About

AI Governance Checklist for Jamaican Organisations

AI Governance Checklist for Jamaican Organisations
Published on 8/6/2026

Artificial intelligence is already inside many Jamaican organisations, even where leaders have not formally approved an “AI project.” Staff may be using generative AI to draft emails, vendors may be embedding AI into HR or CRM platforms, and regulated teams may be relying on automated fraud, credit, or customer-risk tools.

That creates a governance challenge. AI can improve productivity, reduce manual work, and support better decisions, but it can also expose personal data, amplify bias, produce inaccurate outputs, or create accountability gaps. For Jamaican organisations subject to the Data Protection Act, 2020, AI governance is not a future concern. It is part of responsible privacy, risk, compliance, and corporate governance today.

This checklist is designed for boards, executives, compliance officers, data protection officers, legal teams, IT leaders, HR managers, and risk professionals who need a practical way to control AI use without blocking innovation.

What AI governance means in practice

AI governance is the system of policies, roles, controls, evidence, and review processes used to ensure AI is developed, bought, deployed, and monitored responsibly. It answers practical questions such as:

  • Who is allowed to approve AI use cases?

  • What personal data can be entered into AI tools?

  • How are vendors assessed before AI tools go live?

  • When is human review required before an AI-assisted decision affects a person?

  • What evidence can the organisation show to auditors, regulators, customers, or the board?

Strong AI governance does not require every organisation to build complex technical models. A small business using AI for marketing drafts needs proportionate controls. A financial institution using AI for fraud monitoring, customer profiling, or anti-money laundering risk alerts needs a higher level of assurance.

The key is proportionality. The greater the potential impact on individuals, customers, employees, financial crime controls, or critical services, the stronger the governance should be.

Why Jamaican organisations should act now

Jamaica’s Data Protection Act, 2020 places obligations on data controllers around fair and lawful processing, transparency, purpose limitation, security, retention, accountability, and the rights of individuals. AI systems often interact directly with these obligations because they rely on data, generate inferences, and may influence decisions about people.

AI governance is also becoming a business expectation. International partners, parent companies, correspondent banks, insurers, outsourcing clients, and technology vendors are increasingly asking organisations to demonstrate responsible AI practices. Frameworks such as the NIST AI Risk Management Framework and the OECD AI Principles reinforce similar themes: accountability, transparency, robustness, fairness, security, and human oversight.

For Jamaican organisations, the practical objective is clear: align AI adoption with privacy, cyber security, corporate governance, anti-money laundering, and operational risk controls before an incident occurs.

Step 1: Create an AI inventory

You cannot govern what you have not identified. Start by creating a central AI inventory that covers approved tools, pilot projects, vendor systems with AI features, and informal staff use of public AI platforms.

At minimum, the inventory should record:

  • The business unit using the AI tool

  • The purpose of the tool

  • Whether personal data, sensitive personal data, customer data, employee data, or confidential information is involved

  • Whether the tool is internally built, vendor supplied, or publicly available

  • The decision or output the tool supports

  • The owner accountable for the use case

  • The current status, such as proposed, pilot, live, suspended, or retired

This inventory should connect with your broader data mapping work. If your organisation is still building that foundation, PLMC’s guide on a step-by-step roadmap for implementing Jamaica’s Data Protection Act can help align AI governance with privacy implementation rather than treating it as a separate project.

Step 2: Classify AI use cases by risk

Not every AI tool needs the same approval process. A practical risk classification model helps leaders decide which controls are required before deployment.

AI risk level

Typical examples

Governance expectation

Low

Drafting internal emails, summarising non-confidential public information, brainstorming marketing ideas

Basic policy rules, staff training, no confidential or personal data entered into public tools

Medium

Customer service chatbots, internal analytics, AI-assisted document review, productivity tools connected to business systems

Approved use case, privacy review, vendor due diligence, access controls, output verification

High

Recruitment screening, credit scoring, insurance decisions, employee monitoring, biometric identification, health triage, AML risk scoring, fraud alerts

Senior approval, documented risk assessment, human oversight, testing for bias and accuracy, enhanced monitoring, board-level reporting where appropriate

Prohibited or restricted

Tools that secretly process personal data, make final decisions without review in high-impact contexts, or use data outside approved purposes

Do not deploy unless legal, privacy, security, and executive approvals confirm a lawful and controlled basis

This classification should be documented and reviewed periodically. A tool that starts as low risk can become medium or high risk if it is connected to customer data, employee records, payment systems, or decision-making workflows.

