AI Services

Governance that survives being asked about

An AI policy nobody reads is not governance. We build the version that works: rules people can follow, classification that matches real risk, and an evidence trail that answers a procurement questionnaire, an ICO enquiry or an assessor without a fire drill.

  • Written for your regulator
  • Evidence, not intentions
  • Proportionate to real risk
Governance & Compliance in practice
The gap

Policy on the intranet, practice in the wild

The failure mode is almost never a missing document. It is a document with no connection to how work happens.

  • A policy written once, unread, and already out of date
  • No register of AI use cases, so risk cannot be classified or reviewed
  • DPIAs that were completed for the tool but not for how it is actually used
  • Customer and procurement questionnaires answered from memory each time
  • No incident route: nobody knows what to do when an AI output causes harm
What we put in place

Six things that make governance real

Proportionate by design. A 40-person firm and a 4,000-person authority need the same components at very different weights.

Policy people will actually follow

Short, specific and written for roles rather than for lawyers: what you may use, on what data, what must be checked, and what is never permitted. One page per role, not forty for everyone.

Use-case register and risk classification

Every AI use case recorded with purpose, data, owner and risk tier, reviewed on a schedule. This register is the spine everything else hangs from.

EU AI Act positioning

Where your systems sit in the risk tiers, which obligations apply to you as deployer or provider, and a staged plan against the timetable - for any organisation serving EU users or customers.

ISO/IEC 42001 alignment

The AI management system mapped onto your existing ISO 27001 or quality processes rather than built beside them, whether or not you pursue certification.

Data protection in practice

DPIAs for real usage, lawful basis, transparency wording, retention and the transfer position - aligned to current ICO guidance and written so your DPO can defend it.

Assurance and incident response

Monitoring, periodic review, a defined incident route with named owners, and a standing answer to customer due-diligence questions.

In practice

What working with us looks like

The engagement runs with the people who do the work, not around them. Sessions are short, scheduled around delivery, and every stage ends with something you can act on.

You get a named consultant for the whole engagement - the person in the room is the person doing the work.

Policy documents being reviewed
Photo: Unsplash
How it runs

From position to evidence

1

Establish the position

What you run, what applies to you, and what you can currently evidence. Where no audit exists, this stage includes one.

  • Obligations identified for your sector and markets
  • Current evidence tested, not assumed
2

Classify and prioritise

Use cases registered and risk-tiered, so effort goes where the exposure is instead of being spread evenly.

  • Risk tiers agreed with the business, not imposed
  • High-risk uses handled first
3

Build the framework

Policy, register, DPIAs, controls and the incident route - drafted with you, sized to your organisation.

  • Role-based policy pages people can read in five minutes
  • Controls mapped to existing ISO or assurance processes
4

Embed and rehearse

Training for staff and approvers, a walkthrough of the incident route, and a schedule that keeps the register alive.

  • Named owners and review dates
  • A dry run of the questions you will be asked
Deliverables

What you leave with

What you receive

  • AI policy set, written per role
  • Use-case register with risk classification and review schedule
  • EU AI Act position and staged readiness plan
  • ISO/IEC 42001 gap analysis mapped to existing controls
  • DPIAs and data protection position aligned to ICO guidance
  • Incident response route with named owners
  • A standing evidence pack for procurement and customer due diligence

Proportionality is the point

Over-governance fails the same way under-governance does: people route around it. The framework has to be light enough to survive contact with a busy week.

Most obligations already have a home. Your existing information governance, clinical governance, SRA or FCA processes usually extend to AI more cleanly than a parallel structure would.

The test we design to is simple: when a customer, an assessor or a regulator asks how a decision was made, someone can answer within a day, with evidence, without calling us.

Work we can name

CedarGuard: governance made operational, not documented

CedarGuard is a risk and compliance operating system for UK social housing delivery, built to the point where it is a live product at cedarguard.co.uk rather than a pilot that ended at a demo.

It is what this service looks like when it is built into the software rather than written beside it: obligations identified against the regulations that actually apply, decisions attributed to a named owner, and the evidence assembled as the work happens.

Read the CedarGuard case study

What it does

  • Matches statutory obligations to the project from a maintained regulations library
  • Generates a first-pass risk register for a named owner to accept or reject
  • Quantifies exposure as gross and residual Annual Loss Expectancy, in pounds
  • Tracks every risk against the organisation's stated risk appetite
  • Keeps an evidence trail built for the moment a regulator asks
  • Refuses to publish a project until a person has completed and confirmed setup
Where this fits

Related services and sectors

Questions

Questions about governance & compliance

Not automatically. It reaches organisations that place AI systems on the EU market or whose systems' output is used in the EU. Many UK organisations are unaffected, and many with EU customers are surprised to find they are in scope - the positioning exercise establishes which you are.
Only if your customers or your market require it. The management system underneath it is worth building either way; certification is a commercial decision, and we will tell you plainly when it would be an expensive badge.
We can, but it will be generic, and generic policy is the thing that fails. Governance built on a real inventory of what you run is a different document, and usually a shorter one.
Well-built governance speeds up the common cases by making them pre-approved, and slows down only the genuinely risky ones. If your framework is making routine work harder, it is badly designed.

Get the evidence position first

Governance built on an audit is quicker to produce, cheaper to maintain and much harder to pick apart.