What Are the Most Common AI Governance Problems?

The Questions We Hear Most Often About AI Governance
Most owners come to us with the same handful of questions, so let’s just answer them here the way we would on a discovery call.
- Do we need this if staff only use ChatGPT casually? Usually, yes. Casual use without any rules is exactly where governance gaps start, with staff pasting client data into a public tool without knowing where it ends up.
- How long does it take to get sorted? Our AI 90 Day Governance Project runs on a 90 day timeline, from the Cyber Risk Assessment through to a documented, live AI use case.
- Will this slow down our team? No. The goal is to get one use case live with proper documentation, not to bury everyday work under extra layers of approval.
- Does this replace our existing tools? No, we don’t build or replace your AI tools. We handle the documentation needed to get a use case live safely.
- How does this connect to ISO 42001? We hold ISO 42001 certification for AI management ourselves, which is still rare among managed IT providers in New Zealand, and it shapes how we structure the governance work we do for clients.
- What if we don’t have an AI use case yet? That’s common. Part of the discovery process is working out which use case actually makes sense before any governance documentation gets built.
One thing worth saying plainly: we won’t build the AI system itself. Our AI Governance work is about getting a use case live and audit ready, step by step. If you need someone to build the model or the automation, that’s a separate conversation, and larger organisations with more complex approval structures usually need more of this groundwork than smaller teams do.
We run this the same way we run our wider security work, starting with a 15 minute founder call and a 45 minute discovery call before anything gets proposed. You can read more about how our AI Governance work fits alongside our broader security services on the main service page.
For cost questions specifically, we keep that on our pricing page rather than guessing here, since the real driver is almost always the size and complexity of the organisation involved.
Staff Already Using AI Tools Before Any Policy Exists
Most businesses we talk to already have staff using AI tools, whether anyone official knows it or not. Someone in accounts is pasting numbers into ChatGPT to draft a report. A manager is using Copilot to summarise meeting notes. Nobody asked permission, because nobody realised they needed to. This is normal, and we see it in almost every organisation we assess. It’s rarely a sign of recklessness. Staff are just trying to get their work done faster.
The reason it happens before any policy exists is simple: free AI tools are one click away in a browser, and people don’t always stop to think about where their input goes once they hit enter. A client name, a contract clause, or a customer’s personal details can end up inside a public AI tool without anyone actually deciding that should happen. It isn’t a data breach in the traditional sense so much as a line nobody got around to drawing.
What we look at first is what’s being used, by whom, and with what data. That’s part of the Cyber Risk Assessment we run after our 15 minute founder call and 45 minute discovery call, where we map the gaps between what staff are already doing and what a defensible AI use policy needs to cover. From there we build a customised proposal based on what we actually found, not a generic template.
- Which tools staff are already using day to day, including free consumer versions
- What kind of data gets typed or pasted into those tools
- Whether Microsoft 365 or Copilot access is already licensed but ungoverned
- Where a written policy is missing entirely versus where one exists but nobody actually follows it
We don’t treat any of this as a reason to lock everything down overnight. Cutting off AI tools cold turkey usually just pushes staff toward using them on personal devices instead, which is worse for oversight, not better. Our AI Governance work is about building rules staff can actually follow, not a document that sits in a folder. If you want to see how that process is structured before you commit to anything, our AI Governance page walks through it in more detail.
If cost is on your mind at this stage, that’s fair. We keep pricing detail on a separate page so you can see what a 90 day governance project involves before you talk to us.
AI Governance vs Data and Cyber Governance
People mix these up because the words overlap. Cyber governance protects the systems and data you already have. AI Governance controls how you use AI tools inside those systems. They’re related, but they’re not the same project, and buying one doesn’t automatically hand you the other.
Our cyber security work sits under ISO 27001, the certification for information security management. That covers firewalls, access controls, backups, and the SMB1001 framework we use to lift a business’s overall security baseline. In short, it answers the question: is your data and network protected?
AI Governance sits under a separate certification, ISO 42001, for AI management systems. It answers a different question: can you show, in writing, how a specific AI use case was assessed, approved, and put into use? That includes the documentation and risk review needed to get an AI use case live. It doesn’t include building the AI tool itself. This distinction trips up plenty of business owners early on, because they assume good cyber security automatically covers AI use. It doesn’t. A business can have solid firewalls and MFA in place and still have no record of which teams are feeding client data into a chatbot, or why that was ever approved.
In practice we treat them as connected but separate streams. Our Cyber Risk Assessment, part of our standard process, looks at your existing security posture first. From there we can scope an AI Governance project on top of it, built around your actual use cases rather than a generic template. If you want the fuller picture of how that process runs from the first call through to a proposal, our AI Governance page walks through it step by step.
If your business hasn’t done any cyber security foundation work yet, we’d usually say get that assessed first. Governance documentation for an AI tool sitting on top of an unpatched network or shared logins doesn’t hold up well under scrutiny, whether that’s a client audit, an insurer, or an SMB1001 certification review. It’s not that AI Governance goes to waste in that case, it’s that the order matters, and we’ll say so plainly rather than sell the AI project on its own.
Have questions? We’re happy to help.
Get a free 15-minute IT health check. OxygenIT is ready to help.
