Free AI Workshops
AIHA Academy — 8 free live AI workshops for hospitalityFrom AI basics to building your own agents and appsLive online · One hour each · Recordings included
Register free

Simplified AI governance framework

The essential framework path: what it is, the minimum records to establish, the five governance pillars and the questions to ask every AI vendor.

Framework at a glance

Start with the complete governance map

AI GOVERNANCE FRAMEWORK
PILLAR 1AI SYSTEMS, RISK & ACCOUNTABILITYWho governs AI, what we have, and who can decide?
  • 1.1 Know What You Have
  • 1.2 Assess & Classify Risk
  • 1.3 Risk Reclassification Review Triggers
  • 1.4 Assign Accountability & Decision Rights
PILLAR 2PEOPLE, GUESTS & WORKFORCEAre we fair, transparent and accountable to people?
  • 2.1 Transparency
  • 2.2 Fairness
  • 2.3 Human Oversight
  • 2.4 Contestability & Redress
  • 2.5 Workforce & Acceptable Use
PILLAR 3DATA, SECURITY & ASSURANCECan we trust it, protect it and prove it?
  • 3.1 Data Stewardship
  • 3.2 Security
  • 3.3 Testing & Assurance
  • 3.4 Evidence & Auditability
PILLAR 4VENDORS, TECH STACK, PROCUREMENT & AI LIFECYCLEAre we in control through the entire lifecycle?
  • 4.1 Procurement & Vendor Governance
  • 4.2 Deployment & Operational Control
  • 4.3 Monitoring and Operational Oversight
  • 4.4 Incident & Response
  • 4.5 Change Management
  • 4.6 Continuity, Retirement & Exit
PILLAR 5AI AGENTS & HOSPITALITY ECOSYSTEMCan AI that acts on our behalf do so safely, with authority and responsibly?
  • 5.1 Agent Identity
  • 5.2 Delegated Authority
  • 5.3 Agent Permissions & Boundaries
  • 5.4 Internal Agent Oversight
  • 5.5 Inbound AI Agents
  • 5.6 AI-to-AI / Ecosystem Interaction
  • 5.7 Data Collection & Disclosure via Agents
Interactive framework diagram · Open an entry point or pillar to read its summary on this page. Capability labels are shown for reference. Use the button below for the full-size diagram.
View full-size diagram →

Start with the five entry points and pillar summaries on this page, then apply the framework proportionately to your organisation’s size, risk and context. Within each pillar, capabilities define what the organisation needs to be able to do and the outcomes effective governance should achieve.

Before the pillars

Overview

01

Purpose & vision

Hospitality organisations are rapidly embedding AI within their operations, but adoption is moving faster than the industry’s ability to govern it consistently. The framework provides a common, practical reference for organisations developing their own AI governance frameworks.

Read the full section →
02

Definitions

AI governance is the system of roles, decision rights, processes, controls and evidence through which an organisation determines which AI systems may act in its name, for what purpose and under whose authority.

Read the full section →
03

Governance principles & functions

Governance functions describe what governance does. Governance principles are what good governance must stand for while doing it.

Read the full section →
04

AI governance literacy

AI governance literacy is the knowledge and understanding people need to recognise, question, use, oversee and escalate AI appropriately. It is not about teaching people how AI models work technically.

Read the full section →

The operating baseline

Minimum viable governance

Organisational size does not remove the need for basic AI governance. Regardless of size, structure or maturity, every hospitality operator should establish a small set of foundational governance records that provide visibility, accountability and control over its use of AI. At minimum, the organisation should have:

  1. AI Register — a current record of the AI systems in use, including embedded AI, their purpose, risk level and accountable owner.
  2. AI Use & Risk Assessment - a documented assessment of what each material AI system is used for, its approved purpose, boundaries, key risks and required level of governance.
  3. AI Governance & Acceptable Use Policy - clear organisational rules covering approved AI use, data handling, verification, human review, prohibited uses and employee responsibilities.
  4. AI Vendor Due Diligence Record - a record of the key questions asked of vendors and the answers received before adopting material third-party AI.
  5. AI Approval & Decision Record - evidence of who approved the use of material AI, under what conditions, and with what delegated decision rights or controls.
  6. AI Incident & Change Record - a simple record of material incidents, concerns, changes, reviews and resulting actions.
  7. AI Review & Assurance Record - evidence that material AI systems are periodically reviewed and that required controls, human oversight and risk assessments remain appropriate.
  8. Human Review & Redress Route - documented route through which an affected guest or employee can reach an appropriately authorised human to question, review or correct an AI-influenced outcome.

These are the foundational records, not a complete governance system. They provide the minimum foundation from which more sophisticated governance can develop as the organisation's use of AI, risk and maturity increase. What differs between a single property and a global group is the depth, formality and sophistication of these arrangements, not the need for them.

Eight foundational records, plus an agent-specific supplement. The Implementation Workbook provides these eight records and a supplementary Agent Controls worksheet for organisations using AI agents under Pillar 5. Agent Controls is not a ninth foundational record.

