AI Governance & Assurance

Govern your own AI with confidence.

Boards are asking a new question: are we governing our own use of AI safely and compliantly? We help you answer it, with audit-ready AI governance, ISO 42001 readiness and EU AI Act preparation.

Audit-ready governance for your own AI

In plain English

What AI governance actually means.

AI governance is the set of policies, controls and evidence an organisation uses to make sure the AI it builds, buys and uses is safe, lawful and accountable. In practice it means knowing where AI is used, classifying the risk each system carries, putting controls and human oversight in place, and keeping the documentation that proves it, to a standard an auditor, regulator or customer will accept.

Read the full guide to AI governance

What we help with

Three ways to get your AI house in order.

ISO 42001 readiness & certification

The AI Management System standard. We get you ready and certification is delivered through certified assessment partners. Because ISO 42001 shares the ISO 27001 management-system structure, much of the groundwork carries straight over.

EU AI Act preparation

We help you prepare for the Act’s phased obligations. High-risk requirements for standalone systems now apply from December 2027 under the Digital Omnibus adopted in June 2026, but transparency duties land in 2026 and general-purpose AI rules are already live. Any UK organisation serving EU users can fall in scope, so this is a UK question too.

Shadow AI & acceptable use

Discover where AI is already being used across the business, put a clear acceptable-use policy in place, and reduce the risk of sensitive data leaking into public LLMs.

How we help

One team, accountable end to end.

AI governance fails when it is a one-off project that nobody owns afterwards. We run it as an ongoing programme, using the same continuous-compliance engine that keeps your other frameworks audit-ready, with Threat Protect as your single point of accountability throughout.

  1. 01

    Find out where you stand

    A short discovery across the business: where AI is already in use, which uses carry real risk, and what the Act and ISO 42001 would expect of each. You get a sized, specific list instead of an abstract worry.

  2. 02

    Build the governance

    Policy, risk assessment, human oversight and the documentation that evidences all three. Built on your existing management system wherever possible, so it is one framework more, not a parallel programme.

  3. 03

    Certify through assessment partners

    When you want the certificate, ISO 42001 assessment is delivered through certified assessment partners. We prepare you, manage the process and stay accountable for the outcome, so you deal with one team throughout.

  4. 04

    Keep it current

    Governance decays as the business adopts new tools and the rules move. Continuous compliance keeps the evidence live and the inventory accurate year-round, so the next audit is not a scramble.

Not sure where you stand?

Two minutes, eight questions, and an honest read on your scope and the gaps to close first.

Check your readiness

Dec 2027

The EU AI Act’s high-risk obligations for standalone (Annex III) systems apply from 2 December 2027, following the Digital Omnibus adopted in June 2026. Treat that as runway, not a reprieve: transparency duties still land in August 2026, and the governance behind them takes considerably longer to build than the dates suggest.

See the EU AI Act timeline & readiness steps

FAQ

Questions buyers ask

Short, straight answers to what boards and buyers ask most. Still need a steer on your own situation?

Book a call Read the full AI governance guide
  • It can. The Act has extraterritorial reach, so a UK organisation that provides or uses an AI system affecting people in the EU can fall in scope, even with no EU office. For many UK firms it is a UK question, not only an EU one.

A note on what this is and isn’t: we help you build audit-ready AI governance and prepare for the EU AI Act. ISO 42001 is a management-system standard and a commercial signal that procurement increasingly expects. It is not, on its own, legal compliance with the EU AI Act, and we don’t present it as such. We’ll always be clear about where readiness ends and legal advice begins.

Get ahead of the board’s AI question.

Tell us how AI is showing up in your organisation. We’ll map a path to audit-ready governance and EU AI Act readiness.

Book a call