Five principles. One acronym. A governance tool that works in every boardroom, every sector and every jurisdiction.
Karl George MBE · Founder, The Governance Forum & Governance AI
May 2026
In Part 1, I mapped the global AI regulatory landscape: the UK’s principles-based approach, the EU’s binding AI Act, China’s enforcement regime, the US pivot to deregulation, Singapore’s practical frameworks, the Middle East’s investment-driven strategies, and Africa’s Continental AI Strategy. The picture is complex, but the conclusion is simple: every jurisdiction, regardless of its enforcement model, converges on the same core concerns. Fairness. Accountability. Transparency. Safety. The right to challenge AI decisions.
The question for boards is not whether these principles matter. It is how to apply them in practice, consistently, across every AI initiative the organisation undertakes.
As I do in my Effective Board Member (EBM) series, where I distil complex governance concepts into practical, memorable frameworks that directors can carry into every meeting, I have created an acronym for AI governance that does the same job. I call it
FACTS.
FACTS stands for Fairness, Accountability, Contestability, Transparency and Safety. It maps directly to the UK’s five principles, aligns with the OECD framework, addresses the core requirements of the EU AI Act, and provides a practical governance lens that works in any jurisdiction and any sector.
F
AI systems should not discriminate, create bias, or produce unfair outcomes for individuals, groups or communities. This includes both the data AI is trained on and the decisions it informs.
UK Principle: Fairness · OECD: Inclusive growth, sustainable development · EU AI Act: Non-discrimination requirements
A
There must be clear ownership of AI decisions, with named individuals responsible for oversight, governance and outcomes. AI does not remove human accountability; it requires it.
UK Principle: Accountability and governance · OECD: Accountability · EU AI Act: Human oversight, conformity assessment
C
People affected by AI decisions must have clear routes to challenge, question and seek redress for harmful or incorrect outcomes. If you cannot challenge it, it is not governed.
UK Principle: Contestability and redress · OECD: Access to effective remedy · EU AI Act: Right to explanation, redress mechanisms
T
Organisations must be able to explain how AI systems work, when they are being used, and how decisions are made. Transparency builds trust; opacity destroys it.
UK Principle: Appropriate transparency and explainability · OECD: Transparency · EU AI Act: Transparency obligations
S
AI systems must function reliably, securely and safely, with proper safeguards for data, privacy and human wellbeing. This encompasses cybersecurity, data protection, accuracy and resilience.
UK Principle: Safety, security and robustness · OECD: Robustness, security and safety · EU AI Act: Risk management, technical robustness
Governance frameworks only work if people can see them in action. Here are three everyday scenarios that bring FACTS to life.
Fairness means everyone gets clean water, not just those closest to the source. Accountability is the engineer responsible for maintaining the system. Contestability is villagers being able to question water quality and demand testing. Transparency is publishing how the water is filtered and what standards it meets. Safety is ensuring the water is genuinely drinkable, tested and certified.
Fairness ensures all genres, authors and perspectives get equal attention, not just bestsellers. Accountability is the librarian’s oversight of what the system recommends. Contestability is readers being able to request changes or flag inappropriate suggestions. Transparency is explaining how recommendations are generated. Safety is guarding personal reading data and ensuring recommendations are appropriate.
Fairness is equitable route coverage across all communities, not just profitable ones. Accountability is the transport authority taking responsibility for the system’s decisions. Contestability is citizens being able to request route changes and challenge service gaps. Transparency is sharing how routes are planned and what data informs them. Safety is protecting passengers through rigorous testing and human override capability.
Which resonates with you? The point is that FACTS applies wherever AI touches people’s lives, from the simplest system to the most complex.
The power of the FACTS framework becomes clearest when you examine what happens when each pillar is absent.
AI recruitment tools trained on historical hiring data have discriminated based on gender and race, systematically excluding qualified candidates. When the training data reflects past bias, the AI amplifies it at scale. Without active fairness governance, unfair outcomes are not a risk; they are a certainty.
When autonomous vehicles have caused accidents, the immediate question has been: who is responsible? The manufacturer? The software developer? The human “driver”? Without clear accountability structures, harm occurs and nobody owns the consequence.
