Skip to content
McCullochRegulatory Compliance
All practices

AI Governance & EU AI Act Compliance

Artificial intelligence governance and EU AI Act compliance for organisations deploying AI: governance frameworks, risk classification, AI literacy, and assurance that keep the AI you adopt governed, documented, and defensible.

EU AI ActArticle 4 literacyGDPRISO/IEC 42001Life SciencesTechnology & AI

What we do

MRC helps organisations govern the AI they adopt, from a single assessment to a complete governance programme, delivered as discrete engagements or as ongoing support.

Governance

AI governance framework

The governance structure, policies, roles, and AI system inventory that give leadership control of how AI is used.

Assessments

AI risk and impact assessments

We carry out fundamental-rights and data-protection impact assessments, and review systems for bias, robustness, and transparency.

Regulated use

AI in regulated and GxP settings

Governance and validation of AI used in life sciences and other regulated environments.

More AI services

AI literacy and training

Role-based AI literacy training that meets the Article 4 duty for everyone who uses AI at work.

Data protection for AI

We bring the personal data used to train and run models into GDPR compliance, applied alongside the AI Act.

Assurance and audit

Independent review of AI systems, and due diligence on third-party and vendor AI.

Policy and documentation

Acceptable-use policies, model and system documentation, and the records that stand up to scrutiny.

A team reviewing AI systems and oversight records on screen
EU AI Act

EU AI Act compliance

The EU AI Act sets obligations by the risk of each system. We classify your systems, establish the duties that apply, and put the documentation and oversight in place to meet them.

Risk classification

Classifying each AI system as prohibited, high-risk, limited, or minimal risk, and establishing the obligations that follow.

Conformity and documentation

Technical documentation, record-keeping, and conformity steps for higher-risk systems.

AI literacy

Meeting the Article 4 duty with role-based training across the organisation.

Governance and oversight

Human oversight, monitoring, and the governance records an authority would expect.

Who we help

We work with organisations at every stage of AI adoption, from a first deployment to an established estate that governance must catch up with.

Adopting AI

Introducing AI for the first time and needing governance before, not after, deployment.

Scaling AI

Already using AI across the organisation and needing governance to catch up.

Regulated AI users

Deploying AI in life sciences or other regulated settings where validation and evidence matter.

A professional working at a screen

Governed, documented, and defensible

Every recommendation is traced to its rule, sized to the risk of the system, and built to be defensible when a regulator, a customer, or your board asks the question.

Mapped

Every recommendation traced to its rule

AI Act article, GDPR provision, or standard: never advice without a source.

Proportionate

Risk-based and sized to you

Governance scaled to the risk of the system and the size of the organisation.

Defensible

Governed and documented

Records and oversight that demonstrate the AI you run is under control.

Frameworks we work to

EU · UK · ISO

EU AI Act

Reg (EU) 2024/1689

Article 4

AI literacy duty

GDPR

UK & EU data protection

ISO/IEC 42001

AI management systems

Putting AI to work, or proving the AI you run is governed

Whether you are adopting artificial intelligence for the first time or bringing an existing estate under control, tell us where you are and we will come back to you promptly.