AI Governance
Governance, run as a workflow.
ISO/IEC 42001 certified, NIST AI RMF and EU AI Act aligned — with audit evidence produced as a by-product of running the system, not bolted on afterwards.
- Certified
- ISO/IEC 42001
- Aligned
- NIST AI RMF · EU AI Act
- Listed
- National AI Centre
- Tooling
- watsonx · Credo AI
Governance services
The same workflow, pillars and evidence we run ourselves.
Packaged so a public-sector agency or an enterprise can get from an unmanaged AI estate to an audit-ready one in months, not years.
- 01
Assessment and risk tiering of your AI estate
- 02
Policy suite, committee and decision rights
- 03
Impact and risk assessments (ISO 42005, FRIA)
- 04
Testing, evaluation and red-teaming
- 05
Audit, certification readiness and assurance
- 06
AIOps and managed governance against an SLA
The workflow
Four steps, then it runs.
- 01
Discovery & scoping
Use cases, stakeholders, regulatory exposure
- 02
Gap assessment
Current state against a regulatory framework
- 03
Process governance
Controls, roles and decision rights
- 04
Implementation
Tooling, evidence and reporting live
Framework refreshed annually against regulatory change.
Six pillars hold it up
Leadership, policies, risk, controls, training, reporting.
Leadership
Committee, sponsorship, decision rights
Named owner for every AI decision
Policies
Principles, policy suite, procedures
Ratified and version-controlled
Risk
Taxonomy, assessments, register
Treatment plans with due dates
Controls
Gates, monitoring, human review
Release blocked without evidence
Training
AI literacy, role-based enablement
Certification pathway for key staff
Reporting
Evidence, lineage, external reporting
Audit pack produced on demand
Established at three levels
Organisational
Oversight, structure, culture
System
Lifecycle, risk, incidents, gates
Model
Registry, drift, monitoring, evidence
Modular governance solutions
Packaged engagements with fixed scope, milestones and deliverables.
Each mapped to ISO/IEC 42001, NIST AI RMF and the local regulator.
G1Assessment & Risk Tiering4–6 weeksInventory and risk-tier the AI estate, score maturity, price the gap.
Deliverables
Risk-tiered inventory, maturity scorecard
G2Policy, Framework & Literacy6–8 weeksPolicy suite, committee, decision rights, GRC literacy.
Deliverables
Policy suite, committee charter, intake gate
G3Risk & Impact Assessment8–10 weeksISO 42005 impact assessments, FRIA, risk register, controls.
Deliverables
Impact assessments, risk register
G4Testing, Evaluation & Red-Teaming8–12 weeksEvals, red-teaming, bias and drift testing, evidence platform.
Deliverables
Eval results, red-team findings
G5Audit, Certification & Assurance10–14 weeksInternal audit, conformity audit, vendor audit, attestation.
Deliverables
Audit report, control scores, attestation
G6AIOps & Managed GovernanceAnnuity · 12 months+Continuous monitoring, evidence on demand, retained expertise.
Deliverables
Monthly dashboards, incident register
Four-week accelerators
Fixed scope, fixed deliverables. Each draws on one governance module and lands in four weeks.
- A14 weeks
Transparency
Explainability, audit trail and reporting for the AI systems already in use.
Draws on Reporting
- A24 weeks
Vendor audit
Vendor audit against ISO/IEC 42001 and NIST AI RMF, with control scores.
Draws on G5 Audit, Certification & Assurance
- A34 weeks
Agent guardrails
Guardrail tuning, approval gates and exception and escalation paths for agents in production.
Draws on Controls
- A44 weeks
Red-team sprint
Evals, red-teaming, bias and drift testing — eval results and red-team findings.
Draws on G4 Testing, Evaluation & Red-Teaming
- A54 weeks
GRC literacy
AI literacy and role-based enablement, with a certification pathway for key staff.
Draws on G2 Policy, Framework & Literacy
- A64 weeks
AIOps baseline
Continuous monitoring and evidence on demand — monthly dashboards and an incident register.
Draws on G6 AIOps & Managed Governance
Start with an assessment
Inventory the estate, tier the risk, price the gap.
G1 runs four to six weeks and ends with a risk-tiered inventory and a maturity scorecard the board can read.
