For Organisations that want to govern AI use

Your org uses AI. You just don’t know how.

“The organisations that can prove control close the deal, pass the audit, and get asked fewer questions next time”
map[class:max-w-full mt-8 object-cover object-center rounded-4xl src:images/hero.jpg]

AWS Certified Generative AI Developer - Professional

Does AI governance apply to you?

You may have legal duties

  • You place AI-enabled products or services in the EU market, or your AI outputs are used there
  • Your AI speaks to customers, or generates content you publish under your name
  • AI touches client data, personal data, or anything commercially sensitive

Either way, someone will ask

  • A customer, insurer or regulator has ever sent you a security or AI questionnaire
  • You sell software or services to enterprise or regulated customers
  • Staff use ChatGPT, Copilot or another AI tool, with or without a policy covering it
  • Your board has asked what AI the business is running, and what happens if it goes wrong

Even if you answered no, you still have work to do

Potential fines

€15m / 3% turnover

Source: EU AI Act, Article 99

Shadow AI usage

71%

Source: Microsoft/Censuswide, October 2025

What the EU AI Act really requires

2 August 2026

Article 50 transparency obligations apply from this date

The four transparency duties

AI you talk to

AI-generated content

Emotion recognition

Deepfakes and public-interest text

What Article 50 doesn't reach

So what do we do about it?

Source: European Commission guidelines on Article 50, adopted 20 July 2026

Where the pressure comes from

Four sources, and most organisations are carrying all four at once. Each one boils down to the same two questions: what AI is running here, and what happens to the data once it gets there.

The stalled deal

A customer's procurement team sends an AI due-diligence questionnaire, and the deal sits behind it until you can answer it in writing.

Shadow AI

Staff pasting corporate & client data into consumer AI tools, with no register of what's being used or where the data goes.

Vendor risk

Every AI-enabled tool you've brought in carries the vendor's governance gaps as well as your own.

Regulatory exposure

UK GDPR already binds how you use AI, with or without the EU AI Act in play. The ICO doesn't need Brussels to enforce it.

We can help you get in control so...

  • A due-diligence questionnaire arrives and you answer it the same week, not the same quarter
  • Your board can confidently state your AI exposure
  • You know every AI tool in use across the business, and what each vendor does with your data
  • The controls, records and oversight are in place and evidenced, whichever way your regulatory classification goes

Let's talk and start your journey. Book a free call

What a due-diligence questionnaire typically asks

These are the five questions almost every AI due-diligence questionnaire is built around, whatever words it uses to ask them.

1

Do you know what AI is in use across your business, including tools nobody signed off?

2

Is there a human in the loop for decisions that affect the customer, and is that documented rather than assumed?

3

What happens to the customer's data once it touches an AI system, and does any of it leave your control?

4

If something goes wrong, is there a known process, or does it get handled ad hoc?

5

Who is accountable for AI risk internally, by name, not by department?

Answer those five with confidence and you can answer most of what's in a typical questionnaire.

Get the free checklist

What the work involves

1

Find where AI is being used

2

Agree the rules

3

Change how people work

4

Get ready for the questions you'll be asked

5

Manage the risk your suppliers bring in

6

Keep it running

What this gives you

  • An AI inventory covering every tool in use, including the shadow AI
  • An acceptable use policy your leadership has signed
  • Staff and board trained on the policy, not just handed it
  • Controls and documentation mapped to ISO/IEC 42001
  • A third-party risk view across every AI-enabled tool you’ve bought

Governance is usually the first step. Once your people are working differently and the evidence is in place, we build the tools and workflows that make AI pay.

Three things we're clear about upfront

We don't give legal opinions

Your regulatory classification is a question for a solicitor, and you should want it in writing from one. We build the inventory, risk process, documentation and oversight controls that hold up whichever way the answer goes, and hand you the short list of questions worth paying a lawyer to settle.

We don't certify anyone

Certification is done by an accredited certification body, and no consultancy can both advise and certify. We build the management system and get you ready for that audit.