What an AI Governance Engagement Delivers
What people ask us most is what they actually walk away with, and that’s a fair question. A lot of AI governance talk stays abstract, all frameworks and no output. Ours is built to end with a documented, live AI use case in your business, not a slide deck that sits in a shared drive.
The engagement starts with a 15 minute founder call, which is really just us working out if we’re the right fit for each other before anyone spends real time on this. If that goes well, we move to a 45 minute discovery call where we dig into how your business works, what data you hold, and where staff are already using AI tools, sanctioned or not.
From there we run a Cyber Risk Assessment. This is the part that finds the gaps, things like where AI tools touch customer data, who has access, and what happens if a model gets something wrong in front of a client. We’ve seen businesses that assumed staff weren’t using AI tools at all, only to discover three different teams already feeding company data into public chatbots. That gap is exactly what the assessment is built to surface.
The output is a custom proposal based on what we found, not a template. Our AI 90 Day Governance Project is the common path from there, delivering the documentation needed to get one AI use case live in your organisation, properly scoped, with the governance and internal controls built around it. What we don’t do is build the AI tool or model itself. That’s a distinct piece of work, and we’re clear about that split from the proposal stage so nobody is caught off guard later.
- Founder call (15 minutes) to check fit before anything is scoped
- Discovery call (45 minutes) to map current AI use and data exposure
- Cyber Risk Assessment to identify governance gaps
- Custom proposal built on assessment findings, not a fixed template
- Documentation and process to take one AI use case live within the 90 day project
Where cost comes into it, that depends on the size and complexity of the project, and we set it out properly on our pricing guide rather than guessing here.
Larger organisations with more internal sign-off layers and complex project gateways tend to need more structure around the same core process, which is one reason two businesses the same size can end up on quite different paths through this. If you want the full picture of how this connects to our wider AI Governance work, our AI Governance page covers the rest of it.
AI Governance Alongside Existing Security Frameworks
Most businesses coming to us already have some security work done, maybe SMB1001 certification, maybe an ISO 27001 project underway, maybe just firewall and endpoint protection sorted. The question we get most is whether AI Governance sits on top of that work or replaces it. The short answer: it sits on top.
ISO 27001 covers information security generally, how you protect data, systems and access across the whole business. ISO 42001 is a different standard, specific to how an organisation manages artificial intelligence, covering things like use case approval, data handling for AI tools, and ongoing oversight once an AI system is live. We hold both certifications, which is uncommon among managed IT providers in New Zealand. Very few carry both, and that’s a deliberate choice on our part, because the two frameworks answer genuinely different questions.
Our cyber security setup is built around the SMB1001 framework, which gives a business a baseline for things like access control, backups and incident response. AI Governance doesn’t touch that baseline. It sits alongside it and asks a narrower question: if this business starts using an AI tool for a specific task, what needs to be documented, who signed off on it, and what data is it touching? That’s a governance question, not an infrastructure one.
One thing worth being upfront about: our AI Governance work covers the documentation needed to get an AI use case live properly. It doesn’t include building the AI itself. If a business wants a custom AI tool built, that’s separate work. What we’re doing is making sure whatever tool gets used, whether it’s built in house or bought off the shelf, has a paper trail and a decision process behind it.
We run most of this as a defined project over 90 days. It starts with a 15 minute founder call to check fit, then a 45 minute discovery call once we’re aligned. From there we run a Cyber Risk Assessment to find the gaps between where the business sits now and where it needs to be, and we come back with a proposal built around what we found rather than a generic template.
You can read more about how this fits into our wider work on our AI Governance page.
AI Governance: Frequently Asked Questions
Do we need AI Governance if only a couple of staff use AI tools casually?
Usually, yes. Casual use is where gaps start, like someone pasting client details into a public AI tool without a rule against it. Nobody usually decides that should happen, it just happens because the tool is one click away. Our Cyber Risk Assessment looks at what tools are already in use and what data goes into them before we recommend anything.
Is a written AI policy the same thing as AI Governance?
No, they’re related but not the same. A written policy is a document. AI Governance is the process behind it, including the risk review and documentation needed to show how a specific AI use case was assessed and approved. Our work is built to be audit ready, backed by our ISO 42001 certification for AI management.
Does a smaller business need the same 90 day project as a larger one?
Not always to the same degree. Larger organisations with more complex approval structures usually need more groundwork than smaller teams do. The AI 90 Day Governance Project runs the same timeline for everyone, but the size and complexity of the organisation is the main factor behind how much work that timeline covers.
Can we start AI Governance before our cyber security work is finished?
Yes, they’re separate projects. AI Governance runs the same way our wider security work does, starting with a 15 minute founder call and a 45 minute discovery call before anything gets proposed. Cyber security under ISO 27001 protects your systems and data. AI Governance under ISO 42001 covers how you use AI tools inside them, so one doesn’t have to wait on the other.
What backs up the way you structure AI Governance work?
We hold ISO 42001 certification for AI management ourselves, which is still rare among managed IT providers in New Zealand. That certification shapes how we structure the documentation and risk review work we do for clients. Our cyber security work sits separately under ISO 27001, built around the SMB1001 framework.
Related reading