Rutendo Nyeve in Victoria Falls
THE Information Systems Audit and Control Association (ISACA) Harare Chapter successfully convened its 2025 Annual Conference this week, here in Victoria Falls, with amplified calls for the urgent need for organisations to establish proper governance and management over their Artificial Intelligence (AI) initiatives to harness innovation responsibly.
Held under the theme: “Securing the Future: Zero Trust and Privacy in a Borderless Digital Era”, the conference drew a turnout of digital trust professionals.
The conference featured a lineup of local and international experts.
It was officially opened by Chapter President Mr Godwill Chihwayi, who highlighted the chapter’s significant growth to 530 members, underscoring the growing importance of the fields of IT governance, risk, and security in Zimbabwe’s digital landscape.
One of the globally recognised governance experts, Mr Mark Thomas, spoke on the opportunities and perils of AI.
Mr Thomas distilled the complex issue into a clear framework for action.
He said the cornerstone of responsible AI adoption lies in a distinct separation of roles between governance and management.
“Governance evaluates stakeholder needs, conditions and options. It determines balanced, agreed-on enterprise objectives and sets direction through prioritisation and decision-making. It is the responsibility of the board of directors,” he said.
He contrasted this with the role of management, which plans, builds, runs and monitors activities aligned with the direction set by the governance body to achieve enterprise objectives.
To illustrate, Mr Thomas provided a concrete example.
“The board approves an AI Ethics Policy that prohibits the use of black-box AI models in high-risk decisions (e.g., hiring or credit scoring) unless explainability and human oversight are built in.
Meanwhile, the IT and data science teams implement a model explainability toolkit, ensuring they comply with the board’s AI Ethics Policy,” he said.
Mr Thomas bolstered by real-world case studies, including cautionary tales of AI tools at Amazon being scrapped due to bias and data leaks at Samsung, alongside success stories from companies like UPS and Pfizer.
He warned that without a structured approach using established frameworks like COBIT, NIST’s AI Risk Management Framework, and the new EU AI Act, organisations risked ethical, financial, and reputational damage.
The conference served as a critical rallying point for Zimbabwe’s IT leaders, equipping them with the knowledge to navigate the rapidly evolving AI landscape.



