You deployed AI faster than you governed it.

Almost everyone did. The work now is an inventory, a risk classification, and a control set you can show a regulator or an enterprise customer.

Why this is landing on your desk now

Three pressures arrived at once: the EU AI Act's obligations phasing in, enterprise customers adding AI questions to security reviews, and boards asking who owns AI risk. Most companies can answer none of the three, because nobody has written down where AI is actually being used.

The first deliverable is almost never a policy. It is an inventory. You cannot classify risk on systems you have not enumerated, and you cannot answer a customer questionnaire honestly without one.

What the engagement covers

AI use inventory

Enumerating every AI system in use — vendor features, embedded models, internal builds and shadow usage — with owner, purpose, data touched and deployment context recorded for each.

Risk classification

Classifying each use against the EU AI Act's risk tiers and against your own materiality thresholds, so effort concentrates where obligations actually attach.

EU AI Act readiness

Determining which obligations apply given your role as provider or deployer, and building the technical documentation, transparency notices, human oversight and record-keeping those obligations require.

NIST AI RMF alignment

Mapping your program to the Govern, Map, Measure and Manage functions — the framework most US enterprise customers and auditors will recognize.

Controls and evidence

Model approval workflows, vendor AI due diligence, data-handling boundaries, evaluation and monitoring requirements, and incident handling for AI-specific failure modes.

Customer and auditor answers

A defensible written position on AI use that survives a security questionnaire, a customer audit, or an ISO 27001 surveillance visit.

How this connects to what you already have

AI governance is not a separate program. It is a set of controls that belong inside the ISMS, the vendor risk process and the change management process you already run.

Where you hold ISO 27001, AI governance maps into your existing risk assessment, Statement of Applicability and internal audit cycle rather than sitting beside them. ISO/IEC 42001 is available as a certifiable AI management system standard if a customer demands it, but for most companies the cheaper and more useful first step is extending the ISMS you already maintain.

Be skeptical of anyone selling AI governance as a greenfield build. If it does not reuse your existing control framework, you will end up maintaining two of everything.

Start with the inventory

A scoped AI use inventory and risk classification is usually a two-to-four week engagement, and it is the input everything else depends on.

Start an inquiry