AI Governance and Implementation Roadmap

Prepared for: Northbank Trust Company (illustrative) — an independently owned Trust Company, 32 staff, Jersey.
Prepared by: Change AI Consortium
Roadmap horizon: 30 days to a board-signed-off plan, then 90 days to first delivery.

1. Named owner

Accountable owner: Head of Risk and Compliance, reporting to the board monthly on progress against this roadmap. AI decisions are not left to individual staff or to IT; one named role holds the plan.

2. Identified opportunities

Five opportunities, ranked by priority, each carrying a technical deliverable and a business deliverable, a risk, an impact and an owner.

OpportunityTechnical deliverableBusiness deliverableRiskImpactOwner
1. Client onboarding review support AI-assisted first read of onboarding documents against the firm's own checklist, output reviewed by staff before any decision. Staff training on how to brief and check the tool, and when to override it. Medium — document misread could delay onboarding, not cause client harm on its own High Head of Client Services
2. Internal policy drafting support AI-assisted first draft of internal policy updates from regulatory source material, never published without a named sign-off. A short reviewer's checklist, so a human always checks the draft against the source before it becomes policy. Low — nothing reaches a client or a regulator unreviewed Medium Head of Risk and Compliance
3. Correspondence drafting AI-assisted first draft of routine, non-client-data correspondence templates. A style guide so drafts sound like the firm, not like a generic assistant. Low Medium Office Manager
4. Board reporting pack assembly AI-assisted collation of the monthly board pack from existing internal reports, formatting only, no new analysis generated. A named reviewer confirms every figure against source before the pack is circulated. Medium — a wrong figure reaching the board is a real error, caught by the review step Medium Company Secretary
5. Client-matter AI use Deliberately not scoped this phase. No client data, including anything covered by legal professional privilege, goes into an AI tool until the governance and technical controls in section 4 are in place and tested. A board decision, recorded in minutes, on if and when this phase opens, with named conditions. High — confidentiality and privilege are the firm's top concern High The Board

3. Why this order

Every opportunity in the first four rows keeps AI away from client data and privileged material entirely, and keeps a named human checking the output before it goes anywhere. Client-matter use, the highest-value and highest-risk opportunity, is named and scoped, not started, until the controls below are proven on lower-risk work first. This is a deliberate ordering decision, not caution for its own sake.

4. AI policy

Northbank Trust Company — AI Use Policy (illustrative)

1. Purpose. This policy sets out how Northbank Trust Company uses AI tools, so that every member of staff knows what is allowed, what is not, and who to ask.

2. Scope. Covers any AI tool used in the course of work, whether provided by the firm or brought by an individual. Personal AI accounts may not be used for firm business.

3. What AI may be used for. Drafting support on internal, non-client-data material only: policy drafts, internal correspondence templates, report formatting. Every output is reviewed by a named person before it is used or sent.

4. What AI may not be used for. Any client data, any matter covered by legal professional privilege, or any regulated decision, until the board records a specific, minuted decision to open that use, with named controls in place.

5. Approved tools. Only tools on the approved list, held by the Head of Risk and Compliance, may be used. Requests to add a tool go through that role.

6. Ownership. The Head of Risk and Compliance owns this policy, reviews it quarterly, and reports on its use to the board monthly.

7. Breach. A breach of this policy is reported to the Head of Risk and Compliance the same day it is noticed. This is a learning process, not a disciplinary trap, for the first year of use.

5. Controls supporting the roadmap's first stages

Controls in place from day one

6. Value tracking

Each opportunity in section 2 is reviewed 90 days after it starts against one plain question: is this saving real time, and is the output still being checked properly? An opportunity that fails either test is paused, not quietly continued. This is how the roadmap avoids the most common failure seen across the sector: AI deployed with no clear use case and no way to judge whether it is working.

7. First 30 days

  1. Board reviews and signs off this roadmap, names the accountable owner formally in minutes.
  2. Alignment workshop output confirmed against this document; any changes logged.
  3. Approved tool list published to staff, alongside the AI policy above.
  4. Opportunity 1 (onboarding review support) begins as the first live test, chosen because it has the clearest human check already built into the existing process.