AI Governance in HR: How Hospitality Employers Should Govern AI Before a Complaint Forces It
Quick answer:
AI governance in HR means knowing where AI is already used, matching controls to consequences, naming an owner for each use and monitoring what happens after launch, before a complaint forces it.
Most organisations will create rules for using AI. The question is what will cause them to do it. Some will act early, while others will wait until a candidate challenges a decision or a supplier activates a feature nobody realised was being used.
Why does AI governance in HR need more than a policy?
Because a policy employees acknowledge and managers rarely revisit has very little effect on how people use AI during a busy working day. AI governance in HR needs to show up in ownership, decisions and working practices.
This final edition of the September series turns to the practical question: how should an organisation govern all of this?
Where is AI already being used in your hotel or restaurant?
In more places than the leadership team realises. An organisation cannot govern what it does not know exists. Some uses are visible because HR introduced them. Others are harder to see:
A recruitment platform, employee support assistant or analytics tool introduced through a formal HR project.
A feature inside an existing system, added through a supplier update or switched on as an option.
A manager experimenting with a public tool to draft documents, summarise information or solve everyday problems.
A useful AI inventory records, for each use:
The purpose of the use.
The information involved.
The people affected.
Who currently owns the outcome.
Whether it is an approved system, a supplier feature or informal experimentation.
The inventory will never be complete. New uses keep appearing, so this cannot be a one-off exercise.
How much control does each AI use need?
The consequence should determine the control. Treat every use as high risk and you create a process people avoid. Treat every use as an ordinary productivity tool and important decisions go without scrutiny.
An employee tidying a routine presentation with AI is a different concern from a system ranking job applicants. A tool that searches the policy library is different from one that recommends who should be considered for redundancy.
For HR uses, ask:
Does it affect access to employment, pay, progression, performance or job security?
Does it use sensitive information?
Can the person affected understand or challenge the outcome?
Could an error affect one individual or many?
The answers set the level of approval, documentation, testing and monitoring. Proportionality is what makes governance credible.
Who should own AI governance in HR?
Each significant use needs one identifiable owner, even when several functions contribute. Shared expertise can create a situation in which everybody owns one part and nobody owns the outcome.
The owner does not need to be a technical expert. They need enough understanding to ask sensible questions and enough authority to act, including pausing the use.
The owner should still be identifiable six months later, when attention has moved to another project.
Is choosing a responsible AI supplier enough?
No. A strong supplier cannot compensate for a poorly designed internal process.
So ask the supplier more than whether the product works:
How is the system tested, and what information was used to develop it?
How is performance monitored, and what changes when the product is updated?
What explanation is available when an output is challenged?
What support is provided if an unintended pattern appears?
Keep enough control to suspend or restrict a feature rather than depend on the supplier's timetable.
What should you monitor after an AI tool goes live?
Both performance and behaviour. Before launch you test what you expect people to do. After launch you see what people actually do.
Monitoring should cover:
Whether the outputs are accurate and useful.
Who may be affected differently.
Whether managers are overriding recommendations.
Complaints, corrections and unusual outcomes.
Signs that the use has expanded beyond its original purpose.
The absence of complaints is not evidence that everything is working. Candidates and employees may not know AI influenced the process.
Design the oversight before launch. Adding it after something goes wrong leaves the organisation reconstructing decisions it may no longer understand.
Does ISO 42001 solve AI governance?
It provides structure, but it cannot replace ownership. ISO/IEC 42001 treats AI governance as an ongoing discipline rather than a collection of isolated technology decisions.
The real test is whether governance works when somebody is under pressure and the system produces an answer people want to accept. If the response depends on finding a document rather than knowing who is responsible, the governance is not yet strong enough.
What is HR's role in AI governance?
HR should help write the rules, even though it should not own AI governance alone. The function knows which decisions carry personal consequences and where managers already struggle with complexity.
HR should help define which uses need greater scrutiny, what meaningful human review looks like and how employees can raise concerns. It should challenge language that hides consequential decisions behind technical descriptions.
That may occasionally make HR an inconvenient voice in the room. Sometimes that is exactly what the organisation needs.
How do you govern AI in HR before a complaint writes the rules for you?
By building the governance while there is still room to think. Once a complaint has been raised, legal exposure and reputation begin to shape every response.
In practice:
Find out where AI is already being used, including supplier features and informal experimentation.
Keep the inventory alive with a simple way to add and assess new uses.
Match the level of control to the consequence for the person affected.
Name one owner for each significant use, with the authority to pause it.
Ask suppliers how they test, monitor and explain the system, and keep the right to suspend a feature.
Design monitoring of performance and behaviour before launch.
Be willing to pause, change or stop a use when the evidence requires it.
Rules written early give people somewhere to take a concern. Rules written after a failure usually explain why confidence was misplaced.
How AI governance connects to readiness, process quality and the person affected
This edition closes the September series on AI in HR. It began by asking what we allow AI to influence in people decisions, because a person may approve the outcome without the decision having started with them.
The series then looked at AI readiness as an organisational question rather than a technology one. Governance rests on the same foundation. An organisation with unclear processes and unclear ownership cannot govern a tool that inherits both.
Last week turned to what hospitality leaders owe the person affected by an AI decision. Governance is how that obligation becomes practice: a named owner, proportionate controls and a route to challenge an outcome.
In a nutshell
Keep an evolving inventory of formal, embedded and employee-led AI use.
Controls should reflect the effect a use could have, rather than treating every application alike.
Shared expertise across functions must not obscure who owns each outcome.
Governance continues after approval, when real behaviour and consequences become visible.
HR should help set boundaries before a complaint writes them for the organisation.
Frequently asked questions
What is AI governance in HR?
AI governance in HR is the set of ownership, decision and monitoring practices that control how artificial intelligence is used in recruitment, performance, pay, employee relations and workforce planning. It shows up in who owns each use, how controls match consequences and what happens when the technology produces something unexpected.
How do you find out where AI is already being used in an organisation?
Build an inventory that covers three categories: systems HR introduced formally, features embedded in existing software through supplier updates, and informal employee experimentation with public tools. Record the purpose, the information involved, the people affected and who owns the outcome. Keep it alive, because new uses appear as working practices develop.
Who should own AI governance in HR?
Each significant AI use needs one identifiable owner, even when technology, legal, procurement, data protection and HR all contribute. The owner needs enough understanding to ask sensible questions and enough authority to act, including pausing the use. Executive sponsors set the appetite and boundaries so managers are not left carrying accountability without authority.
What should an AI governance policy for HR include?
It should describe how uses are identified and added to an inventory, how the level of control is matched to the consequence for the person affected, who owns each significant use, what suppliers must explain and support, how performance and behaviour are monitored after launch, and how a candidate or employee can raise a concern.
Does ISO 42001 certification mean an organisation's AI is well governed?
Not on its own. ISO/IEC 42001 provides a structured approach to an AI management system and can bring consistency to identifying uses, assessing risk and assigning responsibility. Certification gives assurance about the management system, but it does not remove accountability for individual decisions or guarantee managers know what to do under pressure.
Why should hospitality HR help write AI rules rather than leave it to IT?
Because HR understands where technology meets recruitment, performance, employee relations and job security, and which decisions carry personal consequences. HR should help define which uses need greater scrutiny, what meaningful human review looks like and how employees raise concerns. It should also be prepared to draw boundaries where a use is hard to reconcile with responsible employment practice.