AI Governance
Someone has asked how you govern AI. This gives you an answer you can show them, and a framework that does not slow the business down

Staff use AI tools nobody approved. Teams put AI into customer-facing processes without a risk assessment. Nobody holds a list of where AI is actually in use.
This stays invisible until somebody asks. The question arrives in a supplier assurance questionnaire, a tender clause, an insurer’s renewal, an auditor’s finding or a board paper. At that point you need an answer in days.
The cost is rarely a fine. It is a lost deal, a delayed renewal, a qualified audit, or an AI project blocked indefinitely by a risk function with no basis on which to approve it.
What actually applies to a UK business
There is no UK AI Act. The UK regulates AI at the point of use, through the regulators you already answer to, with the Information Commissioner’s Office leading on data protection and explainability. What binds you today is UK GDPR and the Data Protection Act 2018, including impact assessments and the rules on automated decision-making, plus whatever your sector regulator expects.
The EU AI Act applies to you only if you place an AI system on the EU market, or if the output of your system is used in the EU. Many UK organisations are out of scope entirely.
If you are in scope, the dates have moved. The prohibitions have applied since February 2025 and the transparency rules from August 2026, but the high-risk obligations were deferred: December 2027 for stand-alone high-risk systems, August 2028 for AI inside regulated products.
The deadline moved. The obligation did not.
Most AI governance pitches you will read still quote the old dates. The organisations that use the extra time are the ones that will be ready.
Four pillars, six principles
Accountability
Every AI system has a named business owner accountable for its outcomes.
Transparency
Uses of AI are documented, explainable and disclosed where it matters.
Fairness
Systems are tested for bias and unequal impact before and after launch.
Safety and security
Models are secure, tested and resilient to misuse and attack.
Privacy
Data use respects consent, minimisation and data-protection law.
Human oversight
People stay in control of consequential decisions, with clear escalation.
Strategy and oversight
- Director-level visibility of AI risk and value
- A governance forum with a written charter
- An approved AI position and risk appetite
Policies and standards
- Enterprise AI policy and acceptable-use rules
- Data, model and vendor standards
- Documentation and disclosure requirements
Risk and compliance
- Risk-based classification of every AI use case
- Impact assessments for high-risk systems
- Mapping to what actually binds you
Lifecycle controls
- Approval gates from idea to deployment
- Testing, validation and bias checks
- Continuous monitoring and incident response
Controls scale with risk
Low-risk innovation moves quickly. High-risk systems get real scrutiny. The tier decides the control, not the other way round.
| Tier | What it is | Example | What it takes |
|---|---|---|---|
| Prohibited | Uses the business will not pursue | Covert manipulation, unlawful surveillance | Blocked at intake |
| High risk | Material impact on people, money or safety | Hiring screening, credit decisions | Full impact assessment, forum approval, human oversight |
| Limited risk | Customer-facing but lower stakes | Chatbots, content generation | Transparency notices, standard review, owner sign-off |
| Minimal risk | Internal productivity and analytics | Drafting aids, code assistants | Register the use case, follow acceptable use |
Governance built into the lifecycle, not bolted on
Propose
Use case registered in the AI inventory with a named owner.
Assess
Risk tier assigned, impact assessment for high-risk uses.
Build
Developed to data, security and documentation standards.
Validate
Tested for accuracy, bias, resilience and privacy before launch.
Deploy
Approval gate signed off at the level the tier requires.
Monitor
Performance and incidents tracked, periodic re-review.
The gate
Nothing reaches production without the approval matching its risk tier. Everything in production stays on the register and under monitoring.
Anchored to recognised standards
ISO/IEC 42001
The international AI management system standard, and it is certifiable. UKAS granted its first accreditation under the AI management systems programme in January 2026, so UKAS-accredited certification is available in the UK. We prepare you for it. The certificate is issued by an accredited certification body, not by us.
NIST AI RMF
A widely adopted framework for managing AI risk across four functions: govern, map, measure, manage. It shapes our risk method, and US-headquartered customers recognise it.
UK data protection law
UK GDPR and the Data Protection Act 2018, including impact assessments and automated decision-making, plus your sector regulator. This is what binds you today.
We also work to ISO/IEC 23894 for AI risk management and ISO/IEC 42005 for impact assessment methodology, so the assessment you get has a citable basis rather than an in-house invention.
