# Governance & risk.

> Questions to settle before AI touches real data: KVKK and GDPR, where data goes, usage policies, shadow AI, audit trails, vendor checks and red-teaming.

Governance works when it is specific: who can see what, where data is processed, who approves and what gets logged. These notes offer practical questions and templates; legal questions are framed for your counsel and data protection officer, never answered as legal advice.

- [KVKK, GDPR and AI: questions to ask your DPO before you build](https://veridive.com/insights/kvkk-gdpr-ai-questions/): In Türkiye and Europe, data protection is often the first objection to an AI project. It becomes answerable once the data flow is mapped. These are the questions to settle with your DPO or counsel before anyone builds.
- [Shadow AI: what to do when employees already use their own tools](https://veridive.com/insights/shadow-ai-at-work/): Banning AI tools pushes their use into personal accounts you can’t see. Find out what people use and why, offer an approved tool that is genuinely good, set clear data rules and turn the best unofficial uses into projects.
- [Where does your data go when you use a language model?](https://veridive.com/insights/llm-data-privacy/): Data travels further than people think: prompts, retrieved passages, outputs, logs, caches, search indexes and test sets. Map each hop, check the contract and settings for each, and design so the most sensitive data never makes the trip.
- [An AI acceptable use policy people will actually read](https://veridive.com/insights/ai-acceptable-use-policy-template/): A policy that fits on two pages and answers real questions, which tools, which data, who checks and what to disclose, gets followed. A long list of prohibitions gets ignored and pushes use into personal accounts.
- [What an AI audit trail should record, and who should read it](https://veridive.com/insights/ai-audit-trail/): When a decision is questioned months later, you need to rebuild what the system saw, which sources it used, which model and prompt answered, and who approved it. Log that by design, and treat the logs as sensitive data.
- [Questions to ask an AI vendor before you sign](https://veridive.com/insights/ai-vendor-due-diligence-questions/): Standard security questionnaires miss what matters for AI products: which models sit underneath and who can change them, whether your data trains anything, how quality is measured on your cases, and what you can take with you when you leave.
- [The EU AI Act: questions to ask if you build or buy AI for Europe](https://veridive.com/insights/eu-ai-act-questions/): The EU AI Act sorts AI uses by risk and gives duties to providers and deployers. Settle the basics with counsel first: which role you play, which category each use falls into, and what transparency and oversight you already have.
- [Red-teaming an AI system: a practical test plan before launch](https://veridive.com/insights/ai-red-teaming/): Red-teaming means structured attempts to make the system misbehave: leak data, skip an approval, give off-policy answers or run up costs. Do it with people who know the business, log every finding, and turn each one into a test.
