Back to Blog
AI GovernanceCompliancePrivacy Operations

Build an AI Compliance Roadmap That Works

By Robert Healey · September 19, 2026

Privacy professional at a laptop with AI governance icons showing scales, checklist, padlock and people

A business cannot govern AI effectively from a policy document alone. It needs to know which systems are being used, what decisions they influence, where personal data enters the workflow, and who can stop or change a deployment. An AI compliance roadmap provides that operating structure, turning legal and risk requirements into owned actions, repeatable controls and evidence that senior stakeholders can rely on.

For organisations operating across the EU, UK, Switzerland and other markets, the challenge is rarely a single rule. AI governance sits alongside data protection, security, procurement, sector requirements and existing risk management. A useful roadmap brings these workstreams together without creating a separate compliance programme that the business cannot maintain.

Start with the AI systems, not the policy

The first deliverable should be a credible AI system register. This is more than a list of software licences. It should record internally developed models, externally procured tools, embedded AI functionality within enterprise software, and experimental use cases that may be moving towards production.

For each system, capture its business purpose, owner, users, deployment status, data categories, countries involved, suppliers, outputs and the decisions it supports. The register should also establish whether the organisation is acting as a provider, deployer, importer, distributor or another relevant party under applicable AI rules. These roles affect the controls required and the evidence that must be retained.

This discovery stage often exposes a practical issue: central teams may know about approved AI projects, while business functions are testing generative AI tools through ordinary procurement routes or individual subscriptions. A roadmap should therefore combine central records with targeted engagement across technology, legal, HR, procurement, information security and operational teams. The aim is not to discourage legitimate innovation. It is to establish visibility before use becomes difficult to control.

Classify risk in a way that drives decisions

Once systems are identified, they need proportionate classification. The EU AI Act is a central consideration for organisations with relevant EU activities, particularly where systems may fall within prohibited, high-risk, transparency or general-purpose AI obligations. However, classification cannot be performed by reading product descriptions alone.

The assessment should examine the intended purpose, actual use, affected individuals, degree of automation, potential impact, human oversight arrangements, data sources and downstream dependencies. A recruitment screening tool, for example, requires a different level of scrutiny from an internal drafting assistant. The difference lies not only in the technology but in the effect of its output on people and business decisions.

Privacy analysis must run alongside AI classification. Where personal data is processed, the organisation may need to assess lawful processing, fairness, transparency, data minimisation, retention, international transfers and individual rights. For higher-risk processing, a data protection impact assessment may be required. Treating the AI assessment and privacy assessment as unrelated exercises creates duplicated work and gaps between technical, legal and operational teams.

A practical approach is to build one assessment workflow with distinct decision points. It can identify the AI risk category, privacy implications, security requirements, vendor dependencies and approval conditions in a single controlled record.

Build the AI compliance roadmap around operating controls

A roadmap is valuable only when it defines what people must do differently. Broad principles such as accountability and transparency matter, but they need to be expressed through business controls.

For each priority AI use case, define the minimum conditions for approval, deployment and ongoing operation. These may include documented intended purpose, input-data controls, testing criteria, human review requirements, user instructions, performance monitoring, incident escalation and change management. The precise set will depend on the use case. A system affecting employment, access to essential services or regulated decisions will require deeper assurance than a low-impact productivity tool.

Vendor management is equally important. Many organisations will deploy AI through third-party platforms rather than build models themselves. Procurement and contract teams need a structured AI vendor risk assessment that goes beyond standard security questions. They should understand the supplier's role, training-data position where relevant, model documentation, security safeguards, subprocessors, service locations, restrictions on customer data use, update practices and support for audit or incident response.

Contractual commitments are not a substitute for operational review. A supplier may change functionality, introduce new models or alter how customer content is processed. The roadmap should require reassessment when a material change occurs, rather than assuming the original due diligence remains sufficient.

Assign accountability across three teams

AI compliance can fail when responsibility is placed solely with legal, solely with technology or solely with a data protection officer. Each function sees a different part of the risk. Effective implementation requires a coordinated model spanning legal, privacy and technical operations.

The legal team interprets applicable obligations, contractual responsibilities and governance requirements. The privacy team connects AI use to data inventories, impact assessments, rights management and cross-border processing. Technical operations validates system architecture, access controls, testing, monitoring, configuration and evidence collection. Business owners remain accountable for the purpose, benefits and day-to-day use of their systems.

This is not a call for every project to enter an extended committee process. The roadmap should set approval routes based on risk. Low-risk tools may follow a standard intake and acceptable-use control. Higher-risk deployments should receive structured cross-functional review and documented senior approval. Clear thresholds allow the organisation to focus specialist attention where it has most value.

A responsible executive sponsor should oversee the programme, with defined reporting to the appropriate risk, compliance or board forum. Reporting should show more than the number of policies published. It should identify the systems registered, risk classifications completed, assessments overdue, material vendors reviewed, incidents raised, control exceptions and remediation progress.

Sequence delivery rather than attempting perfection

An AI programme can become unmanageable if every system must meet a fully mature framework immediately. A phased plan is usually more effective, particularly for organisations with a large international technology estate.

The first phase should establish governance ownership, the AI system register, intake rules and interim controls for high-priority use cases. This creates a defensible baseline and prevents uncontrolled expansion while the programme is developed.

The next phase should focus on classification, impact assessments, vendor assurance and documented approval workflows. At this point, organisations can begin producing consistent evidence and identifying where existing privacy, security or procurement controls need adjustment.

The final phase is operational maturity: monitoring, periodic review, model or supplier change controls, staff training, incident exercises and management reporting. ISO/IEC 42001 can provide a useful management-system structure for organisations seeking a formal and repeatable approach, but certification is not necessarily the right first step for every business. The immediate priority is an operating model that reflects actual AI use and can be sustained.

Treat evidence as a business asset

Regulatory readiness depends on being able to demonstrate how decisions were made. The evidence should be generated through normal workflows, not assembled retrospectively after an incident, audit request or customer questionnaire.

This means retaining the system register, risk decisions, impact assessments, technical test results, vendor reviews, approval records, training completion, change logs and incident records in a controlled environment. A central platform can reduce fragmentation by linking these records to existing privacy operations, including records of processing activities, data protection impact assessments, data subject access requests and breach workflows.

Evidence also supports commercial objectives. Enterprise customers, partners and investors increasingly ask how AI is governed. Organisations that can explain their controls clearly are better placed to move through due diligence and procurement discussions without repeated, manual information gathering.

Keep the roadmap connected to the business

The strongest AI governance programmes do not try to eliminate every uncertainty before deployment. They establish clear boundaries, proportionate assurance and accountable decisions, allowing the organisation to use AI with greater control. For international businesses, the roadmap should be reviewed as new markets, suppliers, use cases and regulatory obligations emerge.

Formiti supports this work through its Legal Team, Privacy Team and Technical Operations capability, helping organisations convert AI, privacy and cross-border compliance requirements into managed operational practice. The useful next step is usually not another high-level principle. It is identifying the systems already in use and deciding which controls must be in place before their role expands.

Related Services

Need help with AI governance or data privacy compliance?

Privacy-first website: We do not use tracking cookies, advertising pixels, or third-party analytics on this site. Read our Privacy Notice.