Skip to content
Navigating AI Governance
and Compliance in Business

Navigating AI Governance and Compliance in Business

Most companies can't name the person responsible for their AI. Nur Aslan on why governance is a role, not a brake – and what a small team should do on Monday.

Meet Nur

Nurgül Aslan

Nurgül Aslan

Founder, IADM

iadm.academy

Nurgül Aslan – Nur to everyone – lives in Cologne and founded IADM, the International Academy for Digitalization and Management. She incorporated it in England, not Germany. I opened the episode by teasing her that it was to get away from German bureaucracy. She agreed, then corrected me.

Nurgül Aslan
Nurgül AslanFounder, IADM
1:18
"Yes, to get away from German bureaucracy – but this is not the only reason. IADM is CPD accredited, Continuing Professional Development accredited, and this is an accreditation organization in the UK. So this was also one main reason why I have established it in the UK."

She did not come to AI through technology. She came through people. Her background is HR and people development, and the research for her doctorate is where the topic found her: she surveyed 397 HR professionals across Europe, and kept running into the same hole.

Nurgül Aslan
Nurgül AslanFounder, IADM
5:36
"I also figured out the gap between the AI adoption, AI literacy and readiness. It is important on all levels, because every organization nowadays is using AI systems, AI tools."

A few weeks ago, Dr. Alexa Scheffler answered the software side of this on the podcast: are we allowed to use AI for this? Nur answers the people side – who is responsible, and how do they need to be trained. This is the second half of that conversation.

Nobody Can Answer the One Question That Matters

Nur's starting point: every organisation is using AI tools by now. The tools are not the gap.

Nurgül Aslan
Nurgül AslanFounder, IADM
2:51
"It is basically the gap between AI adoption and AI readiness. Because we see now everywhere AI apps, and every day new applications, tools which organizations are using – but no one knows how to use it, first of all, and at the same time also who owns the responsibility. Who is responsible for the results."

And it doesn't matter how big you are. Large company or small, she sees the same silence when you ask who owns the outcome.

Nurgül Aslan
Nurgül AslanFounder, IADM
5:59
"If you ask the question who is responsible for the result – if this system is working ethically and compliant and secure – no one can answer the question."

Part of the confusion is vocabulary. People use governance and compliance as if they meant the same thing, and Nur thinks that is where it starts going wrong. I tried to paraphrase the difference, and she agreed with it:

Ben Sufiani
Ben SufianiThe Captain
7:58
"So governance is the structured system that also is part of my strategy as the company. Compliance is sticking to the legal rules laid out by my country, that I have to stick to. And ideally they heavily overlap."

Compliance tells you the rules. Governance decides who in your company answers for them. Most companies have neither person nor plan.

When Nobody Owns It, the Answer Is No

I work with founders on one side and companies with thousands of people on the other. They fail in opposite directions.

Ben Sufiani
Ben SufianiThe Captain
8:24
"It feels like founders are not aware enough, and need to act. And big companies over-regulate themselves. … They are waiting always for us, normal people working in the company, to say: can I use this? And then they want to have a catalog of twenty-seven thousand questions answered, and then they will very likely say no, and it takes three to six months."

I've seen companies decide that nobody was allowed to use AI at all – for a year and a half.

Ben Sufiani
Ben SufianiThe Captain
32:02
"Just because no one in compliance, or including the CEO, had the balls to say: this is a manageable risk. We are going forward. We are not waiting until we have ten judges already making the calls."

That is what the missing owner costs. When no one answers for the result, the safest move for everyone in the room is to say no, so everyone does. Nur doesn't accept that this is what governance is for.

Nurgül Aslan
Nurgül AslanFounder, IADM
9:45
"It's not a brake. It's not blocking innovation or procedures. It is enabling organizations to work in a responsible way and be transparent. … It is an enabler. Again, it is not something that should slow down."

What I want from a compliance person is not a verdict. It's a route.

Ben Sufiani
Ben SufianiThe Captain
30:14
"Instead of them saying: dude, you can do all of this, but you have to take care of one, two, three. … I'll help you with that, so you can move on. Please, please create more people like that, Nur."

"No" is what you get when nobody owns the answer. "Yes, if…" is what you get when somebody does.

It's a Role, Not a Hire

So who should that somebody be? I asked for the smallest version, because most people reading this run teams of two to twenty – and because I remember how the data protection officer went.

