top of page
Cyberpunk letterbox blog banner.png

AI Governance

Our AI Governance service helps organisations establish what AI they are actually using, understand the risk it carries, and put proportionate governance around it. Built on your existing risk, security and privacy arrangements rather than alongside them, and aligned to the EU AI Act, UK GDPR and ICO expectations, ISO/IEC 42001 and the NIST AI RMF.

Take Control of AI Risk

01.

Catalogue

Establish what AI is in use across the organisation, including features that arrived through vendor product updates and tools staff adopted on their own.

02.

Assess

Score maturity across six domains and map the gaps against all four frameworks in a single exercise.

03.

Decide

Classify each use case by risk and record a documented decision — proceed, proceed with controls, or do not proceed.

04.

Govern

Put the policy, ownership, AI register and intake approval process in place, integrated with your existing risk register.

05.

Sustain

Keep it current as your AI estate grows and the regulatory position moves, with review, reporting and horizon scanning.

AI Governance Service Picture.png

What Good AI Governance Looks Like

Whatever framework you adopt, the same six principles need to hold. AI use should be human controlled, transparent, appropriate, secure, lawful and accountable. We use these to test both policy and individual use cases.

 

Read more about our approach here.

One Engagement, Four Frameworks

EU AI Act

Risk classification, transparency obligations, conformity assessment requirements, and determination of whether you act as a provider or a deployer.

ISO/IEC 42001

Clause-level gap analysis, AI management system build, Statement of Applicability and readiness for certification through a UKAS-accredited body.

UK GDPR

Lawful basis, DPIA triggers and automated decision-making, alongside the ICO’s AI auditing framework, explainability and fairness expectations.

NIST AI RMF

Govern, Map, Measure and Manage — the operational layer that bridges AI risk into your existing security and enterprise risk programmes.

Services

Assess

Where you are today

 

  • Free Readiness Check

  • Essential Assessment

  • Comprehensive Review

  • Use-Case Risk Assessment

  • Scoring & Roadmap

Advise

Building the framework
 

  • AI Strategy Advisory

  • Framework Design

  • Policy & AI Register

  • ISO/IEC 42001 Gap Review

  • AIMS Build & SoA

  • Internal Audit

  • Certification Support

  • EU AI Act Readiness

  • AI Security & Assurance

Sustain

Run by us — CISOaaS & CAPaaS
 

  • Named Governance Lead

  • AI Register Maintained

  • Intake & Approval Triage

  • Policy Maintenance

  • Horizon Scanning

  • Quarterly Review

  • Board Reporting

  • Annual AI Review

Additional Services

  • Shadow AI Reviews

  • AI Threat Modelling

  • Supplier AI Assurance

  • AI Incident Playbooks

  • Staff AI Awareness

  • AI Prompt Testing

Useful Resources

Free AI Readiness Assessment
Around 15 to 20 minutes, six domains, instant report. No consultant involvement
AI Governance Factsheet
Two-page overview of the service, frameworks and deliverables.
 
AI Cyber Risk Management: Why Leaders Must Act Now
Article covering the Five Eyes joint statement and what it means for boards.
bottom of page