AI concerns: ROI, scaling and governance – part 1

The launch of the ITIL AI Governance (Version 5) certification in July 2026 gave professionals and organizations practical guidance for governing AI as a business capability - helping them manage risk, scale adoption responsibly and connect AI investment to business value.

As businesses and public sector organizations worldwide are tackling the issue of AI adoption, what is the current experience of professionals on the front line?

PeopleCert canvassed the ITIL community to get an up-to-date picture and, in the first of a two-part series, we learn how practitioners are handling the opportunities and risks of AI and deploying the guidance from ITIL AI Governance.

Considering the level of hype around the promise of AI, what is the technology actually achieving in organizations today?

Recent research by consultancy, EY, in conjunction with Oxford Economics, suggests that hype is not an unfair description of the current corporate experience of AI:

“GenAI and agentic AI continue to attract heavy investment, yet many organizations are discovering that the returns are slower, smaller or more uneven than expected,” the authors comment, describing an “AI ROI trap” in which “experimentation accelerates faster than execution, governance and measurement can support”.

One problem the EY research highlights in achieving return on investment is conducting “pilots with immature and inconsistent governance that limit scaling beyond proof-of-concept.”

Without “a clear enterprise vision for AI”, the research adds, “deployment choices default toward speed, cost and risk containment”. This leads to “measurement and governance gaps that prevent enterprise ROI”.

AI ROI and organizational value

When asked whether their team or organization was seeing ROI from AI adoption, more than one-third (38%) of respondents from the ITIL community answered with a definite “Yes”, while a similar amount (35%) stated that ROI was “partly” delivered. Almost one-fifth (16%) had seen no ROI, while 11% didn’t know.

Where ROI was achieved, this has translated to value as follows:

Speed and Time: respondents using phrases like "faster," "speed," "time saving," and "accelerate" to describe benefits.

Efficiency: "efficiency" mentioned repeatedly as an operational benefit.

Productivity: describing improvements at both individual and organizational levels.

Consistency: particularly in documentation and cross-disciplinary work.

Quality: Improving the "quality" of outputs and deliverables.

These experiences suggest that AI can deliver tangible operational value, but realizing value in individual use cases is only part of the challenge. The harder question for organizations is how to scale those benefits while maintaining appropriate governance, oversight and control.

Ulises Gonzalez, a consultant at Rizo.ma (Prozess Group S.A.), noted AI benefits including throughput on document-heavy technical reviews, specifically cross-disciplinary consistency checking on engineering documentation; a turnaround from days to hours in work involving meeting minutes, progress reports, proposals and workshop material and greater analytical depth on unstructured customer data.

Reducing time to market and increasing productivity was experienced by Emilio Ramirez, Process Manager IT Operations Master: “I have recently made a configuration information analysis for a critical service for one of our customers in two days using AI tools. [Without] using AI tools this kind of analysis would have taken me at least two weeks! Also, I have enormously increased my productivity in ITSM practices documentation with greater consistency and reduced redundancy,” he said.

Enhanced innovation and operational efficiency – but a need for greater governance

System Operation Manager at Hitachi Rail, Mina Ezzat Aziz Mehani, described how AI adoption is “creating measurable business impact by enabling smarter and more agile operations”. He explained: “It supports strategic decision-making through data-driven insights, accelerates execution across functions, and helps teams deliver higher-quality outcomes with greater consistency.” The organization is also benefiting from enhanced innovation capabilities, improved resource utilization, and stronger competitiveness in a rapidly evolving business environment.

At Flexera, Premnadh Karekatt, AI Product Manager ITAM, has seen AI automating repetitive and time-consuming tasks, significantly reducing manual effort while improving accuracy, consistency, and operational efficiency:

“Instead of spending valuable time on routine activities, teams can focus on higher-value strategic initiatives, decision-making, and innovation. AI accelerates processing, minimizes human error, provides intelligent recommendations, and enables faster, data-driven outcomes; ultimately making day-to-day work simpler, more productive, and more impactful across the organization,” he added.

However, for some ITIL community respondents, adopting AI and recognizing its value is more tentative:

Service Management Specialist, Bryan Edwards, noted that a lack of ROI is not affecting the desire to use AI, but has created a “very cautious approach” to handling data and implementation of items into production. “Ensuring adoption of the preferred governance structure is currently more important than going full-bore into adopting AI for semi-autonomous automation,” he said.

“I think that the biggest enemy is how to govern AI and its risks,” Francesco Di Faustino, Service Desk Lead & System Administrator, said.

The challenge of scaling AI

A wide variety of issues, according to ITIL Community experts who shared their experiences with us, are affecting the ability of organizations to scale AI.

The most common difficulties fall into four areas:

Governance, security, and compliance: establishing a framework for responsible AI and the need for continually evolving governance.

Operational integration: a frequent struggle to fit AI into existing business models, legacy systems and ensuring processes are "AI-ready”.

Skills and cultural adoption: varying skill levels, a lack of AI awareness and cultural resistance or fear of job loss can hinder AI scaling.

Verification and measurable value: if an organization cannot verify AI output without redoing the work, the cost savings are effectively zero. Equally challenging is to justify investments, demonstrate clear business value and ensure the accuracy and quality of AI-generated outputs.

The problem of moving from a single use of AI to wider enterprise application is a recurring theme:

Project manager, Aleksandar Dimitrov, highlighted the need to “create adaptable, scalable solutions that can be easily adopted across multiple teams and business units, rather than building for a single, isolated use case”, while consultant Marcelo Correa noted the importance of “AI implementation scaling from use by a single individual to a full team - and eventually to an organizational level.”