Flawed AI credit-scoring systems have denied people access to finance based on opaque algorithmic decisions they could not see, understand or challenge. When there is no route to contest an AI decision, people are left powerless against a system that may be wrong.
Facial recognition deployed in public spaces without informing citizens is a transparency failure of the most fundamental kind. People cannot consent to, question or avoid a system they do not know exists.
AI systems in healthcare that have misdiagnosed patients illustrate what happens when safety is not rigorously tested and maintained. When the consequences of failure are harm to human health, safety must be non-negotiable.
These failures are not confined to autonomous vehicles and facial recognition. They play out in every sector where AI is being adopted. Consider how FACTS applies in a professional services, consultancy or housing context.
If AI prioritises large, high-fee clients in resource allocation or service delivery, smaller clients are systematically underserved. In housing, if AI-assisted triage prioritises certain tenant demographics over others, the bias may be invisible but the impact is real.
If an AI-assisted audit process misses a financial discrepancy and no named partner takes responsibility, you have an accountability vacuum. In social housing, if an AI-generated compliance report contains errors and the board accepted it without scrutiny, accountability rests with the board, not the AI.
If a client receives AI-generated tax advice that leads to penalties and has no route to challenge how that advice was produced, trust evaporates. In housing, if a tenant allocation decision is informed by AI and the tenant cannot challenge it, the organisation fails the contestability test.
If a client receives a risk assessment and does not understand that AI generated it, or how it weighted the factors, trust erodes. In governance, if a board paper has been substantially drafted by AI without the board knowing, the integrity of the governance process is compromised.
If an AI tool handling confidential client data is not properly secured, the consequences range from data breach to regulatory sanction to reputational destruction. In housing, tenant data entering free-tier AI tools without data processing agreements is a safety failure waiting to happen.
Having worked with boards across multiple sectors through my Effective Board Member programme and The Governance AI Journey, I consistently see the same governance gaps when it comes to AI. Here are the areas where most boards need to improve.
Many boards still treat AI as an IT matter rather than a governance responsibility. AI should be a standing board agenda item, with regular reporting on adoption, risk, policy compliance and emerging issues. The board cannot govern what it does not discuss.
Too many organisations have adopted AI without designating a named individual responsible for oversight. Whether it is an AI champion, a chief AI officer, or a designated board member, someone must own the accountability. Without it, FACTS collapses at the second letter.
Boards assume they understand AI well enough to govern it. They rarely do. A formal AI literacy assessment for directors, such as the GovernIQ™ Diagnostic, replaces assumption with evidence and identifies development priorities for each individual.
Having an AI acceptable use policy is necessary but not sufficient. The question is whether staff know it exists, understand it, and follow it. The Leeds University research found that 44% of housing associations have no AI policy at all, and those that do often have minimal staff awareness. Policy without implementation is governance theatre.
AI introduces new categories of risk that traditional risk registers do not capture: hallucination risk, bias risk, data leakage, shadow AI, intellectual property exposure, and regulatory compliance. A dedicated AI risk register, or an AI section within the corporate risk register, is essential.
Boards rely on executive assurance that AI is being used responsibly. In a regulatory environment that is tightening across all jurisdictions, independent assurance, whether through internal audit, external review or a framework like the Governance AI Quality Mark, provides the evidence base that executive assurance alone cannot.
Most organisations have not considered how someone affected by an AI decision would challenge it. For housing providers, this means tenant allocation, complaint triage or service prioritisation decisions influenced by AI. For professional services firms, it means client advice. The EU AI Act requires this for high-risk systems. The UK principles expect it. But few organisations have operationalised it.
AI governance is often dependent on a single champion or enthusiast. If that person leaves, the governance framework goes with them. Embedding AI governance into board committee structures, terms of reference and the corporate governance framework ensures continuity beyond any individual.
For every AI initiative, every board paper that references AI, and every decision that involves AI-assisted outputs, directors should apply the FACTS lens by asking five questions.
