AI Governance: How to Get Started
September 23, 2026
By: Elizabeth Wadsworth, VP, Decision Intelligence & Transformation, Velera
When it comes to AI governance, organizations need to keep tabs not only on the things they know – but also on the things that NOBODY knows.
That’s a tall order. But AI is evolving fast – faster than many of the frameworks designed to manage it. New capabilities emerge constantly, regulations continue to develop and expectations are changing just as quickly. That means AI governance isn’t something organizations can implement once and consider finished. It requires ongoing learning and adaptation.
I’ve been involved in AI governance since November 2022 – the early days of generative AI adoption – and along the way, I’ve learned a few lessons about what works, what organizations often get wrong and where leaders should focus their attention. It’s not what I set out to do; it just sort of happened when a previous employer began exploring generative AI and I volunteered to get involved. During an early proof-of-concept effort, I was introduced to conversations around AI governance at a time when very few organizations were talking about it.
I started looking across industries and technology sectors to understand who was doing this work, and what I found was a real void. Everything was moving so fast that people weren’t focused specifically on AI governance – and there wasn’t much practical guidance either.
What stood out to me was how different it was from both traditional governance and data governance. There is certainly overlap, but AI introduces challenges that didn’t neatly fit into existing frameworks. The field was still taking shape, which created an opportunity for people willing to learn alongside the technology itself.
At first, I approached AI risk a little bit more like a check-the-box exercise: Meet these five standards and you’re good to go! At the time, I didn’t realize all the ways things could go sideways – because every AI use case comes with a different set of risks dependent on the technology being used, the data being accessed, the environment in which the solution operates and the outcomes it’s intended to produce. Two applications might use similar technology and require completely different governance approaches.
At the same time, the technology continues evolving while organizations are creating the rules for governing it. Most of us are accustomed to assessing technologies that are already well understood; AI is different because the risks, capabilities and best practices are still emerging.
And there’s no end in sight. What you know today might change tomorrow. So, how do we create a framework for governing something that has no precedent, is constantly evolving and involves different risks in each use case?
Start Easy
Because AI adoption is moving so quickly, organizations often feel pressure to not be left behind and move quickly with AI initiatives of their own. That’s not always a bad thing: You can jump on the bandwagon right away with something easy and lower-risk as a way to experiment and learn while you build governance maturity. For example, try building a simple agent or automation in Copilot to learn how it works. Efficiency building in your own environment is a great way to get started.
Other use cases, especially those that are customer-facing or carry greater consequences, require additional oversight before deployment. Starting easy will spark innovation and help you move forward with confidence.
Start Early
When people think about AI governance, they often focus on what happens after a solution is deployed. But governance needs to begin much earlier. One of my strongest beliefs is that how you arrive at a use case is just as important as how you manage it once it’s implemented. Organizations should be able to explain not just what an AI solution does, but why they chose to pursue it in the first place. And when you can clearly communicate and document the reasoning behind your decisions, you’re in a much better position to build trust.
Start with questions such as:
- Why was this use case selected?
- Who was involved in the decision?
- What risks were considered?
- What data is involved and how sensitive is it?
- How will success be measured?
- How will the solution be monitored over time?
Stakeholders, customers and regulators all care about those questions – and answering them upfront demonstrates that you’ve approached the deployment thoughtfully and intentionally.
Start With What (and Who) You Have
One misconception I encounter frequently is the idea that AI governance requires creating an entirely new function. In reality, most organizations already have many of the right people and processes in place. Risk teams understand risk management. Compliance teams understand regulatory requirements. Legal teams understand accountability. Technology teams understand implementation and controls.
You don’t need to reinvent the wheel, but instead align existing expertise to AI governance responsibilities. AI governance shouldn’t feel like an entirely new job, but rather a new application of existing expertise in a different (and constantly changing) context. When we were developing our own governance ventures at Velera, we developed an AI Governance RACI matrix to help identify who is Responsible, Accountable, Consulted and Informed across AI governance activities. We spec’d out tasks within the categories of Strategy & Policy, Use Case Management, Model Risk Management, Data Governance, Vendor Management, Compliance & Fair Lending, Security & Resilience, Monitoring & Reporting and Training & Awareness – then built out sub-tasks and assigned RACI roles from existing groups within our organization:
- Board
- C-Suite
- Risk
- Compliance
- IT/CISO
- Operations/Business Units
- Internal Audit
- Legal
- Procurement
In doing so, we layered in AI governance within our own corporate structure, helping create clarity before challenges emerged.
Start Learning!
To govern AI, you need to understand both what you know and what you don’t know – and because it’s all moving at breakneck speed, continuous learning is what allows organizations to keep pace.
When you invest in education and literacy, you will be much better positioned to adapt as new risks, opportunities and expectations emerge. Whether it’s following regulatory developments, guidance from organizations like the National Institute of Standards and Technology (NIST), industry publications or conversations happening across the broader community – AI governance professionals need to make continuous learning part of their job.
Final Thoughts
AI governance isn’t something organizations can establish once and forget about – it must evolve at the rate of AI. Governance requires organizations to stay informed, adapt and remain active participants in the conversation.
And it’s not just about avoiding risk, but creating a foundation that allows organizations to adopt AI responsibly. The most successful aren’t necessarily the ones moving the fastest, they’re the ones that combine innovation with accountability, transparency and ongoing learning.
The key is to start now. If you don’t do your governance work now, you’ll usually be forced to do it later – perhaps while you’re scrambling to deal with an issue that could have been avoided with some thoughtful planning upfront.
To learn more about Velera and the solutions they offer, connect with the GoWest Solutions Team today.
About the author: As the VP, Decision Intelligence & Transformation at Velera and a certified AI Governance Professional (AIGP), Elizabeth Wadsworth leads AI strategy for the Innovation team and champions responsible AI across the organization. With more than 20 years of strategic leadership and technology experience and almost a decade in the credit union space, Elizabeth is passionate about making emerging technologies approachable, impactful, and aligned with credit union values.
Posted in GoWest Solutions, Top Headlines.
















