Opulence.
AI Consulting & Automation

AI Governance, Risk & Compliance

Model risk controls, EU AI Act readiness and responsible-AI policies that regulators and customers accept.

AI now carries legal obligations and reputational risk. The EU AI Act classifies systems and sets requirements for the higher-risk ones. Customers ask how your models are tested and monitored. We build the governance framework that answers those questions: inventory, classification, controls, documentation and the policies that guide daily use.

The aim is proportionate control. High-risk systems get rigorous treatment. Low-risk ones get a light process that doesn't slow the team down.

How we're different
  • Governance is designed with the engineers who build the systems, so the controls are practical.
  • We align with ISO 42001 where certification is useful, and keep it lighter where it isn't.
  • Third-party AI tools are covered, since that is where most organisations' real exposure sits.
Who this is for
  • A bank, insurer or healthcare group with AI systems that fall into the higher-risk classes of the EU AI Act.
  • A listed company whose audit committee has asked for an AI risk register.
  • A group using dozens of vendor AI tools with no inventory and no assessment process.
Signals you need this now
  • Nobody can list every AI system in use, including the ones inside vendor products.
  • Customers ask how models are tested and monitored and the answer is improvised.
  • A regulatory deadline is approaching and the obligations have not been mapped.
  • Model failures are handled as IT tickets rather than as risk events.
Scope of work

What is included.

  1. 01

    AI inventory and classification

    Every system in use, including third-party tools, classified by risk and regulation.

  2. 02

    Regulatory mapping

    EU AI Act, GDPR and sector rules mapped to obligations for each system.

  3. 03

    Governance framework

    Roles, review gates, documentation standards and escalation paths.

  4. 04

    Model risk controls

    Testing, evaluation, monitoring and incident handling requirements.

  5. 05

    Policies

    Responsible AI, acceptable use and vendor assessment policies written for your organisation.

Method

Four steps, no surprises.

  1. 01

    Inventory

    Discover and classify AI systems across the organisation.

  2. 02

    Map

    Obligations and gaps identified per system.

  3. 03

    Build

    Framework, controls and policies implemented with owners.

  4. 04

    Embed

    Training, review cycles and audit-ready documentation.

How the engagement runs

From first meeting to steady state.

  1. 01Weeks 1 to 4

    Inventory and classify

    AI systems discovered across the organisation, including third-party tools, and classified by risk and regulation.

  2. 02Weeks 5 to 8

    Map and design

    Obligations mapped per system, then framework, controls and policies drafted with the engineers who build the systems.

  3. 03Weeks 9 to 12

    Embed

    Owners assigned, review cycles running, training delivered and audit-ready documentation in place.

What we measure
  • Share of AI systems inventoried, classified and assigned an owner.
  • Obligations mapped and closed per system against the regulatory timeline.
  • Time to complete a review gate for a new AI system or vendor tool.
  • AI incidents recorded, investigated and closed under the framework.
Who is on the engagement
  • AI governance lead
  • Regulatory and privacy liaison
  • AI engineer
  • Risk analyst
Deliverables
  • AI system inventory and classification.
  • Regulatory obligation map.
  • Governance framework and risk register.
  • Policy pack.
  • Audit-ready documentation templates.
Engagement terms

Governance programmes are fixed scope and typically take six to twelve weeks for a first framework. Ongoing reviews, new system assessments and regulatory updates run on an annual retainer. ISO 42001 certification preparation is scoped separately.

FAQ

AI Governance, Risk & Compliance, in plain terms.

If you provide or use AI systems in the EU, some obligations apply. Which ones depends on the system's purpose and risk class, which the inventory establishes.

The international standard for AI management systems. It is a useful structure for governance and increasingly requested by enterprise customers.

Yes. Using a tool with company or customer data creates obligations, and vendor assessment is part of the framework.

Testing evidence feeds the risk register. Our AI security assessments produce the documentation the governance framework expects.

Next step

Ready to talk about ai governance, risk & compliance?