We only use frameworks that apply to you

ISO/IEC 42001, the EU AI Act and UK GDPR/ICO guidance. We leave out NIST's AI RMF because it's US-focused and adds little to a UK engagement. A longer framework list isn't a better one.

Governance engagements

Each one is a fixed price against a written scope agreed before we start. Stop after any of them. Training is priced separately on the [training page](/training/).

Govern

1 AI Discovery Most popular What AI are we running, and where would it pay? Where AI is already being used across your business, where it should be, and whether your organisation can adopt it. From £5,000 Typically 1-2 weeks +
  • A map of AI use across the business, including what nobody officially approved
  • A ranked shortlist of where AI would pay
  • Risk register covering data, suppliers and regulatory exposure
  • A straight go/no-go on what to do next
Discuss discovery
2 AI Policy & Sign-off What are we allowed to do? What your organisation permits, decided and signed by your leadership. This sets the rules. Proving you follow them is the next engagement. From £3,500 Typically 1-2 weeks +
  • Acceptable use policy: what's approved, what's off-limits
  • Which decisions need a human, and at which point
  • A named owner for every area of AI risk
  • Facilitated leadership session ending in sign-off
  • Board-ready policy document
Discuss policy
3 Gap Assessment How far off are we from proving it? Where your controls stand against ISO/IEC 42001, clause by clause, and what it would cost to close the distance. Rules on paper are one thing; this tests whether you could evidence them to an auditor. From £4,500 Typically 2 weeks +
  • Your existing controls mapped against ISO/IEC 42001, clause by clause
  • A written gap list, ranked by what a customer or auditor asks about first
  • Your AI inventory tested against what the standard asks for, or a first one built if you haven't got one
  • The regulatory questions worth putting to a solicitor, and the ones already settled
  • A remediation plan with the work costed, so the next decision is yours
Discuss an assessment
4 Compliance Readiness How do we close the gaps? The remediation itself, scoped against the gaps we found rather than guessed at before we started. Quoted from your gap assessment A few weeks +
  • The inventory turned into a live register, with an owner and a review cycle
  • Controls and documentation mapped to ISO/IEC 42001
  • AI Act-aligned controls and documentation, built to support your classification once it's confirmed
  • Human oversight and incident handling you can point an auditor at
  • Audit trail and evidence design
  • Certification-ready documentation
Discuss readiness

Our commitments

Fixed scope, fixed price

Each engagement is quoted at a fixed price against a scope agreed in writing before we start. No day-rate creep, and no surprise on the invoice.

Named deliverables

You get the documents listed on each engagement at the end of it, so you can put them straight in front of a customer, an auditor or your board.

Start anywhere, stop anywhere

Nothing here is a bundle or a prerequisite. Come for training, a prototype or a retainer on its own if that's what you need, and stop whenever you're done.

Confidential from the first call

Everything you tell us stays between us, on the free call as much as in a paid engagement, and we'll sign your NDA beforehand if you'd rather have it in writing.

10 Kinds AI Readiness Checklist, page one

Free download

Start by finding out where you are today

Twelve questions every leadership team should be able to answer about the AI already running in their business. It covers similar ground to a paid discovery engagement, condensed into something you can work through yourself in about ten minutes.

  • Twelve questions across visibility, policy, suppliers, regulation and evidence
  • Plain English, written for a leadership team rather than a compliance department
  • A scoring note telling you what your answers mean

Questions

We were sent a customer due-diligence questionnaire about our AI. Can you help? +
We don't build AI ourselves, we just use tools like ChatGPT or Copilot. Does this still apply? +
Will you tell us whether we're a high-risk provider under the EU AI Act? +
Is this just data protection with an AI label on it? +
Do we need to be ISO 42001 certified? +
We'd rather not advertise how messy this is. Is what we tell you confidential? +
What happens to our data while you're working with us? +
Does training count towards ISO 42001? +
How do we get started? +

Start with a conversation

Book a free call

You'll leave with a clear position on where you stand and what to fix first, whether or not you hire us.