AI governance fails in two recognisable ways. The first is a policy document that circulates once and is never opened again. The second is a blanket ban, which moves the same activity onto personal accounts where nobody can see it. This day is designed to produce neither. It is six hours of assembly work, and you leave with documents that an auditor, a client or a regulator can actually be shown.
The morning begins with the register, because nothing can be governed until it has been listed. You build an inventory of the AI systems your organisation genuinely uses, each with an owner, a purpose, the data it touches and its approval status, and you work out how to surface the tools bought quietly on a personal card without pushing them further out of sight. Every entry is then classified by risk, by data sensitivity and by what a wrong output would cost, so that each tier gets a proportionate control rather than one rule stretched across everything.
You then map those controls onto work that has already been done for you. The NIST AI Risk Management Framework and ISO/IEC 42001 give you a structure to borrow from without committing to a full management system in one quarter, and the EU AI Act risk tiers tell you which uses are prohibited, which count as high risk and which carry transparency obligations. The Act applies in phases and its timetable has been amended since it entered into force, so the session works from the position current on the day you attend. Data protection runs alongside: Sri Lanka's Personal Data Protection Act No. 9 of 2022, and GDPR or UK GDPR where your customers and clients bring them into scope, with the practical questions of lawful basis, purpose, retention, cross-border transfer, and what a data subject request means when part of the answer is sitting in a chat log. This is orientation for the people who run the process. It is not legal advice and it does not replace your own advisers.
The afternoon is about controls that hold. Human oversight only counts if the reviewer has the time, the information and the authority to overturn an output, so you design a review step that meets that test rather than one that produces a signature. You write a disclosure standard covering what is labelled as AI-assisted, what clients are told, and where provenance is attached using Content Credentials and the underlying C2PA standard. You run a simple fairness check on a real decision your organisation makes and record what you found, comfortable or otherwise. And you assemble the documentation an audit will ask for before it asks.
The day closes on vendors and incidents: the due diligence questions that decide whether a tool is usable at all, the contract terms worth arguing over, and a procedure for the day an AI system produces something harmful, covering who is told, how it is contained, what is recorded and who reviews it afterwards. You finish with a twelve-week plan naming the first three things to do and who owns each. Runs live online, in the classroom in Colombo, or privately for a leadership, compliance or risk team, priced in LKR for Sri Lanka and USD internationally.