Aiskilljourney
Menu

Overview / Governance

In this issue

Governance literacy for organisations that must account for how AI is used.

Aiskilljourney trains large organisations to treat generative AI as a controlled workplace practice. Participants learn where policy applies, which uses require review, and how to record decisions so that oversight functions can inspect them. The work sits inside enablement, not beside it, because ungoverned tool use is difficult to unwind once it becomes habit.

Corporate programmes differ from open courses because they are bound to licensed tools, internal classification rules and the language already used by risk, legal and information-security teams. We do not invent a parallel vocabulary. Facilitators work from the client’s approved materials and from the control statements the organisation is prepared to defend.

The audience is typically a mix of operational teams, people managers, compliance officers and digital leads in departments of 50 to 5,000 people. Sessions are sized so that discussion of exceptions remains specific. Sponsors receive a written map of topics, assessment criteria and residual questions at the close of each cohort.

Request a briefing View programmes

Why it is taught

Policy that staff cannot apply will not survive first contact with a deadline.

Most organisations already hold statements on acceptable use, data handling and third-party tools. The gap we address is operational: people who must produce work still need a clear method for deciding what may be drafted with a model, what must be checked, and what must not leave the organisation’s environment.

Governance literacy is therefore taught as a workplace skill. Participants practise classifying tasks, identifying personal and confidential data, and choosing an approved tool or a manual method. They rehearse how to escalate when a request sits outside published guidance. The aim is consistent behaviour across teams that share the same systems.

Oversight functions need more than attendance lists. They need evidence that staff can explain the rule they followed and the record they kept. Assessment in our programmes is written against those outcomes. Scores and qualitative notes are returned to the sponsor in a form that can be filed with internal training records.

We work in Singapore and across APAC with organisations whose boards already expect periodic reporting on technology risk. The programmes do not replace the client’s policy owners. They give those owners a structured way to socialise decisions that have already been taken, and to surface ambiguities that still need a written answer.

Where a client has not yet published a complete AI policy, we still teach from a conservative baseline: licensed tools only, no confidential input without an approved pattern, human review of external output, and a named owner for each recurring use. That baseline is adjusted once the organisation issues its own text.

Oversight is credible when a manager can show, for a given team, which uses are permitted, who reviewed them, and what was recorded. Literacy is the skill that makes those three facts available without a special project.
Working session around a table
Working session on policy application.
What is covered

A practical map of duties, records and exceptions.

Each engagement opens with a reading of the client’s current policies, acceptable-use rules and tool inventory. Facilitators then translate those documents into decision points that staff actually meet: drafting, summarising, searching, coding assistance, customer correspondence and internal analysis.

Participants leave with a short reference they can keep at the desk. It names the approved tools, the data classes that must not be entered, the review steps for outward-facing text, and the route for asking for an exception. The reference is the client’s document, formatted for use. We do not substitute our own policy.

Managers receive a companion note on how to observe the practice in their teams: what to sample, how often, and how to record a finding without creating a parallel audit. That note is aligned with the measurement approach described on our Evidence page.

Where sector rules apply, for example in banking, healthcare administration or public bodies, the map is annotated with the client’s existing control language. Sector context is set out on Sectors.

Curriculum strands

Topics treated as skills, with assessed application.

Approved tools

Staff learn which licensed systems may be used for which classes of work, how accounts are provisioned, and what happens when a personal account appears in a workplace task. The session uses the client’s inventory, including any enterprise assistants already in place.

Data classes

Participants practise recognising personal data, client confidential material, unpublished financials and privileged legal content. They apply the organisation’s handling rules before a prompt is written. Ambiguous cases are escalated using the published route.

Human review

Output that will be sent outside the team, or that will inform a decision affecting customers or staff, is treated as draft until a named reviewer accepts it. The programme specifies what “review” means in that organisation’s words.

Records

Teams agree a light record of recurring uses: purpose, tool, data class, reviewer and date. The record is designed to be inspectable by internal audit without requiring a new system. Formats follow what the client already stores.

