Assurance

AI Governance

Someone has asked how you govern AI. This gives you an answer you can show them, and a framework that does not slow the business down

Staff use AI tools nobody approved. Teams put AI into customer-facing processes without a risk assessment. Nobody holds a list of where AI is actually in use.

This stays invisible until somebody asks. The question arrives in a supplier assurance questionnaire, a tender clause, an insurer’s renewal, an auditor’s finding or a board paper. At that point you need an answer in days.

The cost is rarely a fine. It is a lost deal, a delayed renewal, a qualified audit, or an AI project blocked indefinitely by a risk function with no basis on which to approve it.

3 days

to a complete AI inventory, every use case risk-tiered, and a costed twelve-month roadmap

What actually applies to a UK business

There is no UK AI Act. The UK regulates AI at the point of use, through the regulators you already answer to, with the Information Commissioner’s Office leading on data protection and explainability. What binds you today is UK GDPR and the Data Protection Act 2018, including impact assessments and the rules on automated decision-making, plus whatever your sector regulator expects.

The EU AI Act applies to you only if you place an AI system on the EU market, or if the output of your system is used in the EU. Many UK organisations are out of scope entirely.

If you are in scope, the dates have moved. The prohibitions have applied since February 2025 and the transparency rules from August 2026, but the high-risk obligations were deferred: December 2027 for stand-alone high-risk systems, August 2028 for AI inside regulated products.

The deadline moved. The obligation did not.

Most AI governance pitches you will read still quote the old dates. The organisations that use the extra time are the ones that will be ready.

Four pillars, six principles

  • Accountability

    Every AI system has a named business owner accountable for its outcomes.

  • Transparency

    Uses of AI are documented, explainable and disclosed where it matters.

  • Fairness

    Systems are tested for bias and unequal impact before and after launch.

  • Safety and security

    Models are secure, tested and resilient to misuse and attack.

  • Privacy

    Data use respects consent, minimisation and data-protection law.

  • Human oversight

    People stay in control of consequential decisions, with clear escalation.

  • Strategy and oversight

    • Director-level visibility of AI risk and value
    • A governance forum with a written charter
    • An approved AI position and risk appetite
  • Policies and standards

    • Enterprise AI policy and acceptable-use rules
    • Data, model and vendor standards
    • Documentation and disclosure requirements
  • Risk and compliance

    • Risk-based classification of every AI use case
    • Impact assessments for high-risk systems
    • Mapping to what actually binds you
  • Lifecycle controls

    • Approval gates from idea to deployment
    • Testing, validation and bias checks
    • Continuous monitoring and incident response

Controls scale with risk

Low-risk innovation moves quickly. High-risk systems get real scrutiny. The tier decides the control, not the other way round.

TierWhat it isExampleWhat it takes
ProhibitedUses the business will not pursueCovert manipulation, unlawful surveillanceBlocked at intake
High riskMaterial impact on people, money or safetyHiring screening, credit decisionsFull impact assessment, forum approval, human oversight
Limited riskCustomer-facing but lower stakesChatbots, content generationTransparency notices, standard review, owner sign-off
Minimal riskInternal productivity and analyticsDrafting aids, code assistantsRegister the use case, follow acceptable use

Governance built into the lifecycle, not bolted on

  1. Propose

    Use case registered in the AI inventory with a named owner.

  2. Assess

    Risk tier assigned, impact assessment for high-risk uses.

  3. Build

    Developed to data, security and documentation standards.

  4. Validate

    Tested for accuracy, bias, resilience and privacy before launch.

  5. Deploy

    Approval gate signed off at the level the tier requires.

  6. Monitor

    Performance and incidents tracked, periodic re-review.

The gate

Nothing reaches production without the approval matching its risk tier. Everything in production stays on the register and under monitoring.

Anchored to recognised standards

  • ISO/IEC 42001

    The international AI management system standard, and it is certifiable. UKAS granted its first accreditation under the AI management systems programme in January 2026, so UKAS-accredited certification is available in the UK. We prepare you for it. The certificate is issued by an accredited certification body, not by us.

  • NIST AI RMF

    A widely adopted framework for managing AI risk across four functions: govern, map, measure, manage. It shapes our risk method, and US-headquartered customers recognise it.

  • UK data protection law

    UK GDPR and the Data Protection Act 2018, including impact assessments and automated decision-making, plus your sector regulator. This is what binds you today.

We also work to ISO/IEC 23894 for AI risk management and ISO/IEC 42005 for impact assessment methodology, so the assessment you get has a citable basis rather than an in-house invention.

