AI Governance & Compliance

AI Governance and Compliance

Most organizations are already using AI in more places than their leadership can name. We help you inventory those uses, record intended purpose and accountable owners, assess vendor and model risks, and put human oversight and monitoring where the consequences justify it.

We give you a defensible governance record and an honest view of obligations. We do not certify AI systems and we do not issue blanket compliance verdicts.

When this helps

Situations we are usually called into

  • Teams adopted AI assistants and features and nobody has a list of what is in use or with which data.
  • A customer or insurer has started asking how you govern AI.
  • You are launching an AI-supported feature and need oversight and evaluation before it touches customers.
  • Staff are pasting sensitive information into consumer AI tools with no policy or guardrail.
  • Leadership wants to know which AI obligations genuinely apply in the places you operate.

Scope & deliverables

What the engagement covers

AI inventory and intended use

Establish what exists before governing it.

  • Inventory of AI systems, features, assistants and embedded vendor capabilities
  • Documented intended use and out-of-scope use per system
  • Accountable owner and approver recorded for each entry
  • Data categories and populations affected

Vendor, model and data risk

Understand what you are relying on and what your suppliers commit to.

  • Vendor and model due diligence, including training-data and retention terms
  • Data handling review covering inputs, outputs, logs and retention
  • Risk assessment proportionate to consequence, not hype
  • Guardrail and access recommendations for staff use of AI tools

Human oversight and evaluation

Make sure a person is accountable where outcomes matter.

  • Oversight design: review points, escalation and override paths
  • Evaluation approach with test sets and acceptance thresholds
  • Documented limitations and known failure modes
  • Disclosure and user-facing wording review

Policy, impact assessments and monitoring

The written and ongoing parts that keep governance real.

  • AI use policy and acceptable-use guidance for staff
  • Impact assessment template and completed assessments for higher-consequence uses
  • Incident and complaint handling for AI-related issues
  • Monitoring plan with metrics, drift checks and review cadence

What you receive

  • AI system inventory with intended use, owners and data categories
  • Risk assessments and vendor or model due-diligence records
  • AI use policy and staff guidance written for your operating reality
  • Human oversight design and evaluation plan with acceptance criteria
  • Impact assessments for the higher-consequence use cases in scope
  • Monitoring plan, review cadence and a governance record you can show a customer or regulator

Voluntary frameworks, management systems and legal obligations are different things

The NIST AI Risk Management Framework is voluntary guidance that helps structure AI risk work; following it is not a legal compliance status. ISO/IEC 42001 describes an AI management system, and certification against it is issued by an accredited certification body, not by us; we prepare readiness. Legal obligations differ by jurisdiction and by use case, and rules such as the EU AI Act apply on their own timelines and only to certain roles and risk categories. Sector rules on privacy, consumer protection, employment and discrimination often bite before any AI-specific law does. We explain which of these plausibly applies to your situation and recommend legal counsel for binding determinations; we do not tell you that you are compliant.

How we work

A five-step engagement

  1. Step 01

    Discover

    Interview teams, review vendor contracts and build an inventory of AI systems and features actually in use.

  2. Step 02

    Classify

    Record intended use, data involved, affected people and consequence level, then assign accountable owners.

  3. Step 03

    Assess

    Run proportionate risk assessments, vendor and model due diligence and impact assessments for higher-consequence uses.

  4. Step 04

    Design controls

    Put policy, guardrails, oversight points, evaluations and disclosure wording in place where they are justified.

  5. Step 05

    Monitor and review

    Agree metrics, drift checks, incident handling and a review cadence that keeps the inventory current.

Working together

What we need from you, and how we handle your data

Your responsibilities

  • Give us access to the teams using AI, including those using tools that were never formally approved.
  • Share vendor contracts and product documentation for AI features you rely on.
  • Name accountable owners; governance without an owner is documentation, not control.
  • Involve your legal advisers for binding interpretations of laws and contractual obligations.

Data handling

  • We review configuration, prompts, policies and sample outputs rather than bulk personal data.
  • Where evaluation needs real examples, we agree a minimal, redacted sample and a retention limit in writing.
  • We never enter your confidential data into consumer AI tools during an engagement.
  • Governance artefacts are delivered in editable form and remain your property.

How we use enquiry information is set out in our privacy policy.

FAQ

AI Governance & Compliance: common questions

Can you tell us whether we are compliant with AI regulation?

No. We assess your governance against recognised practice, explain which obligations plausibly apply to your jurisdictions and use cases, and document the record. Binding compliance determinations belong with your legal advisers.

Does the EU AI Act apply to us?

It depends on your role, where you operate, who your users are and the risk category of the use case, and its provisions phase in over time. We help you work through those questions and document the reasoning; your counsel confirms the conclusion.

Do we need ISO 42001 certification?

Only if a customer, regulator or contract asks for it. We can prepare an AI management system for certification readiness, but certification itself is issued by an accredited body.

We only use vendor AI features. Do we still need governance?

Yes, and it is usually lighter. You still need to know which features are on, what data flows into them, what the vendor commits to and who is accountable when output is wrong.

How do you evaluate whether an AI system is good enough?

We define the intended use, agree what an unacceptable outcome looks like, build a test set that reflects real cases and set acceptance thresholds with your owners. Evaluation results are recorded with their limitations rather than presented as a guarantee.

How does this relate to our existing security and privacy programme?

It extends it. AI governance reuses your risk register, vendor process, policy workflow and incident handling, and adds AI-specific records such as intended use, oversight design and evaluations.

Discuss AI governance

Tell us where AI is used in your organization and we will propose an inventory, risk and oversight scope.

Stay Updated. Stay Ahead.

Subscribe to receive the latest business insights, technology updates, company news, and useful ideas delivered to your inbox.

We respect your privacy. Unsubscribe at any time.