The heart of the framework

The five governance pillars

Within each pillar, capabilities define what the organisation needs to be able to do and the outcome effective governance should achieve.

Pillar 1

01 AI systems, risk & accountability

An organisation cannot govern AI effectively without knowing what AI systems it has, understanding the risks associated with their use, keeping those risks under review, and assigning clear accountability and decision rights. This pillar establishes the foundations for identifying, assessing and overseeing AI systems and ensuring that appropriate authority and accountability are assigned throughout their lifecycle.

Read the complete pillar →
Core governance areas
  • 1.1 KNOW WHAT YOU HAVE
  • 1.2 ASSESS & CLASSIFY RISK
  • 1.3 RISK RECLASSIFICATION REVIEW TRIGGERS
  • 1.4 ASSIGN ACCOUNTABILITY & DECISION RIGHTS
  • 1.5 GROUP, BRAND, FRANCHISE AND PROPERTY REALITY

Risk tiers

Risk is a property of the use, not the tool. Classify each AI use case against evidence and record the rationale.

TIER

USE PROFILE

MINIMUM GOVERNANCE

HOSPITALITY EXAMPLES

0 - Assistive

Internal drafting or analysis; approved data; no external action; meaningful human review; low consequence.

Register; named owner; acceptable-use and data controls; incident reporting.

• Marketing staff using ChatGPT to draft social media post ideas before review

• A manager using AI to summarise internal meeting notes

• Housekeeping using AI to draft an internal shift-handover summary

1 - Controlled

Low-to-moderate consequence; bounded guest/staff assistance; reversible outcomes; reliable supervision.

Documented assessment; testing; monitoring; role-based oversight; vendor review; escalation.

• A guest-service chatbot answering routine questions like check-in times or spa hours

• AI drafting first-pass responses to guest reviews, reviewed before posting

2 - Material impact

Material guest/employee, financial, access, eligibility, pricing or service impact; or significant personal data.

Formal approval by the designated accountable authority; cross-functional challenge; stronger testing/logging; human intervention; transparency/contestability; periodic review.

• AI-generated dynamic pricing recommendations feeding into room rates

• AI-assisted interview scheduling in HR

• AI staff rostering and scheduling

• AI influencing loyalty status changes or guest eligibility decisions

3 - High consequence

High potential consequence, significant autonomy, difficult-to-reverse outcomes, significant safety, security, privacy, biometric or highly sensitive data or other material impact.

Default: do not deploy until necessity, appropriate legal/ethical review, robust controls, executive approval, continuous monitoring, suspension capability and independent assurance are demonstrated, with effective suspension capability.

• Facial recognition used for guest or staff identification and access

• Emotional recognition (visual and voice)

• An autonomous agent authorised to issue refunds or compensation without human sign-off

• AI-driven access control tied to safety and security systems across a portfolio

• An AI tool screening and ranking job candidates

Accountability and decision rights

A hotel can buy or outsource its AI technology, but it remains accountable for how that AI is used and for its impact on guests, employees and the business.

ACCOUNTABLE PERSON / ROLE

DEFINITION

ACCOUNTABLE FOR

Executive sponsor

Senior person with authority to support, approve or reject significant AI decisions.

Risk appetite, resources and approval of Tier 3 AI uses.

AI system owner

Person accountable for the AI system throughout its organisational lifecycle.

Approved purpose, risk, performance, lifecycle and overall accountability for the AI system.

Business / process owner

Person accountable for the business process in which the AI is used.

Workflow fit, guest/employee impact, adoption and fallback arrangements.

Technical owner

Person responsible for the technical implementation and operation of the AI system.

Architecture, identity, integration, testing, security and technical change control.

Data steward

Person responsible for the appropriate management of data used by the AI system.

Data source, purpose, quality, access, retention and correction.

Security / privacy / legal

Specialist functions providing review and advice within their respective areas.

Specialist review, assurance and advice within their remit; does not replace system ownership.

Vendor / procurement owner

Person responsible for managing the organisation’s relationship with the AI vendor or provider.

Vendor due diligence, contractual controls, service levels, change notification and exit arrangements.

Property accountable manager

Person with operational authority for the property’s use of AI.

Local operating conditions, staff readiness, escalation and authority to suspend use where necessary.

Pillar 2

02 People, guests & workforce

AI can affect people directly or indirectly, including through decisions, communications, recommendations and workplace processes. Organisations should ensure that AI is used transparently, fairly and responsibly where it affects guests, employees or other individuals, with appropriate human oversight and meaningful opportunities to question, correct or challenge AI-influenced outcomes.

Read the complete pillar →
Core governance areas
  • 2.1 TRANSPARENCY
  • 2.2 FAIRNESS
  • 2.3 HUMAN OVERSIGHT
  • 2.4 CONTESTABILITY & REDRESS
  • 2.5 WORKFORCE & ACCEPTABLE USE
Pillar 3

03 Data, security & assurance

AI systems depend on data and connected technologies, creating governance responsibilities for how data is used, how systems are protected, how performance and controls are tested, and how governance can be demonstrated. This pillar establishes the safeguards needed to ensure that AI operates securely, uses data appropriately, remains within its approved boundaries, and can be appropriately challenged, interrupted or corrected, with important governance decisions, actions and outcomes evidenced in a manner proportionate to risk.

