Governance is what lets you ship, not what stops you
The organisations deploying AI at scale are not the ones with the fewest controls. They are the ones who can answer their auditor in an afternoon. We build the inventory, the risk classification, the testing evidence and the human oversight that turns an AI initiative from a legal question mark into a governed production system.
- Days
- to produce audit evidence, instead of a quarter of archaeology
- 100%
- of AI systems inventoried, owned and risk-classified
- Proportional
- controls: light-touch for low risk, rigorous for high
- Continuous
- fairness and drift monitoring rather than a one-off test
What it looks like today
The pattern we find in almost every operation
- Nobody holds a complete list of AI systems in use, including the ones embedded in vendor products.
- A model makes decisions affecting customers and no one can reproduce how any individual case resolved.
- Regulatory obligations are understood by legal and never translated into engineering requirements.
- Human oversight is asserted in the design document and absent from the actual workflow.
- Accuracy and fairness were tested once before go-live and never again.
- Procurement cannot assess vendor AI claims, so it either blocks them or waves them through.
How we do it
The approach, step by step
- 01
Inventory everything, including the invisible
An AI register covering bespoke models, vendor features and embedded capability. You cannot govern what has not been listed, and the embedded ones are almost always the surprise.
- 02
Classify by actual risk
Each system is scored against the regulatory regime that applies to it and the real-world consequence of it being wrong. Proportional controls mean the low-risk majority moves quickly instead of queueing behind the genuinely high-risk few.
- 03
Translate obligations into requirements
Legal requirements become testable acceptance criteria: logging fields, retention rules, explanation format, review thresholds, escalation paths. 'Compliant with data protection law' is not something an engineer can build.
- 04
Prove the oversight is real
Human-in-the-loop designed into the workflow, with measured review rates and a working escalation path, so oversight is evidenced by the system's own logs rather than asserted in a design document nobody re-reads.
- 05
Test continuously, not once
Accuracy, fairness and drift monitored in production against defined thresholds, with a documented response when a threshold is breached. A one-off pre-launch test tells you about the system you deployed, not the one running today.
What you receive
Deliverables, stated up front
- AI system inventory and register with owners and lifecycle status
- Risk classification and regulatory mapping per system
- Model and system cards: purpose, data, limitations, evaluation, oversight
- Control framework with testable acceptance criteria per obligation
- Human oversight design with measured review and escalation rates
- Evaluation harness covering accuracy, fairness, robustness and drift
- Production monitoring thresholds with a documented breach response
- Audit evidence pack and a data protection impact assessment template set
You are a fit if
- You cannot list every AI system your organisation uses
- A model influences decisions about customers, employees or credit
- Legal and engineering disagree about what the regulation requires in practice
- An audit, customer or regulator has asked how an AI decision was reached
- Vendor AI features are being adopted without assessment
We will tell you it is a fit problem if
- Nothing in scope makes automated decisions about people and the risk is genuinely low
- You already have a functioning AI governance practice and need tooling, which is software rather than a service
- The objective is to appear compliant rather than to be able to evidence it
Systems we work with
Not on the list? We integrate against anything with an API, a database, a file interface or a documented import format.
Questions we get on this
AI governance: the practical answers
Will this slow down delivery?
We are not in a regulated sector. Does any of this apply?
Can you assess vendor AI rather than our own models?
Do you write the policy or build the controls?

Bring us the process you already know is costing too much
Thirty minutes with an engineer is usually enough to tell whether it is worth automating, roughly what it would save, and whether the payback is inside a window your finance team will accept. If the answer is no, we will say so on the call.