roughdigits

How we work / Governance

Data and AI governance

Governance means knowing exactly who and what can reach your data, and being able to show what happened to it. Add AI to the mix and it becomes urgent. Governance closes the gaps leaks come through.

Governance, in one picture

Every move leaves a record.

Each time data moves, the record shows who, what, where, when, how and with what. Approved moves go through. The one that should not, is stopped and written down.

WhenWhoWhatWhereHowWith whatResult
Approved, let through and recordedNot approved, blocked and recorded

Illustrative: made-up teams and systems, one blocked request shown. Governance closes the gaps leaks come through; it does not promise nothing ever leaks.

What governance really is

Strip away the jargon and data governance comes down to two things.

Protection: your data can be reached only by the people, and the systems, that should reach it.

Accountability, from end to end: for every piece of data that matters, you can answer six questions.

  1. 1

    Who

    Which person reached it, or which system acting for one.

  2. 2

    What

    What was done: read, changed, copied, shared or deleted.

  3. 3

    Where

    In which system, on which device, in which country.

  4. 4

    When

    The date and time, kept long enough to look back.

  5. 5

    How

    Through which app, connection or route.

  6. 6

    With what

    With which account, key, tool or AI service.

Systems count as much as people. Integrations, automations, service accounts and now AI agents read and move data all day, often with more access than any one person. IBM's 2026 research found fewer than half of organisations are actively securing these non-human identities (IBM, 2026 Cost of a Data Breach findings, read 04/10/2026).

Answering those six questions takes an audit trail on the data that matters, and controls and policies on who and what may reach it and where it may flow. Together they build a picture of normal use, so misuse stands out.

Then AI arrives

AI comes into an organisation three ways at once:

  • Tools staff sign up for, often on their own cards, so nobody else knows they exist.
  • AI features switched on inside software you already pay for: no purchase, no approval, new data flows.
  • Usage bills from AI providers that grow with every request.

Shadow AI is AI used without approval. People paste customer details, contracts, source code and plans into tools nobody approved, usually to get a job done faster and with no real sense of where that data goes next. It is rarely malicious, which is exactly why it gets missed. Nobody keeps a list of these tools, so nobody can say where the data went.

45%
Of employees now use AI tools frequently at work, up from 15% a year earlier. Verizon, 2026 Data Breach Investigations Report, release of 19/05/2026, read 04/10/2026.
3rd
Shadow AI is now the third most common non-malicious data-leak activity Verizon sees. Same source.
92%
Of organisations that had an AI-related breach lacked proper AI access controls; only 40% of all organisations use access controls on AI models and data. IBM, 2026 Cost of a Data Breach findings, read 04/10/2026.
USD 4.99m
Average cost of a data breach worldwide, a record. IBM and Ponemon Institute, Cost of a Data Breach Report 2026, read 04/10/2026.

IBM and Verizon both sell security products and services. The average breach cost is across the organisations studied, mostly larger ones; a small business's cost will be different.

The risks, now and later

Straight away

  • Personal data pasted into a tool you do not control can be a data breach under data protection law, with the duty to report it that follows.
  • Client data sent to an unapproved tool can breach your contract and your confidentiality agreement with that client.
  • Company know-how, source code, prices and plans leave the building, and there is no record of where they went.
  • When a client or a regulator asks what happened, there is no audit trail to answer from.

Over time

  • Data handed over under terms nobody read may be kept by the provider and, depending on those terms, used to improve its service. It cannot be called back.
  • AI agents and automations pile up access nobody reviews, and act with it day and night.
  • Habits harden. The longer AI use runs ungoverned, the harder it is to bring it back under control without stopping the work it supports.
  • Trust is slow to rebuild. Clients who learn their data went into a tool nobody approved do not need a regulator to tell them what to think.

Regulators already set the ceiling. Under Europe's data protection law (GDPR), fines reach EUR 20 million or 4% of worldwide yearly turnover, whichever is higher (GDPR, Article 83, read 04/10/2026). Europe's AI Act sets fines of up to EUR 15 million or 3% of worldwide turnover for breaking the obligations on those who provide and use AI systems, and up to EUR 35 million or 7% for banned practices; for smaller businesses the lower of the two figures applies (EU AI Act, Article 99, read 04/10/2026). Rules differ by country, and which ones apply to you is a question for your legal advisers.

Start simply: quick wins for any size

Governance does not have to start with a programme. These seven steps work for one person and for a global company; what changes is how much there is to list and who does it.

  1. 1

    List where your data lives, and the AI in use

    Every system, shared drive, app and AI tool, with what it holds and who owns it. On your own: one page and half an hour. A team: one shared sheet. A large organisation: start with one business unit, and use sign-in and network records to find what nobody listed.

  2. 2

    Write the one-page AI rule

    What never goes into AI (for example personal data, client confidential data, passwords and keys, unreleased source code), and which approved tools may be used for what.

  3. 3

    Move AI use onto business accounts

    Use approved tools through company accounts whose data terms you have read, not personal free accounts that nobody can see into.

  4. 4

    Lock the front doors

    Everyone signs in with their own account, multi-factor sign-in is on for email and anything holding personal or client data, and access goes the day someone leaves.

  5. 5

    Give systems the same scrutiny as people

    List connected apps, service accounts, API keys and AI agents. Remove anything nobody owns, and give the rest only the access they need.

  6. 6

    Switch on the audit trail

    Most business software already records who did what. Turn it on, keep it long enough to look back, and look at it.

  7. 7

    Name an owner and review

    One person owns the list and the rule, and reviews them: monthly at first, then quarterly. On your own, that person is you.

For the bigger picture, the US National Institute of Standards and Technology's AI Risk Management Framework is free and voluntary, built around four functions (Govern, Map, Measure and Manage), with a profile for generative AI published in July 2024 (NIST, read 04/10/2026).

Why governance is the foundation of good spend management

The list governance needs is the same list spend management needs: every system, every AI use, who owns it, and who and what can reach it. You cannot put a cost on a system nobody knows exists, or hold anyone to a budget for a tool nobody owns. Shadow AI is a data risk and an unplanned cost at the same time.

That is why every engagement starts with governance. See how spend observability and optimisation build on it, and how tokenomics traces AI use, token by token, to the team that owns it.

Check your own setup

A free self-check you can run on your own setup in about 20 minutes: 22 plain questions, each answered yes, partly or no. Your score fills itself in, and every gap comes with what to look at first. It works for any size, from one person to a global company; questions that only matter above a certain size are marked, and you can skip them.

No sign-up and no email address. Download it and keep it.

How we help

The AI and technology cost review builds the register of every system and AI use, and scores your governance on the FinOps Crawl, Walk, Run scale. AI spend management keeps it current every month. Data governance for AI, setting the rules for putting your own data into AI, is scoped with each client: talk to us.

Start with a conversation.

One call to understand what you spend on and what worries you. If an engagement fits, you get a written scope and price.

Book a first call