AI Transformation · Enterprise AI Integration
AI Governance & Risk Management
We set up the policies, inventory, risk assessment, testing and oversight that let you use AI with confidence, organized by the NIST AI Risk Management Framework and scaled to the risk of each system.
The control map
NIST AI RMF
GovernRuns through all three
- Policies and accountability
- AI system inventory
- Roles and training
Map
What could go wrong?
- Context and intended use
- Risks identified
- Impact on people
Measure
How likely, how serious?
- Evaluation and testing
- Fairness and robustness
- Monitoring
Manage
What do we do about it?
- Treatment and approval
- Incident response
- Retirement
Every AI system you build or buy, placed on one map, with an owner for each control.

How to get started
Three steps to a plan for AI Governance & Risk Management
- 1Tell us what you needUse the project form or book a call. A few sentences about the goal is enough to start.
- 2Free technical consultationWe go through your goals, users, existing systems and constraints with you.
- 3Your planA detailed plan covering the right tech stack, architecture, timeline and budget. Then you decide.
Risk tiers
Governance in proportion to the risk
A system's tier is set by what happens if it is wrong: who is affected, how seriously, and whether it can be undone. Choose a tier to see what it requires.
For example
- Customer-facing assistants
- Document processing in finance
- AI suggestions behind internal decisions
Review before launch
A risk assessment and an evaluation report before launch.
Controls
- An evaluation set with agreed thresholds
- A person reviewing a sample of outputs
- Monitoring with alerts
- An incident process
What we guard against
Eight risks, and the control for each
Built into every AI system we deliver, and checked in the systems we review.
- Wrong answersConfident answers that aren't supported by your sources.Answers grounded in your content with citations, and scored on an evaluation test set before every release.
- Data leaksPersonal or confidential data reaching the wrong people or a provider.Permission-aware retrieval, redaction of personal data, and provider terms that exclude your data from training.
- Misuse and attacksPrompt injection, attempts to get around the rules, and attacks on connected tools.Security testing before launch, tools with the minimum permissions, and approvals for consequential actions.
- Unfair resultsModels or assistants that perform worse for some groups of customers.Results compared across groups in the evaluation report, with fixes before launch.
- Over-reliancePeople acting on outputs without checking them.A person's review at consequential steps, with the sources or factors behind each output shown.
- Harmful contentOffensive or unsafe output reaching customers.Content filters and refusal testing before launch.
- Rising costUsage and model spend growing faster than expected.Usage and cost monitoring by team and feature, with limits and caching.
- Model changesA provider's model update changing behaviour without warning.Pinned model versions, re-evaluated on your test set before any upgrade.
The first step
Governance Readiness Review
A review of how your organization governs AI today, against the NIST AI Risk Management Framework, ending with the gaps and a plan to close them.
Who takes part
- Executive sponsor
- Risk and compliance
- Legal
- Security and privacy
- Data and AI leads
- 1InventoryThe AI systems and tools in use, including those bought or built into other software, with their owners.
- 2Policy and control reviewYour policies, approvals and controls, compared with the framework's four functions.
- 3Risk samplingA sample of systems assessed in depth: their data, testing, human oversight and monitoring.
- 4Gaps and planThe gaps ranked by risk, with a governance model and the work to close them.
How it runs
You leave with
- An inventory of AI systems, with owners
- A gap assessment against the NIST AI RMF
- A risk-tiering method for your systems
- A prioritized plan and governance model
Deliverables
What you receive
- An AI policy and acceptable use standard
- An AI system inventory, with owners and risk tiers
- A risk-tiering method and assessment templates
- Governance committee terms and an approval workflow
- Documentation standards: model and system cards
- Evaluation and testing standards for each tier
- Monitoring and incident response procedures
- Assessment criteria for AI bought from vendors
Alongside governance
Where the work goes next
- AI ConsultingAI Adoption & Change ManagementTurn the policy into rules people can follow, and train them on it.
- AI Product EngineeringMLOps & AI OperationsProduce the monitoring evidence and incident records the governance model relies on.
- AI ConsultingAI Readiness AssessmentCheck the rest of your readiness: data, technology, skills and adoption.
Questions
Questions about
AI Governance & Risk Management
Will this make us compliant?
Governance helps you meet your obligations, but we don't certify compliance. We map your controls to the frameworks, sector rules and laws you name, for your legal advisers to confirm which apply and whether the controls satisfy them.
Why the NIST AI Risk Management Framework?
It is a voluntary framework from the US National Institute of Standards and Technology, widely used to manage AI risk, and it fits alongside existing risk and compliance processes. Controls can also be mapped to ISO/IEC 42001 if you plan to certify an AI management system.
Does this cover AI we buy, not just AI we build?
Yes. Vendor tools and AI built into software you already use are included in the inventory, assessed by risk tier, and checked for their data use and contract terms.
Won't governance slow us down?
Not if it follows the risk. Low-risk uses go through a light process, so the effort of review and testing is spent where a wrong answer would matter most.
How is a project priced?
Well-defined scopes are delivered as fixed-price engagements; when requirements are still evolving, we provide a dedicated team instead. Either way, the free technical consultation ends with a plan covering tech stack, architecture, timeline and budget, so you know the cost before work starts.
Enterprise AI Integration
Other services in this line
- Data Foundations for AIPipelines, quality checks and access controls that make your data usable by AI systems.
- AI Integration & Legacy ModernizationAI connected to your ERP, CRM and core systems through APIs, and the older systems that block it modernized.
Ready to talk about AI Governance & Risk Management?
Start with a free technical consultation: a plan covering the right approach, architecture, timeline and budget for your AI work.
Start a project