How ISO/IEC 42001, the NIST AI RMF, the EU AI Act and OECD principles apply in Africa, and a practical framework you can start using this month.
A five-rung maturity ladder that tells an African organisation where its AI governance really stands, from AI it cannot see to AI it can prove is under control. Each rung has a plain test, so you climb on evidence rather than on the strength of a policy document.
Why it matters: Most African organisations are not starting from zero or from a compliance department of fifty. They are starting from staff quietly using AI tools, a data protection law they are still bedding in, and a board that wants an answer. A ladder lets a Lagos bank, a Nairobi fintech and a public agency each find an honest starting point and take the next step that fits their size, instead of copying a multinational's programme.
AI is in use but nobody holds a full picture. Staff use free chatbots, vendors switch on AI features, marketing runs AI-generated creative. There is no owner and no record.
What good looks like: Honesty. The organisation admits it is on this rung and names someone to lead the climb.
An AI inventory exists. Every known use case is listed with its purpose, the data it uses, the people it affects and the vendor behind it.
What good looks like: A living register, reviewed at least quarterly, that a manager outside IT can read and understand.
Every use case has a named business owner. A short AI policy sets acceptable use, approval routes and red lines. Accountability sits with an executive, not with a tool.
What good looks like: Named owners in the register, an approved policy, and staff who can describe the rules without looking them up.
Use cases are triaged by risk. Higher-risk ones get an impact assessment, linked to the data protection impact assessment where personal data is involved, plus testing, human oversight and monitoring after launch.
What good looks like: Completed assessments for higher-risk systems, test results on file, monitoring in place, and at least one documented change made because of governance.
Governance is checked by someone independent of the teams running AI, reported to the board on a schedule, and improved after incidents. The organisation can show its work to customers, partners and regulators.
What good looks like: Independent review findings, regular board reporting, an incident log with follow-up actions, and the option to pursue external certification such as ISO/IEC 42001 if the market asks for it.
How it maps to recognised frameworks: The rungs follow the NIST AI RMF Govern function first (ownership, policy, culture) and then Map, Measure and Manage as use cases are assessed and monitored. Rungs 3 to 5 broadly track what an ISO/IEC 42001 AI management system expects: leadership commitment, risk and impact assessment, operational controls, performance evaluation and continual improvement. This ladder is an aid to progress, not a substitute for either. Sources: [1] [2] [3] [4] [5] [6] [7] [8] [9] [10]
A 30-60-90 day plan to stand up working AI governance in a mid-sized company without a large compliance team. You find what exists, frame the rules and the triage, then prove it works on real use cases before you scale it.
Why it matters: Mid-sized African firms are adopting AI fast, often through vendors, and rarely have a dedicated AI risk function. A time-boxed plan gets a credible baseline in place within a quarter, gives the board something concrete, and avoids the two common failures: doing nothing, or writing a long policy nobody follows.
The CEO or board names an accountable executive, agrees the scope and sets the 90-day goal. A small working group is formed: business, technology, data protection, legal or compliance, and someone from marketing or customer service.
What good looks like: A one-page mandate signed off by the CEO, with names and dates.
Build the AI inventory through short interviews with each department and a review of vendor contracts and software settings. Issue interim acceptable-use guidance for public AI tools straight away.
What good looks like: A first inventory, interim staff guidance issued, and a shortlist of the five to ten use cases that matter most.
Write a short AI policy, adopt a simple risk triage, connect it to existing data protection impact assessments, and add AI clauses to procurement templates. Agree who approves what.
What good looks like: An approved policy of a few pages, a triage form in use, and updated procurement terms.
Run the triage and, where needed, a full assessment on the shortlisted use cases. Train staff on the policy. Report to the board on what was found, what changed and what comes next.
What good looks like: Completed triage and assessments for priority use cases, training records, and a board paper with a risk view and a next-quarter plan.
Move from project to routine. Review the inventory quarterly, monitor live systems, log incidents and revisit the policy at least annually or when the law changes.
What good looks like: A recurring calendar of reviews, an incident log, and AI as a standing item in risk reporting.
How it maps to recognised frameworks: The plan builds the basics of the NIST AI RMF (Govern first, then Map and Measure on priority use cases, then Manage) and the opening clauses of an ISO/IEC 42001 management system: scope, leadership, policy, risk and impact assessment. In Nigeria it connects to the data protection impact assessment duty in section 28 of the Nigeria Data Protection Act 2023, and the staff training step is in the spirit of Article 4 of the EU AI Act, which asks firms within its scope to take measures to support the AI literacy of their staff. Sources: [1] [2] [3] [4] [5] [6] [7] [8] [9] [10] [11] [12] [13] [14] [15] [16]
Five questions any manager can answer in fifteen minutes to sort an AI use case into green, amber or red, without needing a lawyer in the room. It decides how much scrutiny a use case gets, so scarce legal and risk time goes where it matters.
Why it matters: Many African organisations, especially growing firms and public agencies, do not have in-house counsel for every AI decision. Without a triage, everything waits for the one overstretched lawyer or nothing gets checked at all. PAUSE lets the business do the first sort honestly and escalate only what needs expert eyes.
Who feels the output? Internal staff drafting a memo is low. Customers, job applicants, borrowers, patients, students or citizens raise the level.
