AI Governance Questions for African Leaders

Sharp AI governance questions for boards, CEOs, marketing, IT, HR and founders in Africa, with what a good answer should sound like.

AI governance in Africa · Frameworks · Laws and policy by country · Questions to ask · Glossary · Ideas and quotes · Free AI governance tools · Work with Stanislaus

Boards and directors

You do not need to understand the maths. You do need to know who is accountable when the model gets it wrong.

  1. Which named executive is accountable for AI risk in this organisation, and when did they last report to us? Listen for: One name, a reporting date in the last quarter, and a standing agenda slot rather than an ad hoc update.
  2. Do we have a complete register of the AI systems we build, buy and use, including the ones embedded in vendor software? Listen for: A yes with a number, an owner for each entry, and an admission of how the register catches tools staff adopt without asking.
  3. Which of our AI uses make or shape decisions about customers, staff or citizens? Listen for: A short, specific list such as credit, hiring or fraud flags, each with the human checkpoint described.
  4. Where are we exposed to the EU AI Act or to data protection law in the markets we serve? Listen for: A market by market answer that names the laws, not a general assurance that legal has looked at it.
  5. What is our risk appetite for AI, and which uses are we not willing to pursue at all? Listen for: A written statement with at least one clear no, approved by the board rather than inferred by management.
  6. What happened the last time an AI system produced a wrong or harmful result here? Listen for: A real example with what was learned and changed; 'it has never happened' usually means nobody is looking.
  7. How do we test a model before it goes live and keep testing it afterwards? Listen for: Pre-launch testing against agreed thresholds plus ongoing monitoring for drift, with someone empowered to switch it off.
  8. Which AI vendors are we most dependent on, and what is our exit plan if one fails us? Listen for: Named vendors, the contract terms that protect our data, and a realistic fallback that has been thought through.
  9. How are the directors on this board building their own AI literacy? Listen for: Scheduled briefings or training with a record, not a promise to read about it.

Chief executives

AI governance is how you move fast without betting the licence. These questions tell you whether you can.

  1. Which three AI uses will create the most value for us this year, and what could each one break? Listen for: Value and risk discussed in the same breath, with a named owner for each use case.
  2. Can a team launch an AI tool that touches customers without anyone outside that team knowing? Listen for: A no, backed by a simple intake step that takes days, not months.
  3. What data are we feeding into AI tools, and do we have a lawful basis for each use? Listen for: A clear map of data types to purposes, signed off by the data protection officer.
  4. How long does it take to get an AI idea approved here? Listen for: A defined path with time limits, so governance is seen as an enabler rather than a queue.
  5. If a journalist asked tomorrow how we use AI on customers, what would we say? Listen for: A short, honest statement you would be comfortable reading on the front page.
  6. Who can switch off a misbehaving AI system, and how quickly? Listen for: A named role, a tested procedure and a time measured in hours.
  7. Are we training our people to use AI well, or just hoping they do? Listen for: Role-based training with completion tracked, starting with the people who make decisions using AI output.
  8. What is our position on generative AI in content, advice and customer service? Listen for: Written rules on disclosure, review and accuracy, especially where output reaches customers.
  9. What are we spending on AI, and how do we know it is paying back? Listen for: Costs and outcomes measured per use case, with a willingness to stop pilots that do not deliver.

Marketing and customer teams

Marketing is usually the first team to use AI at scale and the last to be asked about it. Fix that.

  1. Which AI tools are we using to create content, target audiences or talk to customers today? Listen for: A full list, including features switched on inside ad platforms and CRM tools by default.
  2. Do we tell people when they are talking to a chatbot or seeing AI-generated content? Listen for: A clear disclosure rule applied consistently, not left to each campaign.
  3. Who checks AI-written copy for accuracy, claims and brand tone before it goes out? Listen for: A named reviewer and a checklist, with stricter review for regulated claims in finance or health.
  4. Are we uploading customer lists or personal data into AI tools, and on what lawful basis? Listen for: A documented basis, a vendor agreement that stops the data being used to train other models, and the DPO's sign-off.
  5. How do we stop a personalisation or targeting model excluding groups unfairly? Listen for: Regular checks on who sees offers and prices, with the results reviewed by someone outside the campaign team.
  6. Do we have the rights to the images, voices and likenesses our AI tools produce or imitate? Listen for: A rule against imitating real people without written permission and a check of each tool's licence terms.
  7. What happens when our chatbot gives a customer wrong information? Listen for: A route to a human, a log of conversations, and a process to correct the bot and the customer.
  8. Are agencies and freelancers using AI on our work, and under what rules? Listen for: Contract clauses on disclosure, data handling and ownership that apply to every supplier.

