AI inventory
Systems, models, agents, vendors, data flows, owners and risk tiers, kept current rather than captured once.
AI Governance
We build the structure that lets your organisation prove how AI is used, who is accountable, which risks were accepted and which controls are in place.
A functioning AI governance programme includes: a maintained inventory of AI systems and vendors; an acceptable-use and development policy; defined roles and an accountable decision forum; a risk classification method per use case; technical and organisational controls; human oversight requirements; model and dataset documentation; incident and complaint handling; indicators; and a recurring internal audit and management review cycle.
Systems, models, agents, vendors, data flows, owners and risk tiers, kept current rather than captured once.
Acceptable use, development and procurement, human oversight, data handling in AI tools and third-party AI.
A classification scheme per use case, tied to EU AI Act tiers and NIST AI RMF functions, with documented acceptance decisions.
Technical and organisational controls mapped to ISO/IEC 42001 Annex A, with owners and evidence requirements.
Committee design, decision rights, escalation paths and reporting cadence to the board.
Evidence structure, indicators, internal audit plan and management review so the programme survives scrutiny.
Interviews, tooling discovery, document review and a gap analysis against ISO/IEC 42001 and NIST AI RMF.
Target operating model, policy architecture, risk method and control set sized to your maturity.
Rollout with the accountable teams — legal, security, privacy, data, IT and business owners.
Committee routine, indicators, evidence collection and internal audit cycle.
A diagnosis and roadmap typically takes four to six weeks. A first operational baseline — inventory, policies, risk method, core controls and governance forum — is usually reached in three to six months, depending on the number of AI use cases and the organisation's existing security and privacy maturity.
No. ISO/IEC 42001 is the reference framework for structuring the management system; certification is a separate, optional step performed by an accredited body. Many organisations implement the standard to obtain the structure and evidence without pursuing certification immediately.
No. It integrates them into a shared architecture so legal, security, privacy, compliance, technology and leadership operate on common criteria and shared evidence.
Request an initial assessment and receive a prioritised view of exposure, gaps and next steps.