What We Deliver
- An AI inventory: every use case, with a named business owner against each one
- Risk tiering so controls scale with consequence rather than applying to everything equally
- An enterprise AI policy and acceptable-use rules people can actually follow
- A governance forum with a written charter and approval gates that match the tier
- Impact assessments for high-risk systems, on a method with a citable basis
- A plain statement of which regulations bind you, and which do not
What it takes, by size of business
| Dimension | Small | Medium | Large |
|---|---|---|---|
| Profile | Up to around 50 staff, a handful of AI use cases | Around 50 to 500 staff, AI in several functions | 500 or more staff, regulated or high-risk AI at scale |
| Total | Around 18 days over 12 months | Around 38 days over 12 months | Around 70 days over 12 months |
| Phase 1, Foundation | 6 days | 12 days | 20 days |
| Phase 2, Operationalise | 8 days | 16 days | 30 days |
| Phase 3, Scale and assure | 4 days | 10 days | 20 days |
| Governance Foundation price | £7,500 fixed | £14,500 fixed | £24,000 fixed |
| Run and Hold | £1,250 per month | £1,950 per month | £3,250 per month |
| Shape | Single forum doubles as review board, light-touch tiering | Full forum and gates, training for priority teams | Multiple business units, audit and ISO 42001 readiness |
Indicative effort for the twelve-month roadmap, confirmed after the assessment. Foundation is phase one and is fixed price. Phases two and three are priced on what the assessment finds.
Engagements & Pricing
Clear deliverables, timelines, and investment levels. No hidden costs.
AI Governance Assessment
A populated AI use-case inventory, every use case risk-tiered, a gap analysis against ISO/IEC 42001 and NIST AI RMF, a plain statement of which regulations actually bind you, and a costed twelve-month roadmap.
Governance Foundation
Phase one of the roadmap delivered: charter and AI policy approved, the governance forum standing, the inventory built, acceptable-use rules published.
Governance Run and Hold
Forum secretariat, quarterly risk reporting, re-review of use cases as they change, policy updates as regulation moves, and an annual internal review against the framework.
Engagements are fixed-price against a stated effort estimate. Effort is what we commit to deliver in, not a day count we bill against. All prices exclude VAT, charged at the prevailing rate.
Governance engagements are delivered at specialist rates rather than our blended day-rate basis, so each tier publishes a fixed price and a delivery window rather than an effort-day figure. The effort in the table above is the delivery model’s own estimate, not a figure worked back from the price.
Not sure which tier fits? Start with the free AI readiness checklist, or the £499 AI Opportunity Report: one call, then a written answer on where AI pays, before you commit to a build.
What we do not do
We design and implement governance. We do not give legal advice, we do not issue certifications, and we do not provide clinical safety sign-off. Where any of those is needed, we say so and tell you what it requires.
Frequently Asked Questions
Does the EU AI Act apply to my UK business?
Only if you place an AI system on the EU market, or the output of your system is used in the EU. Many UK organisations are out of scope entirely. The assessment establishes which position you are in before anyone designs anything around it.
Is there a UK AI Act we need to comply with?
No. The UK regulates AI at the point of use through existing regulators rather than through a single AI statute. What binds you today is UK GDPR and the Data Protection Act 2018, plus your sector regulator’s expectations.
Do we need ISO 42001 certification?
Not necessarily. Certification is worth pursuing when customers, insurers or procurement teams are asking for evidence you cannot otherwise provide. The assessment tells you whether it is worth the cost in your case, and we prepare you for it if it is. The certificate itself is issued by an accredited certification body.
We already have an AI policy. Is this still relevant?
Usually yes, because a policy on its own does not govern anything. The work is the inventory of what is actually in use, the risk tiering of those specific use cases, and the approval gates that make the policy bite. A policy with no register behind it governs nothing.
Will this slow our teams down?
It should speed most of them up. The point of risk tiering is that minimal-risk work gets registered and proceeds, rather than waiting in a queue behind a blanket review. The scrutiny is reserved for the systems that carry real consequence.
Can you help us answer AI questions in a tender or supplier questionnaire?
Yes. It is one of the most common reasons organisations look for governance help. If you are working to a deadline, say so when you book the call and we will tell you honestly whether three days is enough to get you a defensible answer in time.
How much does AI governance cost?
The AI Governance Assessment is £3,500 fixed: three days producing the inventory, the risk tiering, the standards gap analysis and a costed twelve-month roadmap. It is credited in full against Governance Foundation if you proceed within 30 days. Governance Foundation is fixed price by size of business: £7,500 small, £14,500 medium, £24,000 large. Governance Run and Hold runs from £1,250 a month on a six-month minimum. Phases two and three are priced on what the assessment finds, not guessed in advance, and any tooling, registry or monitoring licence costs are stated separately from our fee, always. Public sector buyers purchase via G-Cloud at SFIA rates rather than this ladder.
Governance in your sector
- HealthcareDTAC, DCB0129 and DCB0160, and DSPT interlock
- Financial servicesmodel risk, consumer duty, operational resilience
- Policing and justiceautomated decision-making, disclosure and public scrutiny
- Local governmentequality duty, transparency and procurement
- Enterprisesupplier questionnaires, insurer questions and audit
- SMEs and mid-marketgovernance that fits the size of the business


Ready to Talk AI Governance?
Book a free discovery call. We'll tell you honestly what's worth doing and what it will cost.
Book Your Free Discovery CallNot ready for a call? Take the free AI readiness checklist. Ten questions, five minutes, scored instantly.