Skip to content
Over Unity

Insights/For hirers

What an AI governance function should look like at 200 people

7 minute read. Updated 2026-08-08.

The short answer

At 200 people, build a register of every AI system in use before forming a governance committee: name, owner, data, decision, human oversight, and last review date. Assign one accountable owner, usually the CTO or head of data. Add a lightweight review step only once the register shows real risk. Committees formed first have nothing concrete to govern.

The committee is the wrong first move

At 200 people, the pressure to be seen doing something about AI governance is real, and the easiest thing to do is convene a committee. Legal, IT, a couple of department heads, a slot on the quarterly board pack. It looks like progress because it produces a document: terms of reference, a meeting cadence, a RACI chart with everyone's name on it.

Six months later the committee has met three or four times and approved almost nothing, because nobody has brought it anything concrete to approve. Nobody in the room can list, with any confidence, every model or AI tool currently touching customer data or shaping a decision that affects someone's outcome. The committee has been given authority over a set of systems it cannot name, which makes its authority theoretical.

This is not a failure of the people in the room. Governance needs an object to govern, and a committee convened before anyone has written down what is actually running has nothing to work on except general principles, which is where most of these efforts stall.

Build the register first

A register solves the actual problem, which is that nobody has written down, in one place, what is running. It does not need to be a piece of software bought for the purpose. A shared spreadsheet is entirely adequate at this size. What matters is that every AI-based system in use, whether purchased from a vendor or built in-house, gets one row.

This takes days to assemble, not months, because the systems already exist; what is missing is the act of listing them. Most of the work is asking each department head one direct question: what are you using that makes a decision, or generates content, without a person checking every output before it goes out or acts on someone?

Expect to find more than the obvious candidates. A customer service tool with a generative summary feature, a recruitment platform doing CV screening, a finance tool flagging anomalies for review. None of these arrived with a memo. They were bought, switched on, and used, and that is exactly why the register needs to exist before anyone can decide what to do about them.

What belongs in each row

Name of the system, its business owner, what data feeds it, what decision or output it produces, whether a person reviews that output before it acts on anyone, whether it was bought or built, and the date it was last reviewed. That is the whole register, and it fits on one screen.

The review-date column is what turns an inventory into governance. A system with no review date within the past year should get one on the next board cycle, not urgently, just on the list. For a business of this size the count of systems usually lands somewhere between a handful and thirty, which is a manageable review load for one person working through it a few at a time.

One owner, not a committee

Somebody has to be accountable for the register staying current, and that has to be a named individual, not a group. At 200 people this is usually the CTO or the head of data, because they are the only people with visibility across the systems in the first place. Legal can tell you what the risk means once a system is on the list; legal cannot see what is running until someone tells them.

That person's job is to chase departments for updates, flag anything new before it goes live, and bring the board one page a quarter rather than a deck. Adding a second and third person to share the responsibility dilutes accountability without adding capacity, because now two people can each assume the other checked. One name on the register beats a committee with none on it.

Why the job titles don't help you

Nothing at all is published for AI governance, AI risk and compliance, or AI safety and evaluation as job titles in the UK advertised market. There is no median day rate or salary to quote for any of them, because the market has not agreed on what to call this work yet.

That absence is itself a finding. The work is being bought under borrowed titles: a compliance manager doing it alongside data protection, a machine learning engineer doing it alongside model builds, a fractional CTO doing it alongside everything else on their plate. Writing a job spec for 'Head of AI Governance' and waiting for a settled candidate pool to answer it will produce a long, slow search against a market that has not organised itself around that title.

Hire against the gaps the register reveals instead. If the gap is 'nobody has reviewed the vendor contracts for data handling terms', that is a short, specific piece of work for someone with a procurement or data protection background, not a permanent governance hire.

When a review step earns its place

Once the register exists and shows real risk on it, systems touching regulated data, systems making decisions about customers or staff without a human check, a lightweight review step is worth adding. Keep it small: quarterly, three or four people, and its only job is to sign off anything new before it goes live and re-check anything already flagged.

This is the point at which the EU AI Act becomes a live question rather than a background one, because it applies on a staged timetable and the obligations differ according to what a system does. A register that already records data, decision use and human oversight for every entry is most of the evidence a business needs to respond; building that picture after a regulator asks for it is a far worse position than having it ready.

What this costs

A fractional specialist can build the register and design the review step in a matter of days, not as a standing hire. Advertised UK contract rates over the six months to August 2026 put the median for artificial intelligence roles broadly at £551 a day. 10 days of that work is £5,510, and that arithmetic is worth doing before agreeing to a governance programme priced in months rather than days.

That figure buys the register, a working review process, and a briefing for whoever owns it afterwards. It does not buy a standing committee, and at 200 people it should not need to.

What to do about it

  • Build a register of every AI system in use before forming any committee.
  • Name one accountable owner for the register, not a group.
  • Log data inputs, decision use and human oversight for each system, not just its name.
  • Do not hire to titles like 'AI governance lead' expecting a settled market; there isn't one.
  • Add a lightweight review step only once the register shows real risk on it.
  • Price this as days of focused work, not a standing department.

Questions people also ask

How many people do we need for AI governance at 200 employees?

Usually one, part-time. The job is keeping a register current and running a light review step on new systems, not staffing a department. A committee without a register to work from produces meetings, not governance. Add people only once the register shows enough live risk to need more than one set of eyes checking it.

What should be in an AI system register?

Name of the system, the business owner, what data feeds it, what decision or output it produces, whether a person checks the output before it acts on anyone, whether it's bought or built, and when it was last reviewed. Most 200-person businesses can complete this in days because the systems already exist; the work is writing them down in one place.

What job title do we hire for AI governance work?

There isn't a settled one. Nothing is published for AI governance, AI risk and compliance, or AI safety titles in the UK advertised market, which means the work is currently bought under other names: compliance, data protection, MLOps, fractional CTO. Write the brief around the gaps your register reveals rather than a job title, and expect the right person to have come from an adjacent role.

Does the EU AI Act mean we need a governance committee now?

It means you need to know what you're running and what each system does, which a register gives you regardless of the Act. The Act applies on a staged timetable and the obligations depend on what a system does, so a current register with data, decision use and oversight already logged is most of what you need to respond to it, whatever the timetable turns out to require.

Where the figures come from

Every rate and salary quoted in this article is a median or percentile of figures advertised in UK job postings over the six months to 8 August 2026. They are not rates paid, and the gap widens at the top of a range.

The full salary guide, with sample sizes

More for hirers

Describe a roleWhat it costs

Over Unity makes introductions between hirers and independent specialists. It is not a party to any engagement, does not hold or transfer payments, and does not determine employment status. Specialists are never charged a fee.