Read the complete pillar →
Core governance areas
  • 3.1 DATA STEWARDSHIP
  • 3.2 SECURITY
  • 3.3 TESTING & ASSURANCE
  • 3.4 EVIDENCE & AUDITABILITY
Pillar 4

04 Vendors, tech stack, procurement & AI lifecycle

Hospitality organisations increasingly rely on vendors and technology providers to deliver AI capabilities embedded within the systems used to operate their businesses. AI may therefore enter a hotel through procurement, existing software, vendor updates, integrations or third-party services, without the organisation directly developing or controlling the underlying AI. This creates governance dependencies and risks relating to vendor transparency, data use, security, system performance, contractual accountability, changes to AI functionality and the organisation's ability to intervene when something goes wrong.

Organisations should therefore govern AI throughout its lifecycle, including how AI is procured and provided by third parties, how it is deployed and operated within approved boundaries, how changes and incidents are managed, and how systems can be suspended, replaced or retired. Reliance on a vendor does not transfer the organisation's accountability for how AI is used or for its impact on guests, employees and the business.

Read the complete pillar →
Core governance areas
  • 4.1 PROCUREMENT & VENDOR GOVERNANCE
  • 4.2 DEPLOYMENT & OPERATIONAL CONTROL
  • 4.3 MONITORING & OPERATIONAL OVERSIGHT
  • 4.4 INCIDENT & RESPONSE
  • 4.5 CHANGE MANAGEMENT
  • 4.6 CONTINUITY, RETIREMENT & EXIT
Pillar 5

05 AI agents & hospitality ecosystem

AI agents can increasingly act in roles that were previously performed by people, including searching, evaluating options, making or recommending decisions, communicating, negotiating, booking, purchasing and taking other actions on behalf of an individual or organisation. This changes the nature of AI governance because an AI system may no longer simply produce an output for a person to consider; it may exercise delegated authority and act within a business or transactional environment.

Hospitality organisations therefore need to govern both AI agents acting on their behalf and AI agents acting on behalf of guests, partners, vendors or other external parties. An organisation's own agents may interact directly with people, systems, vendors and other AI agents, while external agents may interact with the organisation's booking, pricing, service or other operational systems as a substitute for human decision-making.

Organisations should establish clear governance over agent identity, delegated authority, permissions, boundaries, actions and accountability, including how authority is granted, limited, monitored and withdrawn. Where agents interact with other agents or automated systems, the organisation should ensure that identity and authority remain attributable and that an agent cannot acquire greater authority merely through delegation or interaction with another agent. AI-to-AI interaction should therefore remain within defined governance boundaries, with appropriate mechanisms to detect unexpected behaviour, escalate decisions, require human intervention where necessary, and interrupt or stop agent activity that exceeds its authorised role.

The fundamental governance question is not simply what an AI agent can do, but what it has been authorised to do, on whose behalf, within what boundaries, and with what consequences if it acts incorrectly.

Source: Singapore IMDA Model AI Governance Framework for Agentic AI — reference 9 →

Read the complete pillar →
Core governance areas
  • 5.1 AGENT IDENTITY
  • 5.2 DELEGATED AUTHORITY
  • 5.3 AGENT PERMISSIONS AND BOUNDARIES
  • 5.4 INTERNAL AGENT OVERSIGHT
  • 5.5 INBOUND AI AGENTS
  • 5.6 AI-TO-AI / ECOSYSTEM INTERACTION
  • 5.7 DATA COLLECTION AND DISCLOSURE THROUGH AGENTS
  • PILLAR 5 IN PRACTICE (INFORMATIVE)

Before procurement or renewal

Vendor due diligence questionnaire

Informative companion to the vendor governance areas in Pillar 4. A property-usable question set; record the answers as part of the AI Vendor Due Diligence Record.

ASK THE VENDOR

WHAT TO ESTABLISH

What AI or models power this system, and how are they updated?

Model and provider chain, material changes and how changes are communicated.

What data do you collect and what is it used for?

Data categories, purpose, inputs, outputs, telemetry and secondary uses.

Do you use our data to train or improve your models?

Whether organisational data trains or improves models, and whether it is isolated from other customers.

Are your recommendations informed by other customers’ data?

Whether pricing or other recommendations draw on non-public data from other customers, including competitors, and how it is segregated.

Where is our data stored and processed, and does it cross borders?

Locations, jurisdictions, subprocessors and transfer safeguards.

How long do you retain our data, and can it be deleted?

Retention for inputs, outputs, logs and backups; deletion process and evidence.

Who can access our data?

Vendor personnel, subprocessors, support arrangements and access controls.

What can the AI do without human approval?

Action boundaries, permissions, human review, override and suspension capability.

How will we know if something changes or goes wrong?

Material-change and incident notification, relevant records and escalation.

What happens when the relationship ends?

Data return or deletion, records, continuity and exit assistance.