AI Governance & Assurance
Govern your own AI with confidence.
Boards are asking a new question: are we governing our own use of AI safely and compliantly? We help you answer it, with audit-ready AI governance, ISO 42001 readiness and EU AI Act preparation.
In plain English
What AI governance actually means.
AI governance is the set of policies, controls and evidence an organisation uses to make sure the AI it builds, buys and uses is safe, lawful and accountable. In practice it means knowing where AI is used, classifying the risk each system carries, putting controls and human oversight in place, and keeping the documentation that proves it, to a standard an auditor, regulator or customer will accept.
What we help with
Three ways to get your AI house in order.
ISO 42001 readiness & certification
The AI Management System standard. We get you ready and certification is delivered through certified assessment partners. Because ISO 42001 shares the ISO 27001 management-system structure, much of the groundwork carries straight over.
EU AI Act preparation
We help you prepare for the Act’s phased obligations. High-risk requirements for standalone systems now apply from December 2027 under the Digital Omnibus adopted in June 2026, but transparency duties land in 2026 and general-purpose AI rules are already live. Any UK organisation serving EU users can fall in scope, so this is a UK question too.
Shadow AI & acceptable use
Discover where AI is already being used across the business, put a clear acceptable-use policy in place, and reduce the risk of sensitive data leaking into public LLMs.
How we help
One team, accountable end to end.
AI governance fails when it is a one-off project that nobody owns afterwards. We run it as an ongoing programme, using the same continuous-compliance engine that keeps your other frameworks audit-ready, with Threat Protect as your single point of accountability throughout.
- 01
Find out where you stand
A short discovery across the business: where AI is already in use, which uses carry real risk, and what the Act and ISO 42001 would expect of each. You get a sized, specific list instead of an abstract worry.
- 02
Build the governance
Policy, risk assessment, human oversight and the documentation that evidences all three. Built on your existing management system wherever possible, so it is one framework more, not a parallel programme.
- 03
Certify through assessment partners
When you want the certificate, ISO 42001 assessment is delivered through certified assessment partners. We prepare you, manage the process and stay accountable for the outcome, so you deal with one team throughout.
- 04
Keep it current
Governance decays as the business adopts new tools and the rules move. Continuous compliance keeps the evidence live and the inventory accurate year-round, so the next audit is not a scramble.
Not sure where you stand?
Two minutes, eight questions, and an honest read on your scope and the gaps to close first.
Dec 2027
The EU AI Act’s high-risk obligations for standalone (Annex III) systems apply from 2 December 2027, following the Digital Omnibus adopted in June 2026. Treat that as runway, not a reprieve: transparency duties still land in August 2026, and the governance behind them takes considerably longer to build than the dates suggest.
See the EU AI Act timeline & readiness stepsFAQ
Questions buyers ask
Short, straight answers to what boards and buyers ask most. Still need a steer on your own situation?
Book a call Read the full AI governance guide- It can. The Act has extraterritorial reach, so a UK organisation that provides or uses an AI system affecting people in the EU can fall in scope, even with no EU office. For many UK firms it is a UK question, not only an EU one.
- There is no legal requirement to hold it. It matters as a commercial signal, because procurement teams and customers increasingly ask for it as proof that AI is governed responsibly. If you already hold ISO 27001, much of the groundwork carries straight over because the two share the same management-system structure.
- With an inventory. You cannot govern, classify or evidence AI you cannot see. Start with a clear picture of where AI is used across the business, then risk classification, then the controls and documentation that match. Most organisations still lack this baseline, which makes it the cheapest, highest-value place to begin.
A note on what this is and isn’t: we help you build audit-ready AI governance and prepare for the EU AI Act. ISO 42001 is a management-system standard and a commercial signal that procurement increasingly expects. It is not, on its own, legal compliance with the EU AI Act, and we don’t present it as such. We’ll always be clear about where readiness ends and legal advice begins.
Get ahead of the board’s AI question.
Tell us how AI is showing up in your organisation. We’ll map a path to audit-ready governance and EU AI Act readiness.
Book a call