Insights
Practical guidance on governing and adopting AI
Written for boards, managing directors and the people who have to make AI work in organisations without a data team or a compliance department. Anchored in Mauritian law, ISO/IEC 42001 and the realities of a small economy.
- An AI governance framework for a 20 to 200 person organisation How a 20 to 200 person organisation with no compliance function can govern AI with named owners, a system register, a three-tier risk classification and a review cadence that stands up to later audit.
- The Data Protection Act 2017 and AI: the six sections that apply to your systems Mauritius has no AI statute, but the Data Protection Act 2017 already governs most AI use on personal data. Here are the six provisions that apply, and what they mean in practice.
- What a board should ask before approving an AI investment A board does not need to understand machine learning to govern an AI investment well. It needs to ask the right twelve questions and insist on evidence.
- ISO/IEC 42001 for small and non-technical organisations: what it involves, who certifies, and when it is worth it A decision guide to ISO/IEC 42001 for small and non-technical organisations in Mauritius: what an AI management system is, alignment versus certification, cost and timeline drivers, and when certification pays.
- The FSC guidance on responsible AI: an implementation checklist for licensees The FSC's nine principles for responsible AI are non-binding, but a licensee that cannot show how it has considered them will struggle to explain itself. Here is how to build the evidence.
- AI impact assessment or DPIA: which one your organisation needs, and how to run it A DPIA is required by law before high-risk processing in Mauritius; an AI system impact assessment is what ISO/IEC 42001 expects. This guide explains the difference, the triggers, and a one-week method that can satisfy both.
- An AI acceptable use policy for Mauritian employers: template and worked example The formal, adoptable version of the staff AI policy: eight clauses, a complete template with bracketed fields, and a worked example for a 30-person firm.
- What data does a non-technical organisation need before it starts with AI? Most organisations have more usable data than they think and less than the vendor assumes. This guide shows a director how to find out which, in days rather than months.
- AI vendor due diligence for small-market buyers: the questions to ask before signing A managing director's checklist for assessing an AI vendor without a procurement function: ten questions, the legal angle, six contract clauses and a scoring table.
- Your staff are already using generative AI. A 30-day plan for managers Unsanctioned AI use is normal, not a scandal. This four-week plan turns it into something a manager can see, shape and hand to a named owner.
Further reading by the founder, on strategy and readiness, is published at faaleh.com.