Toolkit

The seven AI governance non-negotiables

The minimum baseline a medium-to-large enterprise operating in Sub-Saharan Africa needs in place before a board can confidently authorise AI adoption. Seven statements, each grounded in at least one binding instrument. Published in full, not gated.

Grounded and verified · 21 August 2026

Drawn from regulatory mapping across South Africa, Nigeria, Kenya, Rwanda and Ghana. Each statement shows the instruments it rests on, so you can check the reasoning rather than take it on trust. Where an instrument is pending rather than in force, it is labelled.

Most AI governance material is either a framework with no jurisdiction attached, or a compliance checklist with no reasoning attached. This is neither. It is the shortest list we could defend, written as policy statements a board can adopt and an auditor can test.

Two of the seven require a board-level decision rather than a management one. They are marked.

01

Named accountability

Board decision required

Every AI system has an owner at executive level, and the board governs AI.

Every AI system that processes personal data, makes or influences decisions affecting people, or takes automated actions on behalf of the enterprise must have a named accountable executive. The board — not management alone — must formally govern AI adoption, approve the enterprise AI policy, and receive at least annual reports on AI risk and compliance. This accountability cannot be delegated away.

What this requires in practice

  • A board resolution assigning AI governance to a specific committee or named director
  • A named C-suite executive accountable for the enterprise-wide AI register
  • A board-approved enterprise AI policy, reviewed annually
  • AI risk formally integrated into the enterprise risk management framework
  • A named business owner at senior management level for every high-risk system

Why it is non-negotiable

South Africa’s King V Code places AI governance explicitly on the governing body and creates director-level personal liability. Across Nigeria and Kenya, data protection law holds the controller accountable for all processing. Governance without named ownership defaults to diffuse responsibility — which means no responsibility in a regulatory investigation.

Grounded in King V Principle 10 (SA) · NDPA accountability (NG) · Kenya DPA (KE) · NAIS governance expectations (NG, KE)

02

Data residency verified

Know where every data artefact resides before deployment — not after.

Before any AI system processing personal data is deployed, verify and document the physical and contractual location of every data artefact it generates or handles — inputs, outputs, embeddings, logs, telemetry and fine-tuning data. Selecting a regional cloud instance is not sufficient. Vendor claims of local processing must be supported by contractual commitments and architecture documentation. Any system whose residency cannot be confirmed must not be deployed.

What this requires in practice

  • A data artefact inventory per system, covering prompts, outputs, embeddings, logs and telemetry
  • Contractual confirmation of processing location, not a marketing claim
  • Architecture documentation showing where each artefact physically rests
  • A documented position on any artefact that leaves the jurisdiction, and the lawful basis for it

Why it is non-negotiable

Regional cloud selection governs where primary data is stored. It frequently does not govern telemetry, logs, metadata, or the routing of inference itself. Enterprises consistently conflate the two, and the gap is invisible until a regulator asks a specific question.

Grounded in Kenya DPA s.50 (KE) · NITDA Cloud Policy (NG) · Rwanda Law 058 / NCSA certificate (RW) · POPIA s.72 and Data & Cloud Policy (SA)

03

Human oversight for material decisions

No fully automated decision that materially affects a person.

No AI system may produce a decision with legal consequences or significant effect on a customer, employee, supplier or citizen without a documented and tested pathway for human review, notification to the affected person that an automated decision was taken, and a mechanism to contest it and request human reconsideration. This applies whether the system is owned, licensed, or operated by a third party on the enterprise’s behalf.

What this requires in practice

  • A register of decisions classified as material, agreed with legal and risk
  • A named reviewer and a tested review path for each
  • Notification wording that actually reaches the affected person
  • A contest mechanism with a service standard, not a mailbox

Why it is non-negotiable

This is the most widely and consistently legislated AI requirement across all five jurisdictions studied. It is also the one most often satisfied on paper and not in practice: a review step that a reviewer has neither the time nor the information to perform is not oversight.

Grounded in POPIA s.71 (SA) · NDPA s.37 and GAID 2025 (NG) · Kenya DPA s.35 (KE) · Rwanda Law 058 · Ghana DP Bill s.53 (pending)

04

AI tool inventory

Know what AI is in use, by whom, and under what conditions — including what you did not authorise.

Maintain a register of all AI systems and tools in active use, including those procured by business units without central approval. Distinguish approved tools with documented handling conditions, conditionally approved tools with restrictions, and prohibited tools where no enterprise data is permitted. No employee may use an unapproved consumer AI tool to process enterprise data, customer data, or anything subject to confidentiality obligations. This must be actively enforced, not merely stated.