What good looks like: A clear statement of who is affected and how, written in the triage form.
How much does a human check before the output takes effect? A draft reviewed by a person is lower risk than a decision applied automatically.
What good looks like: A named human checkpoint, with authority to override, for anything consequential.
Does the system process personal data, and is any of it sensitive, such as health or biometric data, or high risk, such as financial or children's data?
What good looks like: A lawful basis recorded, vendor data terms checked, and a data protection impact assessment where the processing is likely to be high risk.
How many people, how often, and how easily can a mistake be undone? An error in one email is fixable. An error in ten thousand credit decisions is not.
What good looks like: An estimate of volume and a written rollback or remediation plan.
Is the use public-facing, in a regulated sector, cross-border, or likely to attract media and regulator attention?
What good looks like: Result: mostly low answers go green (owner approves, register entry); any high answer on People or Autonomy with personal data goes red (full assessment, senior and specialist sign-off); everything else goes amber (structured review by the risk or data protection lead).
How it maps to recognised frameworks: PAUSE is a front door to the NIST AI RMF Map function and to the impact assessment expected under ISO/IEC 42001. Its questions echo the factors behind the EU AI Act's high-risk categories, such as employment and creditworthiness in Annex III, and the rules on decisions based solely on automated processing in section 37 of Nigeria's Data Protection Act 2023, section 35 of Kenya's Data Protection Act 2019 and section 71 of South Africa's POPIA. It does not decide legal classification; red cases still need specialist advice. Sources: [1] [2] [3] [4] [5] [6] [7] [8] [9] [10] [11] [12] [13] [14] [15] [16] [17] [18] [19] [20] [21] [22] [23]
Five tests for any AI that speaks to, targets or persuades customers: ads, content, chatbots and personalisation. Consent, Labelling, Evidence, Audience and Recourse keep marketing fast while keeping trust intact.
Why it matters: Marketing is where most African consumers will first meet an organisation's AI, through a chatbot on WhatsApp, a personalised offer or an AI-generated ad. It moves fast, uses a lot of personal data and is highly visible. A single misleading synthetic ad or a chatbot that will not hand over to a human can cost more trust than a year of campaigns can earn back.
Personalisation, profiling and direct marketing need a lawful basis and a working way for people to object or opt out. Check what the data was collected for before you reuse it to train or target.
What good looks like: Documented lawful basis per use, a tested opt-out that stops processing for marketing, and audience data with a clear source.
Tell people when they are talking to a machine, and mark synthetic images, voices or video of real-looking people. Disclosure should be plain and early, not buried in terms.
What good looks like: A disclosure line in every bot, a labelling rule for synthetic media, and a sign-off step for any ad using a real person's likeness or voice.
AI writes confidently and is sometimes wrong. Every factual or product claim in AI-assisted content must be checked by a person who can substantiate it.
What good looks like: A human fact-check on published claims, chatbot answers grounded in approved content, and logs to review what the bot told people.
Check who is being targeted or excluded. Take extra care with children, vulnerable customers and offers on credit, health or gambling, and watch for targeting that quietly shuts groups out of opportunities.
What good looks like: Audience rules written down, sensitive categories excluded or reviewed, and spot checks of outcomes across groups and languages.
Every customer-facing AI needs an easy route to a human, a way to complain, and a way to fix what went wrong.
What good looks like: A visible human handover, complaint handling that covers AI interactions, and a record of fixes made.
How it maps to recognised frameworks: CLEAR applies the NIST AI RMF to marketing use cases and fits the controls ISO/IEC 42001 expects on information for interested parties and use of AI systems. Labelling lines up with the transparency duties for chatbots and synthetic content in Article 50 of the EU AI Act. Consent and objection line up with Nigeria's Data Protection Act 2023, including the right to object to processing for direct marketing in section 36, and with equivalent rights under Kenya's Data Protection Act and South Africa's POPIA. Sources: [1] [2] [3] [4] [5] [6] [7] [8] [9] [10] [11] [12] [13] [14] [15] [16] [17] [18] [19] [20]
How this page was made. Parts of these pages were drafted and researched with the help of AI tools, then reviewed and checked against the sources linked beside each claim. AI can get things wrong and laws change, so treat this as general information, not legal advice: the linked sources are the authority, and you should take qualified advice before relying on anything here. Spotted an error? Tell me and I will fix it. Last checked 7 October 2026. See the terms.
By Stanislaus Martins. Stanislaus Martins is Managing Director, Sub-Saharan Africa at Aleph, the digital advertising group, with teams in Lagos, Nairobi, Johannesburg and Cape Town. He has spent over two decades in marketing, digital business and technology across Sub-Saharan Africa, including roles as Head of Digital Business at Insight Publicis, VP of Growth Marketing and Advertising at Jumia Nigeria, and Agency Partner for Sub-Saharan Africa at Meta. He holds an MBA, is a Fellow of the Chartered Institute of Marketing (UK) and of NIMN, and is Immediate Past President of ADMARP. He has completed the AI Governance online course from Saïd Business School, University of Oxford, and Google Cloud's Gen AI: Beyond the Chatbot course, and is preparing for the IAPP AIGP certification. He runs the AI in Nigeria 2026 survey. He helps organisations put AI to work with clear ownership, sensible risk controls and evidence they can show customers, regulators and boards.