Responsible AI

AI Governance

Practical AI governance for organisations using AI, policy, oversight and generative-AI rules, anchored to POPIA and King V.
POPIA s71 anchoredKing V Principle 10ISO 42001 & NIST alignedGenerative AI covered

The requirements

A framework-neutral AI governance assessment for organisations that build, buy or use AI. It is anchored to POPIA section 71 (automated decision-making, the operative South African legal hook, since no AI-specific statute is yet in force) and King V Principle 10, and aligned with ISO/IEC 42001 and the NIST AI Risk Management Framework. It covers AI policy and accountability, a system inventory, impact assessment, bias and transparency, human oversight, and generative-AI acceptable use, the biggest real exposure for most organisations.

AI Policy & Accountability
A board-approved AI governance policy and clear accountability for the organisation's use of AI
AI Inventory & Risk
A register of AI systems with risk classification, so oversight is proportionate to the risk each system carries
Impact Assessment & Ethics
AI impact assessments and ethical review before deployment, aligned with ISO/IEC 42005
Bias, Fairness & Transparency
Bias testing, fairness monitoring, and transparency to people affected by automated decisions
Human Oversight
Human oversight and override, including the POPIA section 71 right to human review of solely-automated decisions
Generative-AI Acceptable Use
An approved-tools list and rules for handling confidential and personal information in tools like ChatGPT and Copilot

Mapped in Encircle

This framework contributes to the following governance domains in your Encircle score:

D09 AI & DataD08 TechnologyD04 ComplianceD05 Ethics
How Encircle maps this framework

Encircle scores your AI governance across the domains it touches and asks for the artefacts that make AI oversight real, an AI policy, a system register, impact assessments, human-oversight records and a generative-AI acceptable-use standard. Because it is framework-neutral, a single assessment maps onto POPIA, King V, ISO/IEC 42001 and NIST at once. Every gap becomes an assigned remediation task.

Your AI Governance readiness score

Encircle tells you when your AI governance is in place, the policy, inventory, impact assessments and oversight controls a responsible organisation should hold. This is governance readiness, not certification; ISO/IEC 42001 certification, where you want it, is issued by an accredited body.

AI Governance, scored

The same organisation seen through the AI Governance lens. Red is where the exposure is. Switch lens to see how the picture changes under another framework.

Risk & AssuranceHow we provePerformance & InnovationHow we deliver future valueEthics & CultureWho we areComplianceTechnologyAI & DataEthicsAI Gov41%GOV SCORE
FSG
Financial Services Group (Pty) Ltd
Financial services · 350 employees · JSE-listed
41%
Overall

Select a framework

AI Governance: no AI policy, system register or generative-AI acceptable-use standard evidenced. AI & Data craters to 18%, pulling Technology, Compliance and Ethics with it.

Domain breakdown, by pillar
Risk & Assurance42%
Compliance
42%
Performance & Innovation31%
Technology
44%
AI & Data
18%
Ethics & Culture60%
Ethics
60%

Ready to track your AI Governance readiness?

Request early access and get your AI Governance score in your first session.

Book a demo

Tell us about your organisation.

Tell us a little about your organisation and we’ll walk you through Encircle against the frameworks that actually apply to you.

Early sign-on offer
Early access clients get preferential launch pricing and priority onboarding. Applies to all requests submitted before platform launch.

Encircle Network

Are you a specialist in your industry?

Join the Encircle Network and help businesses get governance-ready. We connect consultants, auditors and legal advisors with organisations working through their Encircle score. Tell us about your practice and we’ll be in touch about becoming an Encircle partner.