Putting Trust First: 5 Best Practices for Governing Workplace AI

As AI takes on a greater role in HR, trust can’t be an afterthought. Workday and the Future of Privacy Forum developed a new framework to help policymakers and employers govern AI responsibly.

image alt text here

Half a decade ago, Workday made a deliberate choice: to step up as a thought leader in responsible AI. We have always firmly believed you can’t build a sustainable, innovative enterprise without a foundation of absolute, unyielding trust. Today, we’re taking the next step in fulfilling that promise. Workday is pleased to partner with the Future of Privacy Forum (FPF) and other HR leaders on the recently updated “Best Practices for AI and Workplace Assessment Technologies Framework,” a practical blueprint for governing AI in the workplace.

The timing couldn’t be more critical. As AI moves beyond making predictions and suggestions to taking action, organizations need practical ways to govern those systems—especially the ones influencing important decisions about people. Governments around the world are grappling with enterprise AI governance, and the stakes are high. Fragmented rules slow innovation and can even set trust back. At the same time, overly broad rules can miss the operational differences that determine where risk actually sits. 

Workday engages with lawmakers and regulators globally to share real-world insights from enterprise AI development and deployment. That dialogue is critical. Durable AI policy has to work not just on paper, but also inside the systems organizations use every day. Drawing on Workday’s decade of experience delivering AI innovation to customers, current public policy standards, and real-world examples, the new framework clarifies who is responsible at each stage of building, deploying, and using AI. It builds on established benchmarks, including the NIST AI Risk Management Framework (“NIST AI RMF”) and ISO/IEC 42001, to help organizations put responsible AI governance into practice.

The framework also builds on the initial industry roadmap for managing enterprise AI Workday developed with FPF and other HR technology providers. That roadmap was an important first step, but as AI capabilities and regulations evolve at breakneck speed, organizations need guidance for what comes next.

Durable AI policy has to work not just on paper, but also inside the systems organizations use every day.

Responsible AI Is a Shared Responsibility

The 2.0 framework begins from the recognition that AI governance does not sit with one actor alone. Responsibility changes depending on who builds, deploys, configures, or uses the technology. 

A developer and deployer each play different roles. Treating them as the same can create confusion and unintended gaps in governance. Tailoring responsibilities to the role in the AI value chain makes governance more workable, and gives policymakers a clear mechanism to target accountability where operational control lives.

Operationalizing Responsible AI: 5 Best Practices 

When the original guidance was published, the workplace AI conversation centered on predictive systems that handled single, well-defined tasks like parsing resumes. Thanks to advances in generative and agentic AI, today’s tools can draft communications, schedule interviews, and execute complex, multi-step workflows with limited human intervention. This creates incredible opportunities for efficiency, higher-value human work, and workforce development. But it also introduces new challenges that yesterday's policies weren't built to handle. 

The 2.0 framework offers five best practices to help AI developers and deployers address potential risks and ensure technological progress doesn’t outpace safe, accountable governance.

1. Institute AI Governance Practices Across The AI Lifecycle

Responsible AI governance requires organizations to govern, map, measure, and manage risk across the entire system lifecycle, in line with the NIST AI RMF. Organizations need to build governance structures that assess predictive, generative, and agentic capabilities individually, and the risks that may emerge when they come together. They also must consider how people will use those technologies in the real world. 

At Workday, this holistic approach helps us evaluate AI capabilities as they evolve from predictive recommendations to generative insights and agentic actions. Our Chief Responsible AI Officer Kelly Trindel calls our approach “sociotechnical.” 

“This means we look at the full picture: not just the tech under the hood, but how real people use it in real workplaces,” Trindel said.

“We look at the full picture: not just the tech under the hood, but how real people use it in real workplaces.”

Kelly Trindel Chief Responsible AI Officer Workday

2. Test for Unintended Bias and Comply with Non-Discrimination Laws

Organizations must comply with a range of federal, state, and global anti-discrimination laws. Both developers and deployers need to review information that’s available to them from the provider of the AI model and/or system. They should implement an appropriate governance framework, and where appropriate, proactively test to eliminate bias and maintain fairness.  

3. Provide Meaningful and Accurate Information

Transparency disclosures responsibilities should be divided according to role. Developers are responsible for documenting a system’s characteristics, limitations, and intended uses. Deployers should give affected individuals clear, timely notice before an evaluation begins. This approach ensures that whoever is best positioned to provide the information communicates it, giving people a clear understanding of the technology and how it may affect them.

As a developer, for example, Workday equips enterprise customers with AI fact sheets that provide clear documentation on model inputs, design limits, and intended use cases. This helps customers understand how to configure the feature and empowers them to communicate accurately with their workforce. Transparent resources like these reflect a conviction I've held from the start as Workday's VP, chief privacy and digital trust officer: smart policy, privacy, and digital trust must be foundational to our entire strategy.

Transparent resources reflect a conviction I've held from the start as Workday's VP, chief privacy and digital trust officer: smart policy, privacy, and digital trust must be foundational to our entire strategy.

4. Implement Safeguards to Protect Personal Data and Maintain The Integrity of AI Reasoning and Agency

Privacy and security practices must address emerging AI threats, including prompt injection, data leakage, and unauthorized model inversion. As AI agents interact more broadly with enterprise systems, organizations need strict identity controls, permissions, and segmented access. For example, Workday provides robust tools for securely managing agents, including Agent System of Record and Agent Passport, which require agents to operate within tenant boundaries and worker permission levels.

5. Calibrate Human Oversight and Bind Agentic Authority

Human oversight isn't binary. Organizations should define clear intervention levels based on risk, so teams know precisely when AI tasks need explicit human approval and when AI can act independently within safe boundaries. They should also implement meaningful oversight mechanisms, including training and clear assignment of responsibility and decision rights. 

Trust Is The Path to Durable Innovation

The next phase of workplace AI won’t be defined only by what systems can do. It will be defined by whether organizations can show how those systems are governed.

That’s why the 2.0 framework delivers real value, offering policymakers and enterprises a practical way to align innovation with accountability—from shared responsibility across the value chain to agentic AI use cases that reflect real-world context.

At Workday, trust has always been foundational to how we build. As AI becomes more powerful and more embedded into the flow of work, that foundation becomes even more important. We are pleased to amplify foundational best practices with the goal of continuing the vital work of developing comprehensive and workable enterprise AI safeguards alongside our industry peers, civil society, and policymakers.

Read the updated “Best Practices for AI and Workplace Assessment Technologies Framework.”

More Reading