“We have an AI policy” won’t survive the next RFP.

September 7, 2026 / by JustOne

AI (1)

AI is everywhere in your business. The question is whether you are governing it.

It is already in use, whether management knows it or not. Across your teams, people are quietly using AI tools to get work done, feeding in company information, some of it confidential, and acting on results that may be wrong, biased or unchecked. It is already shaping your products, services and operations, invisibly and without oversight. You cannot govern, or defend, what you cannot see.

The pressure to govern AI responsibly is now arriving from every direction. Clients, investors and regulators are asking harder questions about which tools are in use, how data is protected, who is accountable, and whether oversight is real. The EU AI Act is setting a direction of travel that domestic law and investor expectations tend to follow, as GDPR did. “We have a policy” is no longer enough: stakeholders want auditable evidence, not a document in a folder.

Global mobility is no exception. Two years ago, four in five organisations reported almost no AI use; today 79% use it in some form, yet fewer than half have a full policy with compliance actively monitored. The shift has been rapid and largely invisible, happening at an individual level while organisational frameworks lag. Most businesses do not know exactly what tools are in use, or on what terms, and that gap matters.

What good AI governance looks like

Good governance is not about stopping AI use, but managing it intentionally: knowing what systems are in use, understanding the risks they carry, being clear on who is responsible, and keeping that picture current as tools change.

ISO 42001 is the international standard for AI governance, the same management system approach as ISO 14001 for environment or ISO 9001 for quality. Think of it like a fire evacuation plan: nobody expects a fire, but a clear structure means everyone knows what to do, who is responsible, and how to recover. Its real value is the roadmap. Policy, approved tools and basic training are the starting point; an AI inventory, risk assessments, role-based training, management oversight, supplier governance and evidence that it is all operating are the next steps.

Where is your organisation on its AI governance journey?

Most relocation businesses are on the same path: staff start using AI informally, a policy gets issued, the tools in use get identified, then governance, oversight and assurance follow. Much of the sector still sits between the first two steps, behind the most mature on governance. The gap is rarely technology. It is accountability, management oversight, role-based competence, documentation, and evidence that governance is actually operating. To understand what AI governance means for your business, and whether ISO 42001 might work for you, message Virginia.Schuldt@justone.uk

Leave a Comment