AI Governance
From board oversight to regulatory readiness
We help boards and executives govern AI with the same rigor as financial reporting — governance frameworks, responsible AI programmes, and the reporting lines that make oversight real rather than nominal.
What this covers
Four governance capabilities
Board oversight
The questions a board should be able to answer
Directors are not expected to understand gradient descent. They are expected to know which AI systems the organisation depends on, what happens when those systems are wrong, and who is accountable. Most boards cannot yet answer the second question.
Our governance research- Inventory
- Which AI systems are in use, including those acquired inside vendor products and those built by business units without central approval?
- Materiality
- Which of them, if wrong or unavailable, would cause material financial, regulatory, safety, or reputational harm?
- Accountability
- Who owns each system, and does that person have the authority to stop it?
- Evidence
- What independent evidence exists that the material systems perform as claimed — and how old is it?
- Escalation
- What triggers a report to the board, and has that threshold ever actually been met and reported?
Standards
Built on established management-system practice
ISO/IEC 42001 supplies the management-system spine; ISO/IEC 23894 and ISO 31000 connect AI risk to enterprise risk; the NIST AI RMF supplies the functional decomposition.
- ISO/IEC 42001:2023
- Artificial intelligence management system (AIMS) — the certifiable organisational standard for governing AI.
- ISO/IEC 23894:2023
- Guidance on AI risk management, aligning AI-specific risk to the ISO 31000 process.
- ISO 31000:2018
- The enterprise risk management framework AI risk must fold into rather than sit beside.
- NIST AI RMF 1.0
- The Govern, Map, Measure, Manage functions, plus the Generative AI Profile (NIST AI 600-1).
- IEEE 7000-series
- Standards for addressing ethical concerns during system design.
Programme build
Standing up an AI governance programme
-
Discovery and inventory
Establish what AI is actually in use — including embedded AI inside purchased software, which is where most inventories are wrong.
-
Materiality tiering
Classify systems by consequence, so oversight effort lands on the systems that can cause harm rather than on the ones that are easiest to document.
-
Framework design
Policies, standards, roles, approval gates, and escalation thresholds — written to be enforceable, not aspirational.
-
Operationalisation
Embedding the gates into the delivery lifecycle so governance is a condition of release rather than a document produced afterwards.
-
Assurance and reporting
Independent testing of whether the framework is followed, and reporting that reaches the board in a form it can act on.
Related capabilities
Deploy AI with confidence.
Start with an independent assessment of your highest-stakes AI system.