Exceptions

Not every request fits the published rule. Participants learn how to pause, how to write a short exception request, and who is authorised to grant one. Unanswered questions are logged for the policy owner rather than resolved in the room by improvisation.

Vendor change

When a model, a feature or a contractual term changes, staff need a method for pausing use until the owner confirms the new boundary. The programme includes a short drill on reading a vendor notice against the organisation’s control statements.

Inside the engagement

How oversight is practised during delivery.

Governance is not a single lecture at the start of a course. It is repeated at each stage so that participants apply the same tests to new tasks. The sequence below is the default for a multi-week cohort. Shorter formats keep the same order with reduced practice time. Delivery mechanics are described on Delivery.

  1. Discovery reading

    We collect current policies, tool lists and any prior incident notes the sponsor is willing to share. The reading produces a topic map and a list of questions that only the policy owner can answer. Those questions are returned before the first teaching session.

  2. Sponsor alignment

    A short working meeting confirms which rules are in force, which are in draft, and which examples may be used in the room. Sensitive illustrations are replaced with anonymised cases. Attendance and assessment rules are confirmed in writing.

  3. Taught application

    Classroom and workshop time is spent on classification exercises, prompt hygiene against data rules, and review of sample outputs. Participants work in groups that resemble their actual reporting lines where the sponsor permits it.

  4. Assessed task

    Each participant completes a written task against a scenario drawn from their function. Marking looks for correct tool choice, correct data handling, a stated review step and a usable record. Results are reported to the sponsor, not published.

  5. Close and residual list

    The cohort closes with a residual-question list for the policy owner and a recommendation on sampling for the following quarter. Materials remain with the client. Aiskilljourney retains only what the contract allows for quality review.

Boundaries

What this work does and does not claim.

Aiskilljourney delivers training and enablement. We help staff understand and apply the organisation’s rules. We do not draft statutes, issue legal opinions, certify models, or act as an outsourced risk function. Where a sponsor needs counsel on a regulatory filing, that work belongs with the organisation’s appointed advisers.

We also do not claim that attendance removes residual risk. Generative tools change, vendors alter terms, and new use cases appear between cohorts. Literacy reduces the rate of unmanaged use. It does not replace monitoring, access control or contractual review of suppliers.

Course examples are educational. They are chosen to illustrate a decision, not to prescribe a sector-wide standard. If an organisation’s internal rule is stricter than a public guideline, the internal rule is the one taught in the room.

Read the terms of use

Audiences

The same policy, taught at the depth each role requires.

Staff working at screens
Applied practice against approved tools.

Role-based programmes, listed on Programmes, share a common governance core and then add depth. Individual contributors practise task classification and record-keeping. People managers practise sampling and feedback. Specialists in compliance, risk and information security practise writing control language that non-specialists can follow, and reviewing exception logs.

Executive briefings, described on Briefings, stay at the level of accountability: what the organisation has authorised, what evidence will be available after a cohort, and which questions remain for the policy owner. Briefings are scheduled with sponsors before a large rollout so that teaching language and board language do not diverge.

Cohorts can be mixed or homogeneous. Mixed rooms are useful when a process crosses functions, for example customer operations and legal review. Homogeneous rooms are useful when the data classes are highly specific. The sponsor chooses the mix during scoping. We advise on group size so that exception discussions remain concrete.

Facilitators are briefed on the client’s confidentiality rules and work under the engagement contract. They do not retain identifiable examples from one organisation for use with another. Materials prepared for a cohort are labelled as client property according to the statement of work.

Next step

Bring the current policy pack. We will map it to a teachable sequence.

A first conversation is a working review of documents you already hold: acceptable use, data classification, tool licences and any board or committee paper on AI. From that reading we propose a programme outline, cohort size, assessment method and a calendar that respects your internal governance cycle.

Enquiries are answered within one business day, Monday to Friday, 09:00–18:00 SGT. Write to hello@AISkillJourney.eu or use the form on Contact. Telephone +65 6337 2914.

Open an enquiry Read the FAQ

Our office
5 Temasek Boulevard, Suntec Tower Five, Singapore.