e&
2024 - 2026
Building Responsible AI Governance at e&
No AI use case at e& reached deployment without earning the right to. I collaborated on the governance framework it had to pass through, the UX and adoption of the risk process and platform behind it, then designed the training that got 80% of a 9,000+ person workforce to actually finish it, not just start it.

Overview
How do you make AI deployment accountable?
An AI transformation doesn't hold up without governance behind it. AI deployed without clear accountability, explainable decisions, and defined risk ownership isn't progress, it's exposure to bias, regulatory penalties, and reputational damage. Responsible AI means building systems that stay ethical, transparent, and accountable throughout, so AI supports human judgement rather than replacing it unchecked.
9 components putting it together
One of the first steps my team took was to build that structure from the ground up: a framework, a governance process every use case had to pass, and the awareness to make responsible AI mean something beyond a policy statement. What follows are the nine artifacts I worked on with my team to deploy AI governance:
01
Responsible AI Framework
What it was: Working with a consultancy, we built the Responsible AI framework document: business context, principles, process, governance and assurance structure, committee roles, a RACI matrix, and the risk taxonomy behind it all.
Why it mattered: Governance assigns decision rights and accountability across an organisation's AI activity, not a document on a shelf. Every artifact that follows exists because this one came first, built before a single use case existed rather than retrofitted after something went wrong.

The final framework document was hosted on SharePoint and circulated to relevant teams
My role
I worked with the consultancy on the framework document, connecting the process to how teams actually worked day to day, and brought together the stakeholders needed to reach alignment and final sign-off from senior leadership.
02
AI Use Cases Repository
What it was: Once the roadmap was defined, I built a single repository mapping every AI use case in it, giving senior leaders visibility into what had been agreed and what was being added.
Why it mattered: A roadmap means little if nobody can see what's running against it. This became the single source of truth, and the foundation the risk process and governance committee both depended on for accountability.
My role
I built this entirely on my own, designing the UI and UX and coding the whole site in Framer myself, then kept it updated as each use case was mapped against the roadmap.
03
AI Risk Principles
What it was: The principles we defined became the basis for every AI initiative that followed, and the risk principles specifically ran through the use case assessment process from the start.
Why it mattered: Principles like fairness, transparency, and accountability only mean something if they're built into the process, not stated once and left in a document. Turning values into something a team can actually follow is one of the harder parts of responsible AI, most organisations write them down and stop there. Every assessment afterwards pointed back to the same principles, keeping the standard consistent.

The 8 risk principles published on eand.com
My role
This came out of the framework work with the consultancy. My role was making sure the principles didn't stay a standalone statement, connecting them through into the assessment process and every artifact that followed.
04
AI Risk Assessment Form
What it was: Before any AI use case could move into deployment, it had to go through a risk assessment questionnaire, the form that determined where it sat within the risk taxonomy and what came next.
Why it mattered: This is where governance stopped being a document and became a gate. Explainable, defensible decisions matter most right here, when a use case is about to go live and someone eventually has to justify why it was approved, adjusted, or stopped. A black-box outcome is impossible to defend to an auditor, a regulator, or a board.
My role
Developed with the consultancy as part of the framework. My role was mapping how the form actually needed to work, designing it in Figma for the teams filling it out, and connecting it into the wider risk process working with the Tech team to build into SharePoint.
05
AI Governance Committee
What it was: Any use case flagged as high risk moved to the AI Governance and Steering Committee, leaders from compliance, data security, risk, and cybersecurity, who decided whether it could be adjusted to lower its risk or needed to be stopped entirely.
Why it mattered: A high-risk use case needs more than one person's judgement behind the decision to proceed. Putting it in front of leaders across compliance, security, and risk, rather than leaving it with whoever built it, is what turns governance from policy into an actual check.

Members of the committee blurred for confidentiality
My role
Defined with the consultancy as part of the framework build. My role was mapping how a use case actually reached the group, and making sure the right teams understood their part in it. I also set up any required sessions as high-risk use cases were flagged, and facilitated the discussions to ensure an outcome and next steps were cascaded to the relevant teams.
06
IBM watsonx as the Governance Platform
What it was: e& and IBM signed an agreement in 2024 at Davos, making e& one of the first companies in the region to implement IBM watsonx as a governance tool, moving the risk process from manual to automated.
Why it mattered: Manual governance doesn't scale. As use cases grew, a spreadsheet-and-form process was never going to hold. watsonx gave the organisation lifecycle governance and automated risk tracking across every model in production, continuous monitoring rather than a one-off check at launch.

Screenshot of a change management session taking stakeholders through the new process
My role
I worked with the tech team and IBM on watsonx's user experience as it was integrated into our ecosystem, and ran change management workshops across every team that would touch it: use case owners, risk owners, cybersecurity, governance, audit, PMO, and scrum and domain owner training, gathering feedback after each session. That's what got the tool adopted rather than just installed.
07
Responsible AI Awareness Campaign
What it was: With employees still getting to grips with AI generally, the challenge was making them aware of what responsible AI meant for their own work. We built the campaign around real employees working through hypothetical scenarios, ethical grey areas they might actually hit, rather than abstract policy language. It reached an 80% completion rate across a company of over 2,000 employees.
Why it mattered: Understanding responsible AI isn't instinctive. People learn it by seeing how it plays out in situations that look like their own, not from a list of principles. Someone can know how to use a tool well and still not recognise the ethical line they're about to cross, that's the gap this campaign closed.

The launch email featuring real employees, explaining why this matters and linking to the course
My role
I designed the entire campaign including the creative concept, photography and design, working with a learning agency in the UK to build the course flow, ran user testing before launch, and created the follow-up campaign to get employees to complete it.
08
e& 2024 Annual Report
What it was: We published our responsible AI commitments in the annual report, working with the partnerships and branding teams, and put the same material on the website.
Why it mattered: Governance that only exists internally doesn't build trust with anyone outside the organisation, investors, regulators, or customers included. Putting it in the annual report and on the website made the commitment visible and on record.

2024 report pages featuring Responsible AI as one of the pillars of sustainability
My role
I worked with the partnerships and branding teams on the content and published it to the website with the digital team.
09
CXO and Board Communication
What it was: Regular communication with the board and CXOs kept them aware of the framework and secured the approvals each new artifact needed as it was built.
Why it mattered: None of this holds without the people approving it actually understanding what they're agreeing to. That can't stop at the board. Each CXO owns the AI risk inside their own function, and needs to be able to explain how a decision in their area was made, not defer to whoever built the framework whenever a question comes up.

Slide presented to leaders to showcase how e& was positioned in benchmarks according to the GSMA Responsible AI Maturity Framework (graph blurred for confidentiality)
My role
I built the key slides used to raise board and CXO awareness of the framework and created the materials needed for each approval as it came up.