But scaling brings issues of change management and data security, according to Bishwas Ghimire, Cloud Consultant/Technical Project Coordinator at Emperictech: “It is one thing to have a few tech-savvy people using AI, but training the broader team to use it safely, while ensuring our proprietary data stays secure, is a complex process that takes time to get right.”

And looking beyond developer productivity towards “business outcomes with AI” is a key point for Debashis Bhattacharyya, a Head of Tech Advisory Consulting: “Scaling AI is less about deploying more models and more about creating an AI-native engineering operating model where people, processes, platforms and governance evolve together.”

AI governance in practice

With AI governance pinpointed as a major issue equally by EY’s research and the front-line experience of the ITIL community, what are organizations’ current approaches – and how effective are they?

Ulises Gonzalez explains how every AI-supported workflow is defined by a specification document and a manifest for scope, inputs and output is checked against the specification by a distinct process before it reaches a client. However, despite some success, he admits the measures are not “uniformly successful”.

He adds that mandatory human adjudication on client-facing, AI-generated deliverables is partially effective though this is improved through verification points and a rotation of reviewers. From a contractual transparency perspective, clients are told where AI is used in delivery which ‘converts a latent reputational risk into an explicit, negotiated term”.

AI adoption within Hitachi Rail, according to Mina Ezzat Aziz Mehani, is governed through clear policies, security and data protection controls, compliance oversight, risk assessments, and defined approval processes for AI use cases. Regular user awareness initiatives and performance monitoring help ensure responsible, secure and value-driven use of AI across the organization.

He added: “Governance measures have been largely effective in mitigating AI adoption risks by providing clear controls around security, data privacy, compliance, and responsible use. They have enabled the organization to explore AI opportunities while maintaining operational reliability and ensuring appropriate human oversight for critical business and operational decisions.”

Transitioning from basic "acceptable use" rules to a more structured framework, is how Bishwas Ghimire of Emperictech describes their approach: “We now require all AI tools to go through a formal IT and security vetting process and we are actively mapping our AI usage against established service management practices to ensure we maintain control as we scale.”

The result has been significant and “vital” to the organization: “Having a framework in place gives leadership the confidence to approve new AI initiatives because they know we have guardrails against data leaks or compliance breaches. It shifted our culture from being afraid of "Shadow AI" to embracing AI responsibly,” he said.

Investing heavily in AI literacy in the company, has – Debashis Bhattacharyya said – ensured engineers “understand when to trust AI, when to verify its outputs and when human judgement must prevail.”

“The human-in-the-loop is an important cog in our wheel today and has helped us trust AI, but with caution,” he added.

Across these examples, effective AI governance is emerging not as a single policy or control, but as an ongoing organizational capability combining clear accountability, risk management, human oversight, security, skills and continual monitoring.

Deploying ITIL AI Governance concepts

With the myriad challenges, risks and opportunities faced by enterprises and their employees when managing and governing AI, what advice can they turn to?

Creating new guidance to support practitioners and their organizations with AI governance has been integral to PeopleCert’s publishing and certification development activity since 2025.

When asked whether they had adopted guidance from the new ITIL AI Governance certification, more than 50% of ITIL community members had already done so. In addition, more than 80% had consulted the ITIL AI Governance white paper, released in 2025.

A key principle of the ITIL approach is that AI governance should not sit apart from the way an organization already manages its products, services and risks. Instead, AI governance can be integrated into existing management practices and governance structures, treating AI as an organizational capability rather than simply a technology to control.

Overall, key elements of the guidance that practitioners found useful included:

The ITIL AI Governance Capability Model: adopting the "6C" approach (Creation, Curation, Clarification, Cognition, Communication, and Coordination) to evaluate AI capabilities and risks.

Stress-testing existing frameworks: rather than building a parallel AI governance structure.

Integration with existing processes: Integrating AI risk management directly into established ITIL processes.

Strategic alignment: guidance to ensure that AI implementation drives tangible business goals

Cultural and operational shifts: moving governance from static "control" to ongoing "stewardship".

Business perspective: treating AI as a business and operational capability rather than just a technology tool.

Risk and compliance: implementing robust governance that addresses cost optimization, security, privacy, and regulatory compliance while auditing for "Shadow AI".

Ulises Gonzalez noted how the stress-testing approach in the guidance had “corrected a bias we had toward building AI governance as a parallel structure” and the ITIL AI Governance Capability Model was the “most operationally useful part” to break the “habit of governing AI as one, undifferentiated thing”.

Another view on the “most valuable advice” in the guidance came from Mina Ezzat Aziz Mehani, who said: “Treating AI as a business and operational capability rather than just a technology tool – plus guidance on AI governance, data protection, human oversight, risk assessment, and compliance – has helped ensure that AI is adopted responsibly while maintaining operational reliability and service quality.”

Declaring his “love” for the ITIL AI Governance Capability Model and the risk matrix, Alex Harding – Head of IT Services at Runshaw College – said, simply: “It’s all very practical”.

And Jo Jennett, Service Operations Manager at South Norfolk and Broadlands Councils, summed up one of the core concepts behind the new guidance and certification: “It [has] provided a great, concise overview of the challenges and opportunities written for business stakeholders, opposed to the more technical teams.

“This provided a catalyst for the organization to focus on defining our own tailored governance and to help respond to users' questions and concerns.”

Build practical AI governance capabilities with ITIL

Learn how ITIL AI Governance can help you assess AI capabilities and risks, integrate governance into existing ways of working and scale AI responsibly while maintaining human oversight and alignment with business objectives.

Explore ITIL AI Governance.

Watch for part 2 of our AI concerns series: ROI, scaling, and governance, when we hear more from the ITIL community about their current issues with, and approaches to handling, the AI governance challenge.