Step 3: Assign clear ownership and accountability

AI governance fails when responsibility is scattered. Your organisation should identify who owns AI risk at the executive level and who approves AI use cases operationally.

A practical governance structure may include:

  • Board oversight for AI risks that may affect strategy, reputation, regulatory compliance, or customers

  • Executive accountability through a senior leader such as the CEO, COO, CIO, CRO, General Counsel, or Data Protection Officer, depending on the organisation

  • A cross-functional AI governance group involving privacy, legal, compliance, cyber security, HR, procurement, risk, audit, and business owners

  • Named business owners for each AI system or use case

Boards should not be expected to review every prompt or technical configuration. They should, however, expect regular reporting on material AI risks, high-risk deployments, incidents, unresolved compliance gaps, and whether management has sufficient controls. For broader board-level context, see PLMC’s article on privacy and legal risks boards should review each quarter.

Step 4: Establish an AI policy and acceptable use rules

An AI policy should give employees clear boundaries. It should be short enough to be read, practical enough to be followed, and specific enough to support enforcement.

Your AI policy should address:

  • Approved and prohibited AI tools

  • Rules for entering personal data, customer data, employee data, trade secrets, financial information, contracts, or confidential material

  • Human review requirements before AI-generated content is used externally

  • Requirements for fact-checking, citation checking, and professional judgement

  • Rules for AI-generated marketing, legal, HR, financial, or compliance content

  • Disciplinary or corrective action for misuse

  • Escalation channels for uncertainty, incidents, or suspected data exposure

The policy should not sit alone. It should align with privacy notices, information security policies, incident response plans, HR policies, procurement procedures, retention rules, and data subject rights procedures. If you are reviewing your policy framework more broadly, PLMC’s guide to the minimum set of Data Protection Act policies for compliance is a useful starting point.

Step 5: Build privacy controls into AI use

AI governance and data protection compliance are closely linked. Before any AI system processes personal data, the organisation should confirm why the data is needed, whether the use is fair and lawful, and whether individuals have been given appropriate information.

Key privacy questions include:

  • What categories of personal data will be processed?

  • Is sensitive personal data involved?

  • What is the lawful basis for processing?

  • Is the AI use compatible with the original purpose for which the data was collected?

  • Has the organisation explained the use clearly in a privacy notice or other communication?

  • Can individuals exercise applicable rights in relation to their data?

  • Are automated or AI-assisted decisions subject to meaningful human review where needed?

  • Are retention limits defined for prompts, outputs, logs, training data, and reports?

For medium-risk and high-risk AI systems, a documented privacy impact assessment or AI risk assessment is strongly recommended. This should not be treated as paperwork after launch. It should shape the design, procurement, testing, and approval process before the system goes live.

A Jamaican governance and compliance team reviews printed AI risk assessment materials around a meeting table, with folders labelled privacy, security, vendor review, and board oversight.

Step 6: Review vendors before approving AI tools

Many AI risks enter through third-party systems. A vendor may process data overseas, retain prompts for service improvement, use subcontractors, or introduce new AI features through routine software updates.

Before approving an AI vendor, ask for evidence on:

  • Data hosting locations and cross-border transfer arrangements

  • Whether customer data is used to train or improve the vendor’s model

  • Security certifications, penetration testing, vulnerability management, and access controls

  • Incident notification timelines and breach cooperation

  • Subprocessors and subcontractor controls

  • Data retention and deletion rules

  • Audit rights, compliance reporting, and contractual remedies

  • Explainability, accuracy testing, bias testing, and human oversight features where relevant

Procurement should not approve AI tools on functionality alone. Legal, privacy, security, and compliance teams should review the risk profile before contracts are signed or staff are allowed to upload business data.