What this requires in practice

  • A live register, not an annual survey
  • Discovery through network, identity and expense signals — people under-report
  • A sanctioned alternative for every prohibited tool, or the policy will be ignored
  • Enforcement that someone actually owns

Why it is non-negotiable

Shadow AI is not an edge case. It is the default state of most enterprises that have not looked. A policy that prohibits without providing a sanctioned path simply moves the usage somewhere you cannot see it.

Grounded in POPIA accountability and King V AI policy requirement (SA) · NDPA and GAID 2025 (NG) · NCC pre-notification (NG telecoms)

05

Agentic systems require elevated controls

Board decision required

An agent that can act in your name is a different risk class from one that advises.

AI agents and automated workflows that can act in the enterprise’s name — executing transactions, sending communications, modifying data, invoking external tools, or making procurement commitments — require a higher standard than advisory systems. No agentic system enters production without: a documented list of actions it is and is not authorised to take; a human approval gate before any consequential action; tamper-evident structured logging of the decision chain; a tested kill-switch that halts the agent and revokes its credentials; and a behavioural baseline against which anomalies can be detected. An agent operating beyond its permission scope is a security incident, not a configuration issue.

What this requires in practice

  • An explicit allow-list and deny-list of actions, signed off by the business owner
  • An approval gate that cannot be bypassed under time pressure
  • Logging designed so the agent cannot alter its own record
  • A kill-switch that has actually been tested, with credential revocation included
  • Anomaly detection against a recorded baseline of normal behaviour

Why it is non-negotiable

Advisory AI produces text a human then acts on. Agentic AI acts. The control burden is not incrementally higher, it is categorically different — and the last line matters most: treating scope violations as configuration drift rather than as incidents is how organisations discover the problem late.

Grounded in POPIA s.71 automated decisions (SA) · NDPA s.37 and CBN governance expectations (NG) · Kenya DPA s.35 (KE) · general accountability obligations, all markets

06

AI vendor contracts

Five things in writing before any enterprise data enters the system.

Every contract with an AI vendor, model provider, integrator, or AI-enabled service provider must explicitly address, in writing, before any enterprise data enters the system: whether the vendor may use enterprise data to train, fine-tune or improve its models, and on what basis; data retention periods and deletion timelines; breach notification obligations and timelines; the identity and role of subprocessors with access; and the enterprise’s right to audit or obtain evidence of compliance. Contracts silent on any of these must not be executed until the gaps are resolved.

What this requires in practice

  • A standard AI addendum, so this is not renegotiated per deal
  • Subprocessor chains named, not referenced by a URL the vendor can change
  • Deletion timelines that survive the vendor’s own retention defaults
  • Audit rights that are exercisable in practice, not theoretically

Why it is non-negotiable

Standard processor terms predate generative AI and are silent on training use. Silence is not a prohibition — it is an unresolved question that becomes the enterprise’s problem at the point a regulator asks who trained on what.

Grounded in POPIA s.21 operator contracts (SA) · NDPA processor agreements (NG) · GAID 2025 subprocessor chain (NG) · Kenya DPA processor obligations (KE)

07

Minimum logging and incident response

You must be able to notify inside the shortest applicable window — which may be 48 hours.

Every AI system processing personal data must maintain logs sufficient to identify what data was processed, by what system, at what time, and with what output. Retain them for a minimum aligned to regulatory investigation timelines — at least 12 months. In an incident, the enterprise must be able to notify the relevant regulator within the shortest applicable window. Failure to notify in time is an independent violation, regardless of the underlying incident.

What this requires in practice

  • Logging designed for investigation, not just for debugging
  • 12-month minimum retention, tested by actually retrieving something old
  • An incident path that knows which regulator and which clock applies
  • A rehearsal, because the first time should not be the real time

Why it is non-negotiable

The windows differ by jurisdiction and by sector, and the shortest one governs. An enterprise operating across these markets is exposed to a 48-hour clock whether or not it has noticed.

Grounded in 48 hours — Rwanda NCSA, Nigeria NCC (telecoms). 72 hours — SA Information Regulator, Nigeria NDPC, Kenya ODPC. Plus CBN annual model validation (NG).

Using this

How to put it to work

These are written to be adopted, not admired.

Assess against it

Take the seven statements to your existing AI estate and mark each system red, amber or green. The gaps are usually in 2, 4 and 5.

Adopt what you can defend

A board can adopt all seven as policy in a single sitting. What takes time is 4 — building the register — and 5 — testing the kill-switch.

Watch the pending items

Ghana’s Data Protection Bill is not yet law. Kenya’s AI Bill is at committee. Neither changes what you should do; both change what you will be measured against.

Start here

Want this assessed against your actual estate?

The list is free. Applying it to a real organisation — finding the shadow tools, verifying where the embeddings live, testing whether the kill-switch works — is the engagement.