Move fast on AI, defensibly

AI Governance & Secure AI Adoption

A governance model that lets your teams ship AI instead of waiting for permission , built on NIST AI RMF and ISO 42001, with real controls for model, data and agent risk rather than a policy nobody reads.

The situation

AI is already in production; the governance is not

  • Teams are shipping LLM features and legal found out from the changelog.
  • Customers are sending AI-specific security questionnaires you can't yet answer.
  • Nobody can say what data leaves the building through which model, on what terms.

What we do

  • Inventory AI use across the business: including the shadow usage that already exists
  • Stand up an AI governance framework on NIST AI RMF and ISO/IEC 42001
  • Define an intake and risk-tiering process that approves low-risk use in days, not quarters
  • Threat model AI systems: prompt injection, data leakage, model and agent abuse (OWASP LLM Top 10)
  • Set data handling rules for training, fine-tuning, RAG corpora and vendor retention terms
  • Review AI vendor and model contracts for the terms that actually matter
  • Design controls for agentic systems: tool permissions, human-in-the-loop, blast radius, audit trail
  • Prepare for the AI clauses now appearing in SOC 2, ISO and enterprise customer reviews
Deliverables

What you actually receive.

Artefacts your team can operate after we leave, not a slide deck and a wave goodbye.

DeliverableWhat it contains
AI use inventoryWhat's running, who owns it, what data it touches, what the exposure is
AI governance frameworkPolicy, standards, risk tiers and the approval path, mapped to ISO 42001
AI threat modelsPer high-risk system, with mitigations and residual risk written down
Control set for AIData, model, prompt, output and agent controls that engineering can implement
Vendor review standardThe questions and contract terms to require of every AI vendor
Customer-facing AI trust contentAnswers to the AI questionnaire before it arrives
Ways to engage

Sized to the problem in front of you.

2–4 weeks

AI risk baseline

Inventory, risk tiering and the top exposures with fixes.

6–12 weeks

Governance build

Full framework, intake process and control set operationalised.

4–9 months

ISO 42001 program

Certification-track AI management system, run end to end.

Talk it through with someone senior

Thirty minutes on your situation specifically, what is driving the timeline, what you have already tried, and what we would do first.