Step 7: Require human oversight for consequential decisions

AI should not become an invisible decision-maker in situations that significantly affect people. Jamaican organisations should be especially careful where AI influences hiring, termination, lending, insurance, customer onboarding, fraud escalation, access to services, disciplinary action, or eligibility decisions.

Human oversight should be meaningful, not symbolic. The reviewer should understand what the AI system is doing, have authority to challenge or override the output, and have access to relevant context. If a staff member simply accepts every AI recommendation without question, the organisation may still be relying on automated decision-making in practice.

Good oversight includes documented decision criteria, escalation thresholds, periodic sampling, reviewer training, and evidence that AI outputs are challenged when they appear inaccurate, unfair, incomplete, or inconsistent.

Step 8: Test for accuracy, bias, and reliability

AI systems can produce confident but incorrect results. They may also perform differently across groups, locations, languages, accents, names, demographic characteristics, or data quality conditions. Testing should therefore be built into both pre-launch approval and ongoing monitoring.

Testing should consider:

  • Accuracy against known examples or validated datasets

  • False positives and false negatives

  • Performance across relevant customer, employee, or applicant groups

  • Whether outputs are explainable enough for the intended use

  • Whether staff can identify and correct errors

  • Whether the system remains reliable after updates or changes

For example, an AML or fraud tool that produces too many false positives can overwhelm compliance teams and delay legitimate customers. A recruitment screening tool that filters out qualified applicants based on poor proxies can create fairness and reputational risks. A chatbot that gives inaccurate privacy or financial information can mislead customers.

Testing should be documented, with clear pass or fail criteria. Where risks cannot be reduced to an acceptable level, the system should not be deployed in that form.

Step 9: Strengthen cyber security and access controls

AI systems create new security risks. Staff may paste confidential data into public tools. Attackers may manipulate prompts. Vendors may store logs that contain sensitive information. AI outputs may include hidden instructions, malicious links, or inaccurate code.

Your cyber security controls should include role-based access, multi-factor authentication where appropriate, logging and monitoring, secure configuration, encryption, vendor access controls, data loss prevention, and incident response procedures. Staff should be trained not to enter personal data or confidential information into unauthorised AI tools.

Organisations that already use recognised security frameworks should map AI risks into those controls. For Jamaican organisations comparing approaches, PLMC’s discussion of ISO/IEC 27001 and NIST for data security compliance can help frame the decision.

Step 10: Train employees before AI use becomes routine

AI governance depends heavily on staff behaviour. Even the best policy will fail if employees do not understand what they can and cannot do.

Training should be practical and role-based. A marketing team needs guidance on checking AI-generated claims and avoiding unauthorised customer data use. HR needs guidance on recruitment, employee monitoring, fairness, and confidentiality. Compliance teams need guidance on explainability, evidence, and escalation. IT teams need guidance on secure configuration, vendor review, and monitoring.

Training should cover real examples, not just definitions. Employees should know how to recognise risky prompts, when to escalate a use case, how to verify outputs, and what to do if information may have been exposed.

Step 11: Create an AI incident response process

AI incidents may not look like traditional data breaches. They can include unauthorised disclosure through prompts, harmful or discriminatory outputs, incorrect customer advice, model manipulation, vendor failure, or reliance on inaccurate AI-generated information.

Your incident process should define how AI-related events are reported, triaged, investigated, contained, documented, and escalated. It should also clarify when an event may trigger obligations under data protection, cyber security, contractual, employment, financial services, or sector-specific requirements.

The organisation should keep an incident log and use lessons learned to update policies, training, vendor controls, and technical safeguards.

Step 12: Monitor, audit, and report

AI governance is not a one-time approval exercise. Tools change, vendors update models, business users expand use cases, and risk levels shift. Ongoing monitoring is essential.

