Why this is landing on your desk now
Three pressures arrived at once: the EU AI Act's obligations phasing in, enterprise customers adding AI questions to security reviews, and boards asking who owns AI risk. Most companies can answer none of the three, because nobody has written down where AI is actually being used.
The first deliverable is almost never a policy. It is an inventory. You cannot classify risk on systems you have not enumerated, and you cannot answer a customer questionnaire honestly without one.
What the engagement covers
AI use inventory
Enumerating every AI system in use — vendor features, embedded models, internal builds and shadow usage — with owner, purpose, data touched and deployment context recorded for each.
Risk classification
Classifying each use against the EU AI Act's risk tiers and against your own materiality thresholds, so effort concentrates where obligations actually attach.
EU AI Act readiness
Determining which obligations apply given your role as provider or deployer, and building the technical documentation, transparency notices, human oversight and record-keeping those obligations require.
NIST AI RMF alignment
Mapping your program to the Govern, Map, Measure and Manage functions — the framework most US enterprise customers and auditors will recognize.
Controls and evidence
Model approval workflows, vendor AI due diligence, data-handling boundaries, evaluation and monitoring requirements, and incident handling for AI-specific failure modes.
Customer and auditor answers
A defensible written position on AI use that survives a security questionnaire, a customer audit, or an ISO 27001 surveillance visit.
How this connects to what you already have
AI governance is not a separate program. It is a set of controls that belong inside the ISMS, the vendor risk process and the change management process you already run.
Where you hold ISO 27001, AI governance maps into your existing risk assessment, Statement of Applicability and internal audit cycle rather than sitting beside them. ISO/IEC 42001 is available as a certifiable AI management system standard if a customer demands it, but for most companies the cheaper and more useful first step is extending the ISMS you already maintain.
Be skeptical of anyone selling AI governance as a greenfield build. If it does not reuse your existing control framework, you will end up maintaining two of everything.
Start with the inventory
A scoped AI use inventory and risk classification is usually a two-to-four week engagement, and it is the input everything else depends on.