01 / Map
Inventory & roles
- AI use-case register
- Provider or deployer role
- Triage for new use cases
Govern (NIST)
Practical, defensible AI governance across the EU, UK, and US, from a first map of where AI is used through risk classification, controls, and documentation, to independent assurance and EU AI Act readiness.
Governing framework
EU AI Act
Reg (EU) 2024/1689 · risk-tiered · GPAI duties
ISO/IEC 42001
AI management system · certifiable
NIST AI RMF
Govern · Map · Measure · Manage
UK & EU GDPR
DPIAs · Art. 22 automated decisions
What we do
Boards, regulators, and customers increasingly ask the same question: can you show that your AI is lawful, safe, and well governed?
We turn a fast moving, fragmented set of rules into controls your teams can actually run. From a first inventory of where AI is used, through risk classification and proportionate controls, to documentation and independent assurance, we cover the full path end to end.
Our work is grounded in regulatory compliance and risk. We give you a clear view of which obligations apply to each system, what good looks like, and the shortest credible path to meeting it.
The AI governance lifecycle
Inventory, classification, risk assessment, controls, and assurance, scaled to the risk of each system and the stage you are at.
01 / Map
Govern (NIST)
02 / Classify
EU AI Act
03 / Assess
ISO/IEC 23894
04 / Control
AI Act Annex IV
05 / Assure
ISO/IEC 42001
Three approaches, one standard of rigour
The rules diverge sharply across markets, from a comprehensive statute in the EU to a framework-and-sector model in the US and a principles-based approach in the UK. We navigate each on its own terms and keep your programme coherent across all three.
AI Act · 2024/1689
The EU AI Act is the first comprehensive AI law, applying a risk-tiered set of obligations to providers and deployers, with separate duties for General-Purpose AI. Obligations phase in over several years.
Determine provider or deployer status and classify each system across the prohibited, high-risk, limited, and minimal-risk tiers.
Risk-management system, data governance, technical documentation, logging, transparency, human oversight, accuracy, robustness, and cybersecurity.
Documentation, a training-data and copyright policy, and systemic-risk duties for general-purpose and frontier models.
Conformity-assessment route, EU declaration of conformity, CE marking where applicable, and EU database registration.
User-facing disclosure for chatbots and AI-generated content, and human-oversight design.
Post-market monitoring plan and serious-incident reporting once systems are in use.
Who we help
Whether you build AI, deploy someone else’s, or put it to work in a regulated setting, we meet you where you are.
01
Developers and providers shipping AI features or models who need a defensible compliance position.
02
Organisations deploying third-party or generative AI who must govern use, vendors, and risk.
03
Life-sciences and health-tech teams putting AI into clinical, device, or quality-critical settings.
Practical · Proportionate · Defensible
Done well, AI governance shortens security and procurement reviews, reassures boards and investors, and lets you move faster because the guardrails are clear. We combine hands-on regulatory experience with a compliance-first mindset, so your position holds up when it is tested.
Every control traced to its rule
AI Act article, ISO clause, or NIST function: advice with a source, never opinion alone.
Sized to your risk
Light-touch where risk is low, rigorous where it is high. No box-ticking for its own sake.
Built for the question you will be asked
Documentation and assurance that hold up with a regulator, a customer, or your board.
Tell us where you are, and we will map the shortest credible path to a compliant, defensible position.