
AI Governance
Our AI Governance service helps organisations establish what AI they are actually using, understand the risk it carries, and put proportionate governance around it. Built on your existing risk, security and privacy arrangements rather than alongside them, and aligned to the EU AI Act, UK GDPR and ICO expectations, ISO/IEC 42001 and the NIST AI RMF.
Take Control of AI Risk
01.
Catalogue
Establish what AI is in use across the organisation, including features that arrived through vendor product updates and tools staff adopted on their own.
02.
Assess
Score maturity across six domains and map the gaps against all four frameworks in a single exercise.
03.
Decide
Classify each use case by risk and record a documented decision — proceed, proceed with controls, or do not proceed.
04.
Govern
Put the policy, ownership, AI register and intake approval process in place, integrated with your existing risk register.
05.
Sustain
Keep it current as your AI estate grows and the regulatory position moves, with review, reporting and horizon scanning.

What Good AI Governance Looks Like
Whatever framework you adopt, the same six principles need to hold. AI use should be human controlled, transparent, appropriate, secure, lawful and accountable. We use these to test both policy and individual use cases.
One Engagement, Four Frameworks
EU AI Act
Risk classification, transparency obligations, conformity assessment requirements, and determination of whether you act as a provider or a deployer.
ISO/IEC 42001
Clause-level gap analysis, AI management system build, Statement of Applicability and readiness for certification through a UKAS-accredited body.
UK GDPR
Lawful basis, DPIA triggers and automated decision-making, alongside the ICO’s AI auditing framework, explainability and fairness expectations.
NIST AI RMF
Govern, Map, Measure and Manage — the operational layer that bridges AI risk into your existing security and enterprise risk programmes.
Services
Assess
Where you are today
-
Free Readiness Check
-
Essential Assessment
-
Comprehensive Review
-
Use-Case Risk Assessment
-
Scoring & Roadmap
Advise
Building the framework
-
AI Strategy Advisory
-
Framework Design
-
Policy & AI Register
-
ISO/IEC 42001 Gap Review
-
AIMS Build & SoA
-
Internal Audit
-
Certification Support
-
EU AI Act Readiness
-
AI Security & Assurance
Sustain
Run by us — CISOaaS & CAPaaS
-
Named Governance Lead
-
AI Register Maintained
-
Intake & Approval Triage
-
Policy Maintenance
-
Horizon Scanning
-
Quarterly Review
-
Board Reporting
-
Annual AI Review
Additional Services
-
Shadow AI Reviews
-
AI Threat Modelling
-
Supplier AI Assurance
-
AI Incident Playbooks
-
Staff AI Awareness
-
AI Prompt Testing
