AI Governance

AI governance as an operating structure, not a policy document

We build the structure that lets your organisation prove how AI is used, who is accountable, which risks were accepted and which controls are in place.

What does an AI governance programme actually include?

A functioning AI governance programme includes: a maintained inventory of AI systems and vendors; an acceptable-use and development policy; defined roles and an accountable decision forum; a risk classification method per use case; technical and organisational controls; human oversight requirements; model and dataset documentation; incident and complaint handling; indicators; and a recurring internal audit and management review cycle.

What we deliver

AI inventory

Systems, models, agents, vendors, data flows, owners and risk tiers, kept current rather than captured once.

Policy set

Acceptable use, development and procurement, human oversight, data handling in AI tools and third-party AI.

Risk method

A classification scheme per use case, tied to EU AI Act tiers and NIST AI RMF functions, with documented acceptance decisions.

Control library

Technical and organisational controls mapped to ISO/IEC 42001 Annex A, with owners and evidence requirements.

Governance forum

Committee design, decision rights, escalation paths and reporting cadence to the board.

Evidence and audit

Evidence structure, indicators, internal audit plan and management review so the programme survives scrutiny.

How the engagement runs

  1. 01

    Diagnosis

    Interviews, tooling discovery, document review and a gap analysis against ISO/IEC 42001 and NIST AI RMF.

  2. 02

    Design

    Target operating model, policy architecture, risk method and control set sized to your maturity.

  3. 03

    Implementation

    Rollout with the accountable teams — legal, security, privacy, data, IT and business owners.

  4. 04

    Operation

    Committee routine, indicators, evidence collection and internal audit cycle.

Frequently asked questions

How long does an AI governance programme take to stand up?

A diagnosis and roadmap typically takes four to six weeks. A first operational baseline — inventory, policies, risk method, core controls and governance forum — is usually reached in three to six months, depending on the number of AI use cases and the organisation's existing security and privacy maturity.

Do we need ISO/IEC 42001 certification to have AI governance?

No. ISO/IEC 42001 is the reference framework for structuring the management system; certification is a separate, optional step performed by an accredited body. Many organisations implement the standard to obtain the structure and evidence without pursuing certification immediately.

Does AI governance replace legal, security or IT?

No. It integrates them into a shared architecture so legal, security, privacy, compliance, technology and leadership operate on common criteria and shared evidence.

Map your AI governance gaps

Request an initial assessment and receive a prioritised view of exposure, gaps and next steps.