
governance · ai-adoption · minimum-viable-governance · psychological-safety · human-agency
Minimum Viable Governance: a human-first governance framework
The smallest amount of governance that keeps you, your people, and the people you serve safe - eleven promises, six questions, and a cadence, for organisations too small for boards but too exposed to go without.
Minimum Viable Governance
A human-first governance framework.
What if governance made sense. What if it focused on the people it was made to serve, the people it was meant to protect. What if governance were more people focused and practical.
This short document is aiming to introduce this very concept. I have seen so many times how governance can lose its way and become a box ticking exercise. Now don't get me wrong there is some satisfaction in ticking the boxes, but governance without people centred principles is like salt without its saltiness.
There are so many different types of organisations, some very similar some with wildly varying operating models. So what unifies most of them?
People.
Then along came AI, there are so many ways that this changed the world for us. Even the range of relationships that people have with AI, from personal confidant to super fast expert system. Within this context, without the right type of systems thinking, we can end up inadvertently exposing ourselves and others.
Just the other day, my sister asked me to transcribe some doctors notes from a consultation. I knew exactly how to do it and how much exposure the personal data was put through. I was able to make informed decisions, knowing that my AI settings prevented my data from being used for training. I also knew that if they "needed to" that my AI provider could sequester my data in extreme circumstances. I had to make a decision on the pros, cons and risks that were associated.
I was applying my own personal AI strategy principles and informal governance framework.
In this era, we have a greater need to apply governance principles to the new way we work, both as individuals and organisations. We have an obligation to ourselves and others to protect!
So Minimum Viable Governance.
Minimum Viable Governance is the smallest amount of governance that keeps you, your people, and the people you serve safe.
The idea
Governance is not risk paperwork. It is a set of promises to real people, and a way of keeping them.
A large organisation makes those promises through boards, roles and committees. A small one cannot afford any of that, and does not need it. It needs the promises, someone to hold each one, and a way to stop something when it goes wrong.
That is the whole of it.
Psychological safety
Why would we bring this up? What does this have to do with governance? If the point of governance is to serve and protect people, then psychological safety is one of the outcomes of good governance.
What is psychological safety? For me it is characterised by people having the ability to safely do the work knowing that if they succeed or fail that there are supports that keep them safe. Within process (or lack of it) people are able to speak up on what is working or not. From a personal point of view it allows you to be fully human, free to say when you are vulnerable and when you are strong. At its core is relationship, relationship that nurtures, supports and perseveres even when it is painful and costs.
Amy Edmondson defined it as "a belief that one will not be punished or humiliated for speaking up with ideas, questions, concerns or mistakes, and that the team is safe for interpersonal risk-taking"
It matters more now than it ever has. AI has put powerful, open tools into everyone's hands at once, faster than any organisation can write rules to keep up. The only real control in that gap is a person willing to say I used this, or this looks wrong, or we should stop. If those sentences are unsafe to say, they go unsaid, and you are governed by silence.
You can feel the difference. Where safety is present, people tell you what they are using, flag the system when it errs, and stop something in good faith without looking over their shoulder. Where it is absent, they hide the tool, stay quiet when it is wrong, and keep a failing thing running because owning up would cost them.
So this framework builds safety in, in five places:
- Safe to Admit. Say what you are already using, or a mistake you have made with it. Raising it itself is never the thing that gets you into trouble. The honest mistake is exactly what this protects. Genuinely unlawful or bad-faith use is not.
- Safe to Stop. Anyone can switch something off in good faith, based on their judgement. Switching it back on is what needs agreement.
- Safe to Disagree. Saying no to the machine is easy and ordinary, because the moment it costs you anything, people stop, and nobody is really checking it.
- Safe to Innovate. Enabling people to build new ways of doing things by providing frameworks for safe operation
- Safe in Vulnerability. Enabling people to not hold the full picture and build it up as part of personal development. We always arrive partially formed.

Three principles
- Protect a person/team/people group, not a position. Every promise names the human it keeps safe, and the threat. If you cannot name the people, cut it, that one test clears out most governance theatre.
- Governance is a discipline, not a switch. We are wired to be efficiently lazy - leave anything to lapse on its own and everything will. So the engine is not passive expiry; it is cadence: a regular, committed review of a deliberately small set you have chosen to keep. An expiry date is the alarm that brings something back to the table, and if nobody comes it is flagged, loudly, as overdue - never quietly retired. Something still running with no live decision behind it is the failure, not the fix.
- Small is enough - as long as the gaps are chosen. The smallest honest version is real governance, not a lesser one. What keeps "small" from becoming "barely" is that everything you leave out is a decision you can name, not a place you simply never looked. Sized to what you are; never to what you fear.
The eleven functions
Each function is a promise waiting to be made - a standing area where someone could be let down. A function is not the same thing as a promise: it is the category a promise lives in. One function can hold several promises, one, or none yet - and an empty function is a choice you have made, not a corner you missed. You bring in the functions your situation asks for, not all eleven at once.
| # | Function | The promise |
|---|---|---|
| 1 | Technical assurance | It will work when you rely on it |
| 2 | Information governance | It will handle you lawfully |
| 3 | Locality & resilience | It will be there tomorrow |
| 4 | Security assurance | It will not be turned against you |
| 5 | Ethics & fairness | It will treat you fairly |
| 6 | Human impact | Your work and dignity were considered |
| 7 | Engagement | You were asked |
| 8 | Auditability | Someone can explain what happened to you |
| 9 | Capability & training | You can use it, and challenge it |
| 10 | Benefit accountability | The good we promised actually reached you |
| 11 | Revocation | Someone will stop it if it hurts you |
They group into four: Foundations (does it work, stay up, stay safe), People (how it treats those it touches), Transformation (did it land and deliver), Control (can we explain it, and stop it).
