
AI Governance Consultancy
ICA Consultancy is an independent AI governance consultancy working with organisations that may already have AI in their business, whether they chose it deliberately or not. We help you establish what AI you are actually using, understand where the risk sits, and put proportionate governance around it, without the cost of a specialist internal team, or the bias of a vendor selling you a platform.
What Our AI Governance Service Covers
We provide end-to-end AI governance support, covering discovery, assessment, framework design and ongoing oversight.
-
AI cataloguing and inventory, including shadow AI and embedded vendor features
-
AI governance maturity assessments and framework gap analysis
-
AI policy, acceptable use and governance framework design
-
AI use case and system risk assessment, with documented approval decisions
-
EU AI Act applicability, system classification and compliance planning
-
ISO/IEC 42001 gap review, AIMS build, Statement of Applicability and certification support
-
AI security testing, including prompt injection, model abuse and adversarial scenarios
-
Supplier AI assurance and AI incident response playbooks
-
AI risk integrated into your existing risk register, with board reporting and ongoing oversight through CISOaaS and Capability-as-a-Service
Our Approach
AI governance should sit inside your existing governance arrangements, not alongside them. AI is another risk area — one that needs particular treatment, but not a separate organisation, a separate committee structure or a separate set of processes. Most organisations already have a risk register, an ISMS and a privacy programme. The work is extending them, not duplicating them.
Every engagement starts with establishing what AI is genuinely in use, including the AI that arrived through vendor product updates and staff using consumer tools. You cannot govern what you have not found.
We are independent of any AI platform or tooling vendor, and we do not build AI systems. Our recommendations are based on what your organisation needs, sized so your existing team can actually operate them.
What Good AI Governance Looks Like
Whatever framework an organisation adopts, the same six principles need to hold. We use these to test AI policy and individual use cases.
-
Human controlled: There is oversight of decisions AI makes on behalf of the business, and real people can intervene.
-
Transparent: Where AI informs a decision, it is possible to establish how it reached that conclusion.
-
Appropriate: There is a basis for deciding whether AI is a good fit for a problem, rather than assuming it is.
-
Secure: AI systems, the data they use and the outputs they produce are protected to the same standard as everything else.
-
Lawful: Aligned with data protection obligations and applicable regulation.
-
Accountable: A named person in the business owns each AI initiative.
Related Services
Talk to an AI Governance Consultancy UK Businesses Trust
Whether you need to establish what AI is already in use, prepare for ISO/IEC 42001, or put governance around an adoption programme that has already started, we can help you work out where to focus. Start with the free assessment, or get in touch for an initial conversation.