F – Fairness: Is it fair? Who benefits, who might be disadvantaged, and have we tested for bias? Are we confident that the AI does not systematically favour or exclude particular groups, clients or communities?
A – Accountability: Is someone accountable? Who owns the outcomes? Who reviews the outputs? Is that ownership documented in a terms of reference or role description? Can we name the person who is responsible?
C – Contestability: Can it be contested? If someone is affected by an AI-informed decision, do they know about it? Can they challenge it? Is there a clear, accessible route to redress? Have we communicated that route?
T – Transparency: Is it transparent? Can we explain how the AI works, when it is used, and what informs its outputs? Do our staff, clients and stakeholders know when AI is involved? Are we being honest about what AI does and does not do?
S – Safety: Is it safe? Is the data protected? Is the system tested? Is human oversight in place? Are we using approved platforms with appropriate data processing agreements? Have we assessed the risk of hallucination, inaccuracy and data leakage?
If the answer to any of these is “no” or “I don’t know,” you have identified a governance gap that needs to be addressed before you proceed. That is not bureaucracy. That is responsible leadership.
FACTS is not a compliance checklist. It is a governance discipline. It should be applied not once, at the point of adoption, but continuously, at every board meeting, every review and every decision where AI plays a role.
The FACTS framework is embedded throughout The Governance AI Journey, the seven-module programme I developed for boards and senior leaders to adopt AI responsibly.
In Module 1 (AI Wake-Up Call), we introduce the global regulatory landscape and the FACTS principles as the governance lens for everything that follows. Directors complete a literacy review and the board conducts a maturity assessment, providing the baseline for FACTS governance.
In Module 2 (GovernIQ™ Diagnostic), we assess how well the organisation currently addresses each FACTS dimension at individual, departmental and organisational level. This replaces assumption with evidence.
In Module 3 (Departmental Use Case Taster), we pilot a live AI use case with FACTS governance applied in practice. The AI steering committee practises oversight through the FACTS lens.
In Module 4 (Governance AI Playbook), we co-create the policies, oversight structures and accountability frameworks that operationalise FACTS across the organisation, benchmarked against the Governance AI Code and global standards including ISO 42001.
In Module 7 (Governance AI Quality Mark), independent validation confirms that FACTS governance is genuinely embedded, not just documented. This provides the assurance that boards, regulators, funders and stakeholders increasingly expect.
The global AI regulatory landscape is complex and fast-moving. But the underlying principles are remarkably consistent. Fairness. Accountability. Contestability. Transparency. Safety. FACTS.
For boards and directors, FACTS provides what every effective governance framework needs: a memorable structure, a practical application, and a universal relevance that works across jurisdictions, sectors and the evolving AI landscape. It maps to the UK’s five principles, aligns with the OECD, addresses the EU AI Act, and provides a governance lens that holds regardless of how individual jurisdictions choose to regulate.
In the same way that my Effective Board Member series gives directors practical tools for governance, FACTS gives them a practical tool for AI governance. Five letters. Five questions. Applied to every AI initiative, every board paper, every decision. That is how responsible AI governance works in practice.
The Governance AI Journey takes boards and senior leaders from AI literacy through to accreditation, with the FACTS framework at its core. It begins with the AI Wake-Up Call Workshop.
Contact Karl George MBE at The Governance Forum
[email protected]
Part 1
How the World Is Governing AI: What Every Board Needs to Know
Part 2
The FACTS of AI Governance: A Practical Framework for Every Board
Sources
UK Government, A Pro-Innovation Approach to AI Regulation, White Paper March 2023; Government Response February 2024. Five principles: safety, transparency, fairness, accountability, contestability.
OECD, AI Principles, adopted May 2019, endorsed by 45+ countries.
European Union, AI Act, entered into force August 2024.
Leeds University Business School / Service Insights (2025), Aspirations and Applications of AI in Social Housing.
Microsoft / LinkedIn, Work Trend Index 2024. 78% of AI users bring own tools to work.
Gallup (2024). Only 15% of US employees report their workplace has communicated a clear AI strategy.
ISO/IEC 42001:2023, Artificial Intelligence – Management System.
Company Number: 16359543