Your business may already be using AI even if it has no formal AI programme.
An employee drafts a proposal with a public chatbot. A team summarises meeting notes. A software product adds an AI feature during an update. These uses can be helpful, but they also create questions about data, access, accuracy and accountability.
A practical review starts by making those uses visible.
Ten questions to ask
| Question | Evidence to look for | Next action if unclear |
|---|---|---|
| 1. Which AI tools are being used? | Tool inventory, browser extensions, software features and team declarations | Create a simple register with an owner and purpose |
| 2. What business purpose does each tool serve? | A named task, user group and expected output | Stop or review uses with no clear business need |
| 3. What information enters the tool? | Examples of prompts, uploaded files and connected data sources | Classify the information and restrict inappropriate input |
| 4. Who can access it? | User list, roles, shared accounts and offboarding steps | Assign individual access and remove unused accounts |
| 5. What decisions can its output influence? | Workflow map and approval points | Require human review where mistakes have meaningful consequences |
| 6. How is accuracy checked? | Review instructions, test examples and correction records | Define who checks outputs and what evidence they use |
| 7. What happens to submitted data? | Vendor terms, settings and retention information | Review the vendor and configure available privacy controls |
| 8. How are incidents reported? | Named contact and escalation procedure | Add AI-related issues to the existing incident process |
| 9. Do employees know the boundaries? | Short guidance, onboarding and examples | Give teams practical instructions for allowed and prohibited use |
| 10. Who owns the next action? | Named business and technology owners with dates | Record gaps, priorities and accountable owners |
Keep oversight proportionate to the use
A low-consequence drafting aid does not need the same controls as a tool that recommends payments, affects customers or acts on connected systems. Assess the information involved, the consequences of error and the ability of a person to review or reverse the outcome.
Human review should also be specific. "A person is involved" is not enough if nobody knows what to check or has the information needed to challenge the output.
Review access and operational continuity
AI oversight includes ordinary account discipline. Know who has access, avoid shared credentials, remove access when roles change and record which systems an AI feature can reach.
If a tool becomes unavailable or produces an unsuitable output, the team should know how to continue the work. A manual fallback is particularly useful during early adoption.
Use external resources for their actual purpose
Singapore's Personal Data Protection Commission maintains resources describing Singapore's approach to AI governance. Use the current guidance as a primary reference when detailed governance claims are needed: PDPC guidance on Singapore's approach to AI governance.
The Cyber Security Agency of Singapore's Internet Hygiene Portal provides non-intrusive checks for websites, email and network connectivity. It can support a limited internet-hygiene review; it is not a complete security assessment or AI governance certification: Internet Hygiene Portal.
Turn the review into decisions
For every gap, record an owner, evidence and a next action. Some issues may need a configuration change or clearer guidance. Others may reveal a wider process, security or governance need.
The goal is useful visibility: what the business uses, which risks matter, who decides and how the organisation will respond when something changes.
Explore Switch's cybersecurity and AI governance services, or book a discovery conversation to review where to begin.