What We Deliver

  • An AI inventory: every use case, with a named business owner against each one
  • Risk tiering so controls scale with consequence rather than applying to everything equally
  • An enterprise AI policy and acceptable-use rules people can actually follow
  • A governance forum with a written charter and approval gates that match the tier
  • Impact assessments for high-risk systems, on a method with a citable basis
  • A plain statement of which regulations bind you, and which do not

What it takes, by size of business

DimensionSmallMediumLarge
ProfileUp to around 50 staff, a handful of AI use casesAround 50 to 500 staff, AI in several functions500 or more staff, regulated or high-risk AI at scale
TotalAround 18 days over 12 monthsAround 38 days over 12 monthsAround 70 days over 12 months
Phase 1, Foundation6 days12 days20 days
Phase 2, Operationalise8 days16 days30 days
Phase 3, Scale and assure4 days10 days20 days
Governance Foundation price£7,500 fixed£14,500 fixed£24,000 fixed
Run and Hold£1,250 per month£1,950 per month£3,250 per month
ShapeSingle forum doubles as review board, light-touch tieringFull forum and gates, training for priority teamsMultiple business units, audit and ISO 42001 readiness

Indicative effort for the twelve-month roadmap, confirmed after the assessment. Foundation is phase one and is fixed price. Phases two and three are priced on what the assessment finds.

Engagements & Pricing

Clear deliverables, timelines, and investment levels. No hidden costs.

AI Governance Assessment

A populated AI use-case inventory, every use case risk-tiered, a gap analysis against ISO/IEC 42001 and NIST AI RMF, a plain statement of which regulations actually bind you, and a costed twelve-month roadmap.

£3,500 fixeddelivered within 3 days

Governance Run and Hold

Forum secretariat, quarterly risk reporting, re-review of use cases as they change, policy updates as regulation moves, and an annual internal review against the framework.

£1,250 a month6-month minimum

Engagements are fixed-price against a stated effort estimate. Effort is what we commit to deliver in, not a day count we bill against. All prices exclude VAT, charged at the prevailing rate.

Governance engagements are delivered at specialist rates rather than our blended day-rate basis, so each tier publishes a fixed price and a delivery window rather than an effort-day figure. The effort in the table above is the delivery model’s own estimate, not a figure worked back from the price.

Not sure which tier fits? Start with the free AI readiness checklist, or the £499 AI Opportunity Report: one call, then a written answer on where AI pays, before you commit to a build.

What we do not do

We design and implement governance. We do not give legal advice, we do not issue certifications, and we do not provide clinical safety sign-off. Where any of those is needed, we say so and tell you what it requires.

Frequently Asked Questions

Does the EU AI Act apply to my UK business?

Only if you place an AI system on the EU market, or the output of your system is used in the EU. Many UK organisations are out of scope entirely. The assessment establishes which position you are in before anyone designs anything around it.

Is there a UK AI Act we need to comply with?

No. The UK regulates AI at the point of use through existing regulators rather than through a single AI statute. What binds you today is UK GDPR and the Data Protection Act 2018, plus your sector regulator’s expectations.

Do we need ISO 42001 certification?

Not necessarily. Certification is worth pursuing when customers, insurers or procurement teams are asking for evidence you cannot otherwise provide. The assessment tells you whether it is worth the cost in your case, and we prepare you for it if it is. The certificate itself is issued by an accredited certification body.

We already have an AI policy. Is this still relevant?

Usually yes, because a policy on its own does not govern anything. The work is the inventory of what is actually in use, the risk tiering of those specific use cases, and the approval gates that make the policy bite. A policy with no register behind it governs nothing.

Will this slow our teams down?

It should speed most of them up. The point of risk tiering is that minimal-risk work gets registered and proceeds, rather than waiting in a queue behind a blanket review. The scrutiny is reserved for the systems that carry real consequence.

Can you help us answer AI questions in a tender or supplier questionnaire?

Yes. It is one of the most common reasons organisations look for governance help. If you are working to a deadline, say so when you book the call and we will tell you honestly whether three days is enough to get you a defensible answer in time.

How much does AI governance cost?

The AI Governance Assessment is £3,500 fixed: three days producing the inventory, the risk tiering, the standards gap analysis and a costed twelve-month roadmap. It is credited in full against Governance Foundation if you proceed within 30 days. Governance Foundation is fixed price by size of business: £7,500 small, £14,500 medium, £24,000 large. Governance Run and Hold runs from £1,250 a month on a six-month minimum. Phases two and three are priced on what the assessment finds, not guessed in advance, and any tooling, registry or monitoring licence costs are stated separately from our fee, always. Public sector buyers purchase via G-Cloud at SFIA rates rather than this ladder.

Ready to Talk AI Governance?

Book a free discovery call. We'll tell you honestly what's worth doing and what it will cost.

Book Your Free Discovery Call

Not ready for a call? Take the free AI readiness checklist. Ten questions, five minutes, scored instantly.