Skip to main content
Promotional banner for the pentest readiness checklist
Build an AI Governance Program Before Your Regulator Does It For YouRegulatory Compliance
6 min readFor GRC Leaders

Build an AI Governance Program Before Your Regulator Does It For You

The Solicitors Regulation Authority's August 17 warning was clear: law firms are using AI inappropriately, leading to court filings with AI errors and confidential client data leaking into public AI tools. Senior judiciary members have filed breach reports. The SRA's message is direct: if you can't govern AI use, you're violating your professional obligations.

For GRC leaders across industries, this is a warning. Legal professionals work under strict confidentiality and accuracy requirements. If they're struggling with AI governance, your organization likely faces similar risks. The question isn't whether you'll need an AI governance program; it's whether you'll build one before a regulator forces your hand.

The Problem: Why This Matters Now

AI tools have spread faster than governance frameworks. Your employees are likely using ChatGPT, Claude, or Copilot to draft documents, analyze data, and generate reports. Some are pasting sensitive information into public interfaces without understanding the confidentiality implications. Others are citing AI-generated references without verification, creating compliance and reputational risks.

The SRA identified two critical failure modes: hallucinated outputs treated as fact, and confidential data entering systems without safeguards. Both stem from the same root cause: organizations haven't defined acceptable use, implemented technical controls, or established human oversight requirements.

You're accountable for AI outputs your team produces, whether you know they're using AI or not. Waiting for comprehensive AI regulations won't protect you. The SRA's outcomes-based approach is instructive: they set standards but don't prescribe implementation. You need to define "responsible AI use" for your context before an incident defines it for you.

What You Need Before Starting

Executive sponsorship with budget authority. AI governance crosses IT, legal, compliance, HR, and business units. You need a sponsor who can allocate resources and enforce policy across silos.

Current-state inventory. Before you can govern AI use, you need to know what's already happening. This includes:

  • Sanctioned AI tools (licensed software, API integrations, embedded features)
  • Shadow AI (employees using consumer tools for work tasks)
  • Data flows (where sensitive information might be exposed)

Regulatory and contractual obligations mapped. Pull your obligations library. Identify which regulations govern your data handling, professional standards, and disclosure requirements. For financial services firms, this includes SEC reporting accuracy. For healthcare, HIPAA confidentiality. For legal, professional conduct codes.

Risk appetite statement. Define acceptable risk levels for AI use. Some organizations will prohibit AI in client-facing work entirely. Others will allow it with human review. Document your position before you start writing policy.

Cross-functional working group. Pull representatives from information security, legal, compliance, internal audit, and key business units. You'll need their expertise to build practical controls.

Step-by-Step Implementation

Step 1: Draft an AI acceptable use policy (Week 1-2)

Create a policy standard that addresses:

  • Prohibited uses (e.g., entering confidential data into public tools, using AI output without verification)
  • Approved tools and procurement requirements
  • Human oversight requirements by use case
  • Data classification rules for AI interactions
  • Citation and attribution standards

Make it specific. "Use AI responsibly" isn't enforceable. "Do not paste client information, regulated data, or proprietary analysis into ChatGPT, Claude, or other public AI interfaces" is.

Include a materiality threshold. The SRA emphasized that putting false citations before a court could constitute contempt. Define what constitutes material misrepresentation in your context.

Step 2: Implement technical controls (Week 2-4)

Policy without enforcement is aspirational. Deploy:

Data loss prevention (DLP) rules that flag or block sensitive data patterns being pasted into browser-based AI tools. Configure your DLP platform to monitor for:

  • Regulated data identifiers (SSNs, account numbers, patient IDs)
  • Confidentiality markers in document metadata
  • Large text blocks from internal systems

Network controls that log access to public AI services. You need visibility into who's using what tools before you can assess risk.

Approved AI tool procurement. If teams need AI capabilities, provide enterprise solutions with appropriate data handling agreements. Microsoft 365 Copilot, Google Workspace AI, and enterprise ChatGPT all offer contractual protections that consumer versions don't.

Configure these tools with data residency requirements and audit logging enabled.

Step 3: Establish human oversight requirements (Week 3-4)

The SRA specified that human oversight and informed professional judgment are essential. Define what that means operationally:

For AI-assisted document drafting: Require human review of all outputs before external distribution. The reviewer must verify factual claims, check citations, and assess tone appropriateness.

For AI-generated analysis: Mandate that a qualified professional validate methodology and conclusions. Document who reviewed what.

For AI in regulated submissions: Implement a two-person rule. The author reviews AI output, and a second qualified person verifies accuracy before filing.

Create verification checklists. For legal citations, this means checking case law in official databases. For financial data, reconciling to source systems.

Step 4: Train your organization (Week 4-6)

Run role-specific training:

For all employees: Cover acceptable use policy, prohibited tools, and how to request approved AI access.

For supervisors: The SRA noted that supervisors can be held responsible for their team's AI misuse. Train them on oversight obligations and red flags.

For high-risk roles (legal, finance, audit, compliance): Deep dive on verification requirements, confidentiality risks, and professional standards. Use the SRA's warning as a case study.

Make training attestation a compliance control. Track completion and require annual refreshers.

Step 5: Build ongoing governance (Week 6-8)

Establish a standing AI governance committee that meets monthly to:

  • Review AI tool requests and approve/deny based on risk assessment
  • Analyze DLP alerts and usage patterns
  • Update policy as new tools and use cases emerge
  • Track AI-related incidents and near-misses

Create an AI risk register. Document identified risks, controls, and residual exposure. Include this in your enterprise risk oversight reporting.

Add AI governance to your internal audit plan. Schedule periodic reviews of policy compliance, control effectiveness, and incident response.

Validation: How to Verify It Works

Test your technical controls. Have a trusted employee attempt to paste sample confidential data into ChatGPT. Your DLP should flag or block it. If it doesn't, tune your rules.

Audit a sample of AI-assisted work. Pull recent documents, filings, or analyses that may have used AI. Verify that citations are genuine, facts are accurate, and review documentation exists. If you find hallucinated content that passed review, your human oversight process needs strengthening.

Review access logs. Check which employees are accessing approved AI tools and whether usage patterns match authorized use cases. Investigate anomalies.

Survey your teams. Ask about AI tool usage anonymously. If people report using prohibited tools, your communication or enforcement needs adjustment.

Track leading indicators: Monitor DLP alert volume, Approved Exception requests, and training completion rates. Rising alerts may indicate growing shadow AI use.

Maintenance and Ongoing Tasks

Monthly: Review AI governance committee findings. Update risk register. Analyze incident trends.

Quarterly: Refresh training materials with new examples and regulatory developments. Review and update your approved tools list as vendors release new capabilities.

Annually: Conduct a comprehensive AI risk assessment. Re-evaluate your risk appetite as organizational capabilities mature. Update policy to reflect lessons learned.

Continuously: Monitor regulatory developments. The SRA promised continued guidance as AI evolves. Your regulatory inventory should track AI-related obligations as they emerge.

After any AI-related incident: Conduct a root cause analysis. Update controls and training based on findings. Report material incidents according to your obligations.

The SRA's warning shows that regulators won't wait for perfect AI governance frameworks before holding organizations accountable. They'll apply existing professional standards and expect you to figure out implementation. Build your program now, while you still control the timeline.

Promotional banner for the Pentest Readiness checklist download

You Might Also Like