How to start with governance and risk
29 August 2026

How to start with governance and risk


Getting started with enterprise AI governance involves choosing a first case with a known answer, such as a shift supervisor checking the maintenance log, to verify results and build trust in the system, and then enforcing permission at retrieval to prevent unauthorised access to sensitive data.

When a large organisation first starts using AsscherAi to query its own data in natural language, the shift supervisor often finds that the initial results are not quite what they expected, and it takes some time to figure out why the answers do not match the known outcomes, a problem that can stall the entire project if not addressed promptly, which is why it is critical to start with a strong foundation in governance and risk.

Choosing a first case

The first step in getting started with enterprise AI governance is to choose a first case that already has a known answer to compare against, this allows the category manager to verify the results and build trust in the system, for example, a shift supervisor checks the maintenance log to see when the last equipment inspection was done, and then uses AsscherAi to ask the same question, if the answers match, it gives confidence that the system is working correctly.

This approach also helps to identify any potential issues with the data or the model, and allows for adjustments to be made before moving on to more complex queries, it is also important to choose a case that is relevant to the business, and that has a clear and measurable outcome, this will help to ensure that the project is focused on delivering value to the organisation.

Enforcing permission

One of the common mistakes that organisations make when implementing AsscherAi is to try to enforce permission by instructing the model to only return certain types of data, however, this approach is flawed, as it relies on the model to understand the nuances of the organisation's permission structure, a better approach is to enforce permission at retrieval, this means that the system checks the user's permissions before returning any data, and only returns the data that the user is authorised to see.

This approach is more secure, and helps to prevent unauthorised access to sensitive data, it also makes it easier to manage permissions, as the organisation can use its existing permission structures and workflows, rather than trying to recreate them in the model, for more information on how to implement permission structures, you can visit our documentation page.

Auditability

Auditability is a critical component of governance and risk, it refers to the ability to track and record all interactions with the system, including what was asked, what was returned, and on what data, this information is essential for ensuring that the system is being used correctly, and for identifying any potential issues or errors.

AsscherAi provides a full audit trail of all interactions, which can be used to track user activity, and to identify any potential security or compliance issues, the audit trail also provides a clear record of what data was used to answer each question, which can be useful for tracking data lineage, and for ensuring that the system is using the most up-to-date and accurate data.

What to stop doing

If the comparison between the known answer and the result from AsscherAi fails, it is often because the organisation is trying to do too much, too soon, in this case, it is necessary to stop and reassess the approach, and to focus on getting the basics right, this may involve stopping certain activities, such as trying to use the system to answer complex queries, or trying to integrate it with other systems.

It is also important to stop trying to use the system as a replacement for human judgment, AsscherAi is a tool that is designed to provide answers to specific questions, it is not a replacement for human decision-making, and it should not be used as such, by focusing on getting the basics right, and by using the system in a way that is consistent with its design, organisations can get the most out of AsscherAi, and can ensure that it is being used in a way that is safe and effective.

What this does not do

AsscherAi is a powerful tool, but it is not a solution to all governance and risk challenges, it is designed to provide answers to specific questions, and to help organisations to get the most out of their data, however, it is not a replacement for other governance and risk activities, such as risk assessments, or compliance monitoring.

Organisations that are looking for a more comprehensive solution to their governance and risk challenges may want to consider other options, such as consulting with a governance and risk expert, or using a more specialised tool, for more information on how to get started with AsscherAi, or to discuss your specific needs, you can contact us through our contact page.

Conclusion of the process

The process of getting started with enterprise AI governance is not a one-time event, but rather an ongoing process, it requires continuous monitoring, and regular assessment, to ensure that the system is being used correctly, and that it is delivering value to the organisation.

By following the steps outlined above, and by using AsscherAi in a way that is consistent with its design, organisations can get the most out of the system, and can ensure that it is being used in a way that is safe and effective, it is also important to remember that governance and risk is an ongoing process, and that it requires continuous attention, and regular review, to ensure that the organisation is meeting its goals, and that it is complying with all relevant regulations.

Frequently asked questions

What is the first step in getting started with enterprise AI governance?

Choosing a first case with a known answer to compare against and verify results.

How can organisations enforce permission when using AsscherAi?

By enforcing permission at retrieval, checking user permissions before returning data.

What is the importance of auditability in governance and risk?

Auditability tracks interactions with the system, ensuring correct use and identifying potential issues.

What should organisations stop doing when implementing AsscherAi?

Trying to do too much too soon, and using the system as a replacement for human judgment.