Data, IT and security

Most AI failures are ordinary engineering failures with a new name. Ask the ordinary questions.

  1. How do we discover AI tools in use that IT never approved? Listen for: Network and expense monitoring, a simple request route, and an amnesty rather than a witch hunt.
  2. Where does data go when staff use a public AI tool, and is it retained or used for training? Listen for: Specific answers per tool from the vendor's terms, and enterprise settings that switch training off.
  3. How are we defending against prompt injection in tools that read emails, documents or web pages? Listen for: Limited permissions for AI agents, separation of untrusted content, and testing with malicious inputs.
  4. Do we red team our AI systems before launch, and who does it? Listen for: Structured adversarial testing by people who did not build the system, with findings fixed before release.
  5. How do we monitor a live model for drift, errors and misuse? Listen for: Defined metrics, alert thresholds, logs kept for an agreed period, and a named owner who reviews them.
  6. What is our process when an AI system causes an incident? Listen for: AI incidents folded into the existing incident process, with extra steps for model rollback and regulator notification.
  7. Can we explain how a given output was produced, and reproduce it? Listen for: Versioned models, prompts and data, with enough logging to reconstruct a decision after a complaint.
  8. Where are our models hosted, and does that create a cross-border data transfer? Listen for: A clear map of hosting locations and the transfer mechanism relied on under each applicable data protection law.
  9. What security review does an AI vendor go through before we connect it to our systems? Listen for: The normal third-party security review plus AI-specific questions on training data, retention and model updates.
  10. Do we apply least privilege to AI agents the way we do to people? Listen for: Agents with their own scoped credentials, approval steps for high-impact actions, and full audit logs.

HR and people teams

AI in hiring, performance and pay decisions touches people's livelihoods. It needs the highest care you have.

  1. Are we using AI anywhere in recruitment, screening, performance or promotion decisions? Listen for: A complete list including features inside applicant tracking and HR software, not only standalone tools.
  2. Is any of those decisions made solely by automated processing? Listen for: No, or a clear legal basis and safeguards, because data protection laws in Nigeria, Kenya and South Africa restrict this.
  3. How have we tested our hiring tools for bias against women, older candidates, or people from particular regions or schools? Listen for: Test results broken down by group, a plan for what happens if gaps appear, and a repeat schedule.
  4. Do candidates and employees know when AI is involved in decisions about them? Listen for: Plain-language notices at the point of use, and a way to ask for a human review.
  5. What is our policy on staff using generative AI in their daily work? Listen for: A short acceptable use policy that says what is encouraged, what is banned and where to ask.
  6. Are we monitoring employees with AI, and is that proportionate and lawful? Listen for: A documented assessment of necessity and proportionality, consultation where required, and limits on what is collected.
  7. Which roles are changing because of AI, and what is our plan for the people in them? Listen for: A real plan for reskilling and redeployment, communicated before the change rather than after.
  8. How are we building AI literacy across the workforce? Listen for: Training that differs by role, from awareness for everyone to deeper skills for heavy users and managers.

Founders and startups

Governance is not a tax on growth. Done early and light, it is what gets you through a bank's or investor's due diligence.

  1. Can we describe in one page what our AI does, what data it uses and where it can go wrong? Listen for: A plain one-pager you could hand to a customer, an investor or a regulator today.
  2. Will any of our customers or users be in the EU, and does our product fall into a regulated category? Listen for: A considered answer on EU AI Act scope, because the Act can reach providers outside the EU.
  3. Do we have a lawful basis for the personal data we used to train or fine-tune our models? Listen for: A record of data sources, the basis relied on, and a plan for honouring deletion requests.
  4. What would an enterprise customer's procurement team ask us about AI, and can we answer it now? Listen for: Ready answers on security, data use, testing and human oversight, ideally in a standard pack.
  5. Which foundation model providers do we depend on, and what happens if their terms or prices change? Listen for: Awareness of the dependency, a contract reviewed for data rights, and some ability to switch.
  6. How do we test for harmful or wrong outputs before each release? Listen for: A repeatable test set covering accuracy, bias and abuse cases, run on every significant change.
  7. Who in the founding team owns AI risk? Listen for: A named person with time set aside, even if it is a part of their role.
  8. Do our marketing claims about the AI match what it actually does? Listen for: Claims checked against test evidence, with no promises of accuracy or autonomy the product cannot keep.
  9. Would ISO/IEC 42001 or a lighter framework help us win deals in our market? Listen for: A judgement based on what customers actually ask for, rather than certification for its own sake.