A practical AI governance reporting pack should include:

Governance area

Evidence to maintain

Review frequency

AI inventory

Current list of tools, owners, purposes, data categories, and risk ratings

Quarterly or when new tools are introduced

Risk assessments

Privacy, security, legal, operational, and fairness assessments

Before launch and after material changes

Vendor controls

Due diligence files, contracts, security evidence, transfer reviews

Before contract approval and at renewal

Training

Attendance records, role-based materials, policy acknowledgements

At onboarding and annually

Incidents

AI incident register, investigation notes, corrective actions

Ongoing with periodic management review

Board reporting

High-risk use cases, incidents, unresolved gaps, assurance results

Quarterly or based on risk profile

Internal audit or compliance teams should periodically test whether AI governance controls are working in practice. This includes checking whether unapproved tools are being used, whether staff understand the policy, whether vendors were reviewed, and whether high-risk systems have current assessments.

A 30-60-90 day AI governance action plan

If your organisation is starting from scratch, avoid trying to solve everything in one meeting. Use a phased approach.

Timeline

Priority actions

Expected outcome

First 30 days

Appoint an AI governance owner, issue interim acceptable use rules, identify obvious high-risk tools, stop unauthorised use of public AI tools with confidential or personal data

Immediate risk reduction and leadership accountability

Days 31 to 60

Build the AI inventory, classify use cases, review priority vendors, draft or update AI policy, begin staff awareness training

Clear visibility of AI use and consistent rules

Days 61 to 90

Complete risk assessments for high-risk use cases, define board reporting, integrate AI into incident response and procurement, test monitoring controls

Operational governance and evidence for assurance

After 90 days, AI governance should become part of normal business operations. New AI tools should be reviewed before deployment, material changes should trigger reassessment, and board reporting should focus on risk, assurance, and unresolved gaps.

Common mistakes to avoid

The most common mistake is assuming AI governance is only an IT issue. It is also a privacy, legal, compliance, HR, procurement, cyber security, operational risk, and board oversight issue.

Another mistake is waiting for a perfect AI law before acting. Jamaican organisations already have obligations under data protection, employment, contract, consumer protection, financial crime, and corporate governance expectations. AI may be new, but accountability is not.

A third mistake is focusing only on public generative AI tools while ignoring AI embedded in existing vendor platforms. Many organisations already use AI through cloud software, HR tools, analytics platforms, payment systems, marketing automation, fraud monitoring, and customer service tools.

Finally, avoid creating policies that no one can follow. Effective AI governance must be practical. If staff do not know where to seek approval, which tools are allowed, or what data is prohibited, they will improvise.

Frequently Asked Questions

Does Jamaica have a specific AI law? Jamaica’s primary AI governance obligations currently come through existing legal and regulatory duties, especially data protection, cyber security, corporate governance, contracts, employment, and sector requirements. Organisations should not wait for a standalone AI law before implementing controls.

Is AI governance required under the Data Protection Act, 2020? The Act does not operate as an AI-specific statute, but AI systems that process personal data must still comply with data protection principles such as fairness, lawfulness, transparency, purpose limitation, security, retention, and accountability.

Who should own AI governance in a Jamaican organisation? Ownership should sit with senior management, supported by privacy, legal, compliance, IT, cyber security, procurement, HR, and business teams. Boards should oversee material AI risks and receive reporting on high-risk uses.

Can employees use free AI tools at work? Only if the organisation’s policy permits it and employees follow clear restrictions. As a general control, staff should not enter personal data, confidential business information, customer records, employee records, contracts, or sensitive information into unauthorised public AI tools.

What is the first step in building AI governance? Start with an AI inventory and interim acceptable use rules. Identify which tools are being used, what data they process, who owns them, and whether any use case could affect individuals, customers, employees, or regulated decisions.

Build AI governance before risk becomes an incident

AI can support innovation across Jamaican organisations, but only when it is governed with discipline. The most effective approach is to connect AI governance with the controls your organisation should already be building for data protection, cyber security, corporate governance, vendor management, and compliance.

Privacy & Legal Management Consultants Ltd. supports organisations in Jamaica with data protection implementation, governance, risk, compliance, training, and privacy awareness. If your organisation needs help assessing AI risks, strengthening policies, or building an audit-ready governance framework, start with a free consultation with PLMC.