The promise is the tip of something bigger
Each headline promise is a compression. When you actually hold a function, you write the promise in full, so it names the person and the specific harm it guards them from. The shape is always the same:
We will [do this], so that [you] can [outcome], without [specific harm].
Two worked examples, one from Foundations, one from People, show it holds across the range:
Security assurance - "It will not be turned against you."
We will check the security of each tool we rely on, so that you can trust it with what matters to you, without you or the people connected to you being harmed by an attacker or left exposed when it fails.
Engagement - "You were asked."
We will bring the people a change affects into the room before it is decided, so that you can shape what happens to you, without a decision being made about your life in your absence.
If a promise cannot finish its without clause honestly, it is either undeliverable or self-serving, and it should be cut. But honestly has to bite, or a fluent, empty clause slips through - "without your data being misused" sounds fine and guards nothing. So the harm must be specific (a named actor or mechanism, not "without harm to anyone"), it must pair to a mitigation in the Risk Register that someone else could check was actually done, and you must be able to say how you would know the promise had been broken. A harm you cannot describe the breach of is not one you are guarding against. That is most of the discipline.
How it works
Start where you actually are: with an amnesty. Most organisations do not know what they are already running. So the first move is not a policy, it is a list: tell us what you are using, and the telling itself is never what gets you into trouble. You cannot govern what nobody will admit to.
Then the framework asks a short set of plain questions, six of them at the lightest tier, set out below and turns the answers into named responsibilities, each with a person, a rhythm, and an expiry date. A first draft is generated, then challenged.
Anything that cannot honestly say who it protects is discussed and amended or cut.
Then you keep it, on a cadence. The whole loop looks like this:

At its very lightest, this whole loop comes down to six questions.
The six questions
Six honest answers is real governance. The fuller version is those same six questions held against each of the eleven functions - the six are how you probe, the eleven are what you probe. It is a deliberately lossy view: quick, and mostly complete. You check it for gaps the same way every time - look for a function with no promise against it and no reason written for leaving it out. That empty cell is the signal, not the silence around it.
| # | The question | What it settles | Output |
|---|---|---|---|
| 1 | What are we actually using? | You cannot govern what you cannot name. The honest list comes first. | AI Tool List |
| 2 | What could go wrong that we would feel responsible for? | The risks worth naming: the ones that would keep you up at night. | List of Risks |
| 3 | Who gets hurt if it does? | The person at the centre. Every promise is made to a named human. | Promise List |
| 4 | Who would have to say sorry, and who else could? | Who owns it, and the second name that collectives always miss. | Risk Owner |
| 5 | Who can stop it, and how fast? | The power to halt harm today, without waiting for a meeting. | Risk Mitigation |
| 6 | When will we look again? | The cadence: governance is a discipline you return to, not a document you file. | Promise Review Date |
Scale to your size
A tier is not a difficulty setting. It is simply which of the eleven functions are in scope for you. The smallest version has fewer functions live; the fullest has all eleven. Moving up is not doing the same work harder, it is bringing a function that was out of scope into scope.
What pulls a function in is exposure, not headcount alone: how many AI tools you run, how sensitive the data they touch, how many people they affect, and whether a regulator or funder is watching. More of any of those, more functions.
Two rules stop "small" from becoming an alibi for "barely":
- A few functions are always in scope. Revocation, Auditability and Information governance hold at every size - if you cannot stop it, explain it, or handle people's data lawfully, being small is no excuse. (This mandatory core is a proposal - worth confirming.)
- Every function you leave out, you write down. "We are not governing X, because Y" - one line. An excluded function is a stated choice, never a silent gap. That single discipline is the whole difference between small and negligent.
What you end up with
Two things that must exist in writing, and nothing that needs a secretariat:
- A Promise Register: A list of all the derived promises to people that the organisation commits to and will review on an agreed cadence.
- A Risk Register: A list of all the risks that need managing and reviewed on a cadence.
The two registers, filled in
To make it concrete: a small counselling charity has started using an AI note-taker to transcribe and summarise support sessions. The same six answers produce both registers.
Promise Register
| Promise | To whom | Held by | Review |
|---|---|---|---|
| We will only handle your session notes as we told you, and never put them through a tool that trains on them, so you can speak freely without your words being used elsewhere. | Clients | A. Okafor | Quarterly · next 01 Oct |
| We will keep one person able to write a session up by hand, so you are still supported if the tool is wrong or down. | Clients and staff | J. Miles | Half-yearly · next 15 Jan |
| Anyone here can switch the note-taker off the moment it worries them, so you are never harmed by it while we decide. | Everyone | A. Okafor | On trigger |
Risk Register
| Risk | Tool | Who is hurt | Owner | Rating | Mitigation | Review |
|---|---|---|---|---|---|---|
| Notes pasted into a free chatbot that trains on them | AI note-taker | Client | A. Okafor | High / High | The note-taker is the only permitted route; everything else is named and off-limits | 01 Oct |
| Nobody can write a session up if the tool is down | AI note-taker | Client | J. Miles | High / Medium | One person keeps the manual method alive, tested each quarter | 15 Jan |
| The tool changed its model and its summaries drifted | AI note-taker | Client | A. Okafor | High / Medium | Change log kept; ten summaries spot-checked each review | 01 Oct |
Two short tables, six honest answers behind them. That is Minimum Viable Governance doing its job.
A small boat does not need a large crew to stay upright. It needs a keel to hold direction under pressure, and ballast to right itself when it heels over. Minimum Viable Governance is the smallest set of both that keeps an organisation pointed where it meant to go - and able to recover when it gets something wrong.