The AI Trust Triangle 4
Completing the HOW of trust
Welcome to the final installation of our AI Trust Triangle series.
In the first article, we explored identity – the control layer that determines who can act, in what context, and with what authority. In the second, we examined data security – defining what AI can see and use, and how that interaction is monitored.
Now we turn to the third side of the triangle: governance.
If identity tells us who is acting, and data security defines what they can access, governance determines how those actions align with organisational intent.
In other words: governance is the system of oversight, rules, and behaviours that ensures AI doesn’t just operate – it operates responsibly.
Why governance is the trickiest side of the Trust Triangle
Identity and data security may not be simple, but they are largely technical. They establish who can act and what they can access – complex but measurable boundaries.
Governance is different, because it asks whether those actions – even when technically permitted – actually align with organisational intent.
It forces organisations to decide:
- What AI should be allowed to do, and what it shouldn’t
- Where automation ends and human judgement begins
- How much risk is acceptable
- Who is accountable when something goes wrong
Those aren’t configuration questions. They’re leadership decisions – and they inevitably expose trade-offs like:
- Speed vs safety.
- Autonomy vs oversight.
- Collaboration vs control.
Governance is hard because it brings those trade-offs into the open – and because it has a habit of revealing uncomfortable truths:
- Data sprawl leadership didn’t know existed
- Long-standing over-permissioned access
- Informal workarounds and shadow processes
- Cultural habits that don’t align with policy
Governance is a journey, not a switch
As if that weren’t enough to deal with, governance is also a moving target. It reflects risk tolerance, organisational culture and strategic priorities – all of which evolve as:
- New AI use cases emerge
- Business priorities shift
- Regulatory expectations change
- Teams discover new ways of working
That’s why the most successful organisations don’t treat governance as a one-off initiative or a compliance exercise. They treat it as a leadership practice – something reviewed, refined, and strengthened as the organisation matures.
- Policies are adjusted.
- Risk thresholds are recalibrated.
- Oversight becomes more nuanced.
Done right, this enables governance to move from reactive to proactive over time, anticipating risk rather than responding to incidents.
The Data Governance Accelerator Programme
Many organisations recognise the need for stronger oversight, clearer ownership, and better alignment between AI ambition and risk tolerance, but struggle to translate that into practical steps.
That’s why we developed the Data Governance Accelerator Programme: a structured, leadership-focused approach to building mature, AI-ready governance without overwhelming the organisation.
Phase 1: Assess and Benchmark
Gain visibility into data risk and AI use cases. Agree on governance principles and define risk tolerance at leadership level.
Phase 2: Prioritise and Plan
Identify high-value data domains. Establish clear data owners and decision-makers. Focus on what matters most first.
Phase 3: Assemble and Engage
Introduce sensitivity labels, baseline DLP, retention policies, and monitoring – proportionately and with minimal disruption.
Phase 4: Drive and Deliver
Move from reactive to proactive oversight. Contextualise policies. Scale AI confidently, supported – not slowed – by governance
Phase 5: Monitor and Report
Embed governance into leadership practice through regular reviews, escalation pathways, executive dashboards, and training.
Turning governance into action
Let’s be real: no matter how strong your policies are, they can’t shape behaviour on their own. That’s why governance can’t be viewed as a standalone element. It relies on the other two sides of the Trust Triangle to enforce leadership decisions.
Microsoft Purview enforces data rules:
- Sensitivity labels that reflect business priorities
- Data loss prevention policies aligned to risk tolerance
- Retention rules that support regulatory and operational needs
- Controls on how sensitive information can be shared or moved
Microsoft Defender provides the oversight layer:
- Risk alerts and anomaly detection
- Insider risk signals
- Automated investigation and response workflows
- Visibility into behaviour that falls outside expected norms
Together, they make governance measurable. They turn abstract principles – “protect sensitive data”, “reduce risk”, “enable safe AI” – into operational controls. Governance doesn’t sit above them – it directs them.
Closing the triangle
When identity, data security, and governance work together, the Trust Triangle is complete.
- Identity clarifies who can act.
- Data security defines what they can access.
- Governance ensures how those actions align with the organisation’s priorities and risk tolerance.
None of these elements works in isolation. Strong identity without governance can still allow misaligned decisions. Robust data controls without oversight can drift over time. Governance without enforcement remains theory.
But when all three are designed deliberately, AI becomes more than a powerful capability. It becomes a controlled, accountable, and scalable part of how the organisation operates.
If your organisation is investing in AI, it’s worth asking whether the HOW is as well defined as the WHO and the WHAT.
And if it isn’t, that’s where the real work begins.