AI Governance, Risk & Compliance
Model risk controls, EU AI Act readiness and responsible-AI policies that regulators and customers accept.
AI now carries legal obligations and reputational risk. The EU AI Act classifies systems and sets requirements for the higher-risk ones. Customers ask how your models are tested and monitored. We build the governance framework that answers those questions: inventory, classification, controls, documentation and the policies that guide daily use.
The aim is proportionate control. High-risk systems get rigorous treatment. Low-risk ones get a light process that doesn't slow the team down.
- Governance is designed with the engineers who build the systems, so the controls are practical.
- We align with ISO 42001 where certification is useful, and keep it lighter where it isn't.
- Third-party AI tools are covered, since that is where most organisations' real exposure sits.
- A bank, insurer or healthcare group with AI systems that fall into the higher-risk classes of the EU AI Act.
- A listed company whose audit committee has asked for an AI risk register.
- A group using dozens of vendor AI tools with no inventory and no assessment process.
- Nobody can list every AI system in use, including the ones inside vendor products.
- Customers ask how models are tested and monitored and the answer is improvised.
- A regulatory deadline is approaching and the obligations have not been mapped.
- Model failures are handled as IT tickets rather than as risk events.
What is included.
- 01
AI inventory and classification
Every system in use, including third-party tools, classified by risk and regulation.
- 02
Regulatory mapping
EU AI Act, GDPR and sector rules mapped to obligations for each system.
- 03
Governance framework
Roles, review gates, documentation standards and escalation paths.
- 04
Model risk controls
Testing, evaluation, monitoring and incident handling requirements.
- 05
Policies
Responsible AI, acceptable use and vendor assessment policies written for your organisation.
Four steps, no surprises.
- 01
Inventory
Discover and classify AI systems across the organisation.
- 02
Map
Obligations and gaps identified per system.
- 03
Build
Framework, controls and policies implemented with owners.
- 04
Embed
Training, review cycles and audit-ready documentation.
From first meeting to steady state.
- 01Weeks 1 to 4
Inventory and classify
AI systems discovered across the organisation, including third-party tools, and classified by risk and regulation.
- 02Weeks 5 to 8
Map and design
Obligations mapped per system, then framework, controls and policies drafted with the engineers who build the systems.
- 03Weeks 9 to 12
Embed
Owners assigned, review cycles running, training delivered and audit-ready documentation in place.
- Share of AI systems inventoried, classified and assigned an owner.
- Obligations mapped and closed per system against the regulatory timeline.
- Time to complete a review gate for a new AI system or vendor tool.
- AI incidents recorded, investigated and closed under the framework.
- AI governance lead
- Regulatory and privacy liaison
- AI engineer
- Risk analyst
- AI system inventory and classification.
- Regulatory obligation map.
- Governance framework and risk register.
- Policy pack.
- Audit-ready documentation templates.
Governance programmes are fixed scope and typically take six to twelve weeks for a first framework. Ongoing reviews, new system assessments and regulatory updates run on an annual retainer. ISO 42001 certification preparation is scoped separately.
Compliance & Governance (ISO 27001, SOC 2, NIS2, GDPR)
Gap assessment, policy writing and audit preparation across the frameworks your customers demand.
CybersecurityAI/LLM Security Assessment
Prompt injection, data leakage and model abuse testing for AI features, assistants and agents.
AI Consulting & AutomationAI Adoption & Team Enablement
Training, operating model and change management so people use what has been built.
AI Governance, Risk & Compliance, in plain terms.
If you provide or use AI systems in the EU, some obligations apply. Which ones depends on the system's purpose and risk class, which the inventory establishes.
The international standard for AI management systems. It is a useful structure for governance and increasingly requested by enterprise customers.
Yes. Using a tool with company or customer data creates obligations, and vendor assessment is part of the framework.
Testing evidence feeds the risk register. Our AI security assessments produce the documentation the governance framework expects.