Ben Sufiani
Ben SufianiThe Captain
13:59
"I'm not hiring anyone, I'm not paying an external service. I just want to do what I'm forced by the madness that is living as an entrepreneur in Europe. What do I need to do?"

Her answer is the most useful thing in the episode for a small company: you don't add a person. You add a responsibility to a person you already have.

Nurgül Aslan
Nurgül AslanFounder, IADM
15:17
"I would add the responsibilities that a certified AI officer is carrying to your current responsibilities. You don't need to hire someone. And my personal opinion is also that the person who is responsible for AI governance, AI compliance, should be someone who is from within the company already, because he knows the structure."

An outsider can do it, she says, but you would spend so much time explaining your own organisation to them that it stops being efficient. And the job itself is smaller than its title: "not as complex as people think."

If you survived GDPR, you are also closer than you think. In her words, GDPR "builds the basis" for the EU AI Act, and someone who understands data protection will understand the AI Act faster.

So, on air, I took the job. I'm already the data privacy officer at Pirate Skills. As of this episode I'm its AI officer too. Then I asked what that means for the one person I work with – because Alexa had told us the training record can be four lines in a text file.

Ben Sufiani
Ben SufianiThe Captain
17:05
"I have this wonderful employee called Christina. I think I need to train her. Is this just a line in a markdown document where I say: hey, I train Christina using what our AI system is like, and that's it?"
Nurgül Aslan
Nurgül AslanFounder, IADM
18:01
"It would be important that you train her that she has an understanding of the risk classes – and when a new AI tool comes in, that it has to be in the AI inventory, and that it has to be reported."

The two episodes fit together. Alexa is right that the record can be four lines. Nur is right about what those lines have to describe: someone who knows the risk classes, keeps the list of tools, and reports what's new.

The record is small. What it records has to be real.

The Monday List

I asked her to skip the theory: someone has just finished her programme, and walks into the company on Monday. What do they do?

Nurgül Aslan
Nurgül AslanFounder, IADM
27:46
"He should make a list of the AI tools which are used within an organization. The next thing would be: he should classify them, if they are on a high risk or not. And if they are on a high risk, what to do, how to deal with it, who is really responsible."

That is the whole list, and a small team can do it this week:

  1. List every AI tool your company uses.
  2. Classify each one by risk. For most everyday tools, the answer is not high risk – Alexa's episode explains why.
  3. Name an owner for anything that is high risk, and decide how to handle it.
  4. Get help where it gets technical. In Nur's words, the owner can bring in "someone who is deeper into tech and AI development."

Here is why the owner has to understand a little of the technology. With GDPR, I learned that the question is rarely "can I do this?" – it's "how do I build it so it's fine?"

Ben Sufiani
Ben SufianiThe Captain
29:40
"With the GDPR, I know how to build my system that gives me the same results, but way more data privacy friendly. I don't need to know which person bought something for a hundred bucks after I acquired them for ten bucks on Meta Ads, as long as I can see a person had a clear connection."

Someone who understands the system can redesign it. Someone who doesn't can only refuse it.

You Can't Download This Job

I'll admit I went looking for the shortcut. Couldn't somebody just hand me the agent?

Ben Sufiani
Ben SufianiThe Captain
24:28
"I need a Claude skill that teaches me and helps me implement it in my own company. Isn't there a skill for that?"
Nurgül Aslan
Nurgül AslanFounder, IADM
25:15
"We wish there would be something like that. But because the EU AI Act has to be applied on the organizational structure – it has to adjust certain procedures maybe within the organization."

That is the honest limit. A skill can explain the Act. It can't know which tools your team opened this morning, and it can't be the person who answers for them. What I liked about Alexa's approach is the combination:

Ben Sufiani
Ben SufianiThe Captain
26:35
"There are also some hard facts that need to be gathered and documented. And a little bit of software – hard software around a soft skill, in the sense of an agent skill – is a good combination. But you bring the human component to it."

I still asked her for the smaller thing, and I'll repeat the request here: not the whole academy in a skill, but something a founder can ask the stupid questions to, from a source you can trust – one that tells you when your case needs a trained person and when it doesn't. Her answer: "Sure, we will prepare for it."

If you want to build that kind of thing yourself, project rules are where your agent's standing instructions live, and Safety First covers the guardrails around it.

