Service / 08
AI Governance
We build the governance layer that lets an organisation use AI and prove it is in control: policies, review gates, model inventories, and audit trails. It is designed with regulation in view — and with engineers at the table, so the controls are technical, not theatrical.
When you need this
The situations we are called into.
Regulators or auditors have asked how you control the AI already in production, and the answer is thin.
Model use has spread informally and no inventory says what runs where, on whose data.
Procurement, risk, and engineering each block AI adoption for different, unreconciled reasons.
Approach
How the engagement runs.
Inventory and classification
Every model and AI-dependent system catalogued and risk-classified against applicable regulation.
Policy framework
Acceptable use, procurement, data handling, and incident policies — short enough to be read.
Control design
Technical controls enforced in the platform — logging, access, evaluation gates — not only in documents.
Process installation
Review committees, approval gates, and exception handling with named owners and defined turnaround.
Audit rehearsal
A dry-run audit against the framework, so the first real one holds no surprises.
Deliverables
What you hold at the end.
Model and system inventory
AI policy set
Control catalogue mapped to regulation
Review-gate process with owners
Audit evidence pack
Related research
The evidence behind this practice.
Technical report · 2026
Evaluating large language models for regulated enterprise workflows
A practical evaluation framework for LLM systems in banking, insurance, and government contexts — metrics, test harnesses, and a taxonomy of failure modes.
In preparation
Contact
Talk to our engineers.
Describe the situation you are in. The person who replies is the person who would do the work.