NEW The 2026 State of AI Trust Report is now available. Read the report →

AI Governance

From board oversight to regulatory readiness

We help boards and executives govern AI with the same rigor as financial reporting — governance frameworks, responsible AI programmes, and the reporting lines that make oversight real rather than nominal.

What this covers

Four governance capabilities

Governance frameworks & policies The operating model: who may approve an AI system, on what evidence, with what escalation, and who is accountable when it fails.
Board advisory Briefings and structured sessions that give directors enough technical grounding to ask the questions their duty requires.
Responsible AI & ethics Principles translated into decisions — review gates, prohibited uses, redress routes, and the record that shows they were applied.
Risk governance AI risk folded into the enterprise risk framework the organisation already runs, rather than maintained as a parallel exercise nobody reads.

Board oversight

The questions a board should be able to answer

Directors are not expected to understand gradient descent. They are expected to know which AI systems the organisation depends on, what happens when those systems are wrong, and who is accountable. Most boards cannot yet answer the second question.

Our governance research
Inventory
Which AI systems are in use, including those acquired inside vendor products and those built by business units without central approval?
Materiality
Which of them, if wrong or unavailable, would cause material financial, regulatory, safety, or reputational harm?
Accountability
Who owns each system, and does that person have the authority to stop it?
Evidence
What independent evidence exists that the material systems perform as claimed — and how old is it?
Escalation
What triggers a report to the board, and has that threshold ever actually been met and reported?

Standards

Built on established management-system practice

ISO/IEC 42001 supplies the management-system spine; ISO/IEC 23894 and ISO 31000 connect AI risk to enterprise risk; the NIST AI RMF supplies the functional decomposition.

ISO/IEC 42001:2023
Artificial intelligence management system (AIMS) — the certifiable organisational standard for governing AI.
ISO/IEC 23894:2023
Guidance on AI risk management, aligning AI-specific risk to the ISO 31000 process.
ISO 31000:2018
The enterprise risk management framework AI risk must fold into rather than sit beside.
NIST AI RMF 1.0
The Govern, Map, Measure, Manage functions, plus the Generative AI Profile (NIST AI 600-1).
IEEE 7000-series
Standards for addressing ethical concerns during system design.

Programme build

Standing up an AI governance programme

  1. Discovery and inventory

    Establish what AI is actually in use — including embedded AI inside purchased software, which is where most inventories are wrong.

  2. Materiality tiering

    Classify systems by consequence, so oversight effort lands on the systems that can cause harm rather than on the ones that are easiest to document.

  3. Framework design

    Policies, standards, roles, approval gates, and escalation thresholds — written to be enforceable, not aspirational.

  4. Operationalisation

    Embedding the gates into the delivery lifecycle so governance is a condition of release rather than a document produced afterwards.

  5. Assurance and reporting

    Independent testing of whether the framework is followed, and reporting that reaches the board in a form it can act on.

Deploy AI with confidence.

Start with an independent assessment of your highest-stakes AI system.