All services

Governance & Trust

AI Governance & Compliance

Turn the supervisory review from a fire drill into an export.

1 export
Full audit evidence pack
100%
Models classified and owned
ISO 42001
Control mapping ready

The problem we solve

Regulators, auditors and boards are now asking the same question: which models are running, who owns them, and what evidence do you hold? We build the register, the controls and the evidence trail that answers it in a single export.

What the work includes

Model inventory & registry

Every model, prompt and agent registered with owner, purpose, risk class and lifecycle state.

Risk classification

EU AI Act tiering, impact assessments and control requirements proportional to risk.

Policy & standards

Acceptable use, human oversight, disclosure and procurement standards written to be followed, not filed.

Assurance & audit evidence

Automated evidence collection, control testing and reviewer sign-off workflows.

Responsible AI

Bias testing, explainability, contestability and incident response procedures.

How the engagement runs

A sequence you can plan a quarter around.

  1. 01

    Discover

    Shadow AI sweep, model inventory and current control assessment.

  2. 02

    Design

    Risk framework, policies and control mapping to EU AI Act and ISO 42001.

  3. 03

    Embed

    Tooling, workflows and training so governance runs without a consultant in the room.

Common questions

Before you commit.

Will this slow delivery down?
Done properly it speeds it up: proportional controls mean low-risk use cases ship without committee review.
Do you cover shadow AI?
Yes — discovery of unsanctioned tool use is usually the first and most uncomfortable finding.

Talk through ai governance & compliance.

A 45-minute briefing with the people who would run the work — scope, timeline and a straight answer on whether it is the right next step.

Book a briefing