AI governance and risk management

We inventory the AI your organization uses, assess the risk each system carries, and write the policies, roles and compliance roadmap to govern it. The work is aligned to the NIST AI RMF and, where it applies to you, the EU AI Act.

Every AI system needs an owner.

AI tends to arrive before anyone has decided who is accountable for it. We set out who approves new AI use, how its risk is assessed, and which regulatory requirements apply, then document it so an auditor or board member can follow it.

Governance areas

Regulatory compliance

What the EU AI Act, NIST AI RMF and newer AI regulations mean for the systems you run.

Policy frameworks

AI policies covering acceptable use, data handling and risk management.

Risk management

A consistent way to identify, assess and reduce AI-related risk.

Ethical AI

Establish principles for fair, transparent, and accountable AI development and use.

Stakeholder alignment

Engage leadership, legal, compliance, and technical teams in governance programs.

Training and awareness

AI literacy and governance training for staff, managers and the board.

What an engagement can include

EU AI Act readiness

Risk classification of your AI systems, the documentation the Act asks for, and support preparing for conformity assessment.

NIST AI RMF alignment

Structure your AI risk management around the NIST AI Risk Management Framework: govern, map, measure and manage.

AI policy development

AI use policies, acceptable use guidelines and governance structures written around how your staff actually use AI.

Risk assessment frameworks

A repeatable process for evaluating AI risk across your organization, not a one-off review.

Responsible AI guidelines

Principles on bias, fairness, transparency and accountability that teams can apply to real projects.

Board and executive briefings

Plain-language briefings for leadership on AI risk, opportunity and their governance responsibilities.

How a governance engagement runs

Six steps, from finding out what AI you already use to rolling out the program.

01

Current state assessment

Evaluate existing AI initiatives, policies, and governance maturity.

02

Regulatory analysis

Identify applicable AI regulations and compliance requirements.

03

Risk identification

Catalog AI systems and assess associated risks and impact.

04

Framework design

Design a governance framework that fits your organization's size and risk profile.

05

Policy development

Write the AI policies, procedures and supporting documentation.

06

Implementation support

Guide rollout of governance program with training and change management.

What you get.

01

Governance framework

An AI governance structure with named roles, responsibilities and decision-making processes.

02

Policy documentation

AI policies covering acceptable use, risk management and ethics.

03

Risk assessment tools

Templates and methodologies for ongoing AI risk identification and evaluation.

04

Compliance roadmap

Action plan for achieving and maintaining compliance with applicable AI regulations.

Start with what AI you already run.

We'll ask which AI tools and models are in use today, which regulations you fall under, and tell you what a governance program would need to cover first.