Questions with no easy answer

  • Which AI systems are we already accountable for that this board has never discussed? Directors carry responsibility for AI in use today, including AI inside bought software.
  • If our chatbot gave a customer wrong information about fees tomorrow, who would find out first: us, the customer or social media? Monitoring and complaint routes decide whether an error stays small.
  • Would we be comfortable if every AI-generated ad we ran this year was published with a label saying so? Discomfort with disclosure is an early sign of a trust problem.
  • Who in this organisation can switch off an AI system that is causing harm, and do they know it? Without a clear stop authority, harm continues while people seek permission.
  • Are we using customer data to train or personalise AI for purposes customers never agreed to? Purpose limitation and lawful basis apply to AI as much as to any processing.
  • Which of our decisions about people are now made solely by a system, with no meaningful human review? Data protection laws in Nigeria, Kenya and South Africa set specific rules for solely automated decisions.
  • Do our human reviewers have the time and authority to overrule the AI, or do they simply approve it? Rubber-stamp review gives the appearance of oversight without the substance.
  • What would we lose if we paused our riskiest AI use case for a month to assess it properly? If the answer is little, the pause is cheap insurance.
  • Do our AI vendors use our data to train their models, and have we actually checked? Vendor terms often decide where confidential and personal data ends up.
  • Does our AI serve customers who speak Hausa, Swahili or isiZulu as well as it serves those who speak English? Uneven performance across languages is unequal treatment, whether intended or not.
  • Is AI governance slowing good ideas down, and if so, is the problem the rules or their design? Governance that only delays will be bypassed, which is worse than none.
  • What is the one AI use we will not pursue, whatever the commercial upside? Red lines agreed in advance are easier to hold under pressure.
  • If a regulator asked for our AI inventory today, how long would it take to produce? The answer is an honest measure of governance maturity.
  • Should we disclose to customers when an AI, not a person, made or shaped a decision about them? Transparency builds trust and is increasingly expected in law and by customers.
  • Are we comfortable that our targeting never reaches children or people in financial distress with offers that could harm them? Vulnerable audiences are where marketing AI can do the most damage.
  • Who owns AI risk here: technology, legal, compliance or the business unit using it? Shared ownership often means no ownership.
  • What have we changed because of an AI risk assessment in the last year? If nothing changed, the assessments may be paperwork rather than control.
  • Is our ambition to comply with AI rules, or to be a company customers trust with AI? Compliance is a floor; trust is a competitive position.
  • What happens to our AI governance when the person championing it leaves? Governance that depends on one person is not yet embedded.
  • Are we building AI capability in Africa, or only renting it from elsewhere? Where skills and data value sit shapes long-term competitiveness and bargaining power.

How this page was made. Parts of these pages were drafted and researched with the help of AI tools, then reviewed and checked against the sources linked beside each claim. AI can get things wrong and laws change, so treat this as general information, not legal advice: the linked sources are the authority, and you should take qualified advice before relying on anything here. Spotted an error? Tell me and I will fix it. Last checked 7 October 2026. See the terms.

By Stanislaus Martins. Stanislaus Martins is Managing Director, Sub-Saharan Africa at Aleph, the digital advertising group, with teams in Lagos, Nairobi, Johannesburg and Cape Town. He has spent over two decades in marketing, digital business and technology across Sub-Saharan Africa, including roles as Head of Digital Business at Insight Publicis, VP of Growth Marketing and Advertising at Jumia Nigeria, and Agency Partner for Sub-Saharan Africa at Meta. He holds an MBA, is a Fellow of the Chartered Institute of Marketing (UK) and of NIMN, and is Immediate Past President of ADMARP. He has completed the AI Governance online course from Saïd Business School, University of Oxford, and Google Cloud's Gen AI: Beyond the Chatbot course, and is preparing for the IAPP AIGP certification. He runs the AI in Nigeria 2026 survey. He helps organisations put AI to work with clear ownership, sensible risk controls and evidence they can show customers, regulators and boards.