Software can hold the list. Only a person can own it.

AI, With a Rule Attached

The way Nur built her academy is a small version of her argument. It started as live Zoom sessions, and that didn't hold.

Nurgül Aslan
Nurgül AslanFounder, IADM
20:16
"At the beginning, yes, it was built only on live Zoom. … It took too much time. … Some people couldn't attend, and then they were delayed, and it was not that comfortable for our clients and for our learners. That's why we switched now to video learnings."

Some of those videos are presented by her AI avatar, made with HeyGen. Her first reaction:

Nurgül Aslan
Nurgül AslanFounder, IADM
22:34
"It was quite interesting to see that I'm speaking things that I never spoke."

But she doesn't let the avatar run the whole course. It appears at the start, again after two or three videos, and at the end.

Nurgül Aslan
Nurgül AslanFounder, IADM
23:54
"If our learners see an avatar all the time in the video, it's not always beneficial for them."

Even the person teaching AI governance uses AI with a rule attached: as much as helps the learner, and no more.

Name the Person, Then Move

The whole argument, compressed:

Your company already uses AI. The gap is not the tools – it's that nobody can say who answers for them, so the default becomes "no". Give that job to someone you already have. Make sure they understand the risk classes, keep the list of tools, and report what's new. Then work the Monday list: list, classify, own, get help.

None of that slows you down. It is what lets you say yes without waiting for a judge to say it first. And it matters beyond one company:

Ben Sufiani
Ben SufianiThe Captain
33:00
"We need people [who] can cut through the red tape, make it actionable, and let entrepreneurs do what we need to do – while keeping us in check."
Nurgül Aslan
Nurgül AslanFounder, IADM
36:06
"Please do not see AI governance, AI compliance, as something that is stopping AI innovation. This is what I want people to understand."

Nur is joining us live at Vibe Coding Cologne on 7 October. Come and ask her your own stupid questions in person. If you can't make it, sign up anyway – we send the recording that night.

Someone in your company is going to own this. Better that it's someone who knows how to say "yes, if…".

About This Conversation

Nurgül Aslan

Nurgül Aslan

Founder, IADM

Nur is the founder of IADM, the International Academy for Digitalization and Management – a CPD-accredited academy for AI management and AI governance, including its Certified AI Officer programme. She comes from HR and people development, researched AI readiness across Europe for her doctorate, and lived and worked for almost ten years in Dubai and Abu Dhabi before returning to Cologne. She also teaches at ISM in Cologne.

Ben Sufiani

Ben Sufiani

The Captain

Founder from Cologne with 15 years of startup experience across 9 ventures. Former marketing consultant and agency owner. Now vibe coding real products and building Pirate Skills to help others do the same.

Ready to Go Deeper?

Don't miss the next Captain's Insight

Join the crew and get fresh perspectives delivered weekly.

Free account. No spam. Unsubscribe anytime.

Questions & Answers

Does a small company need an AI officer?
It needs someone who holds the responsibility – not necessarily a new hire. Nur's advice for small teams is to add the responsibilities a certified AI officer carries to someone's current role, ideally someone already inside the company, "because he knows the structure." An external person is possible, but you spend so much time explaining your organisation that it stops being efficient.
What's the difference between AI governance and AI compliance?
Compliance is sticking to the legal rules – in Europe, the EU AI Act. Governance is the structured system inside your company, part of your strategy, that decides how AI is used and who answers for it. Ideally they overlap heavily. Nur's warning is that people use the two words as synonyms, which is where it starts going wrong.
What should an AI officer do first?
Nur's Monday list: **make a list** of the AI tools used in the organisation, **classify** each one by risk, and for anything high risk decide how to deal with it and **who is really responsible**. Where it gets technical, bring in someone who is deeper into tech and AI development.
How do I train my team on AI compliance?
The record can be short – the Alexa Scheffler episode showed it can be a few lines saying who was trained, when and on what. Nur adds what the training has to cover: an understanding of the **risk classes**, keeping new tools in the **AI inventory**, and **reporting** them.
Is there a Claude skill that makes my company EU AI Act compliant?
Not in the way you'd hope. Nur's answer: the Act has to be applied to your own organisational structure and procedures, so no skill can do it for you. What works is a combination – some software that gathers and documents the hard facts, agent knowledge in the background, and a person who owns the result.