can actually follow, not a document that sits in a folder. If you want to see how that process is structured before you commit to anything, our AI Governance page walks through it in more detail.

If cost is on your mind at this stage, that’s fair. We keep pricing detail on a separate page so you can see what a 90 day governance project involves before you talk to us.

Call 0800 242 206

AI Governance vs Data and Cyber Governance

People mix these up because the words overlap. Cyber governance protects the systems and data you already have. AI Governance controls how you use AI tools inside those systems. They’re related, but they’re not the same project, and buying one doesn’t automatically hand you the other.

Our cyber security work sits under ISO 27001, the certification for information security management. That covers firewalls, access controls, backups, and the SMB1001 framework we use to lift a business’s overall security baseline. In short, it answers the question: is your data and network protected?

AI Governance sits under a separate certification, ISO 42001, for AI management systems. It answers a different question: can you show, in writing, how a specific AI use case was assessed, approved, and put into use? That includes the documentation and risk review needed to get an AI use case live. It doesn’t include building the AI tool itself. This distinction trips up plenty of business owners early on, because they assume good cyber security automatically covers AI use. It doesn’t. A business can have solid firewalls and MFA in place and still have no record of which teams are feeding client data into a chatbot, or why that was ever approved.

In practice we treat them as connected but separate streams. Our Cyber Risk Assessment, part of our standard process, looks at your existing security posture first. From there we can scope an AI Governance project on top of it, built around your actual use cases rather than a generic template. If you want the fuller picture of how that process runs from the first call through to a proposal, our AI Governance page walks through it step by step.

If your business hasn’t done any cyber security foundation work yet, we’d usually say get that assessed first. Governance documentation for an AI tool sitting on top of an unpatched network or shared logins doesn’t hold up well under scrutiny, whether that’s a client audit, an insurer, or an SMB1001 certification review. It’s not that AI Governance goes to waste in that case, it’s that the order matters, and we’ll say so plainly rather than sell the AI project on its own.

Have questions? We’re happy to help.

0800 242 206

Get a free 15-minute IT health check. OxygenIT is ready to help.

What an AI Governance Engagement Delivers

What people ask us most is what they actually walk away with, and that’s a fair question. A lot of AI governance talk stays abstract, all frameworks and no output. Ours is built to end with a documented, live AI use case in your business, not a slide deck that sits in a shared drive.

The engagement starts with a 15 minute founder call, which is really just us working out if we’re the right fit for each other before anyone spends real time on this. If that goes well, we move to a 45 minute discovery call where we dig into how your business works, what data you hold, and where staff are already using AI tools, sanctioned or not.

From there we run a Cyber Risk Assessment. This is the part that finds the gaps, things like where AI tools touch customer data, who has access, and what happens if a model gets something wrong in front of a client. We’ve seen businesses that assumed staff weren’t using AI tools at all, only to discover three different teams already feeding company data into public chatbots. That gap is exactly what the assessment is built to surface.

The output is a custom proposal based on what we found, not a template. Our AI 90 Day Governance Project is the common path from there, delivering the documentation needed to get one AI use case live in your organisation, properly scoped, with the governance and internal controls built around it. What we don’t do is build the AI tool or model itself. That’s a distinct piece of work, and we’re clear about that split from the proposal stage so nobody is caught off guard later.

Where cost comes into it, that depends on the size and complexity of the project, and we set it out properly on our pricing guide rather than guessing here.

Larger organisations with more internal sign-off layers and complex project gateways tend to need more structure around the same core process, which is one reason two businesses the same size can end up on quite different paths through this. If you want the full picture of how this connects to our wider AI Governance work, our AI Governance page covers the rest of it.

Call 0800 242 206

AI Governance Alongside Existing Security Frameworks

Most businesses coming to us already have some security work done, maybe SMB1001 certification, maybe an ISO 27001 project underway, maybe just firewall and endpoint protection sorted. The question we get most is whether AI Governance sits on top of that work or replaces it. The short answer: it sits on top.

ISO 27001 covers information security generally, how you protect data, systems and access across the whole business. ISO 42001 is a different standard, specific to how an organisation manages artificial intelligence, covering things like use case approval, data handling for AI tools, and ongoing oversight once an AI system is live. We hold both certifications, which is uncommon among managed IT providers in New Zealand. Very few carry both, and that’s a deliberate choice on our part, because the two frameworks answer genuinely different questions.

Our cyber security setup is built around the SMB1001 framework, which gives a business a baseline for things like access control, backups and incident response. AI Governance doesn’t touch that baseline. It sits alongside it and asks a narrower question: if this business starts using an AI tool for a specific task, what needs to be documented, who signed off on it, and what data is it touching? That’s a governance question, not an infrastructure one.

One thing worth being upfront about: our AI Governance work covers the documentation needed to get an AI use case live properly. It doesn’t include building the AI itself. If a business wants a custom AI tool built, that’s separate work. What we’re doing is making sure whatever tool gets used, whether it’s built in house or bought off the shelf, has a paper trail and a decision process behind it.

We run most of this as a defined project over 90 days. It starts with a 15 minute founder call to check fit, then a 45 minute discovery call once we’re aligned. From there we run a Cyber Risk Assessment to find the gaps between where the business sits now and where it needs to be, and we come back with a proposal built around what we found rather than a generic template.

You can read more about how this fits into our wider work on our AI Governance page.

Book a review

AI Governance: Frequently Asked Questions

Do we need AI Governance if only a couple of staff use AI tools casually?

Usually, yes. Casual use is where gaps start, like someone pasting client details into a public AI tool without a rule against it. Nobody usually decides that should happen, it just happens because the tool is one click away. Our Cyber Risk Assessment looks at what tools are already in use and what data goes into them before we recommend anything.

Is a written AI policy the same thing as AI Governance?

No, they’re related but not the same. A written policy is a document. AI Governance is the process behind it, including the risk review and documentation needed to show how a specific AI use case was assessed and approved. Our work is built to be audit ready, backed by our ISO 42001 certification for AI management.

Does a smaller business need the same 90 day project as a larger one?

Not always to the same degree. Larger organisations with more complex approval structures usually need more groundwork than smaller teams do. The AI 90 Day Governance Project runs the same timeline for everyone, but the size and complexity of the organisation is the main factor behind how much work that timeline covers.

Can we start AI Governance before our cyber security work is finished?

Yes, they’re separate projects. AI Governance runs the same way our wider security work does, starting with a 15 minute founder call and a 45 minute discovery call before anything gets proposed. Cyber security under ISO 27001 protects your systems and data. AI Governance under ISO 42001 covers how you use AI tools inside them, so one doesn’t have to wait on the other.

What backs up the way you structure AI Governance work?

We hold ISO 42001 certification for AI management ourselves, which is still rare among managed IT providers in New Zealand. That certification shapes how we structure the documentation and risk review work we do for clients. Our cyber security work sits separately under ISO 27001, built around the SMB1001 framework.