AI Governance & Secure AI Adoption
A governance model that lets your teams ship AI instead of waiting for permission , built on NIST AI RMF and ISO 42001, with real controls for model, data and agent risk rather than a policy nobody reads.
AI is already in production; the governance is not
- Teams are shipping LLM features and legal found out from the changelog.
- Customers are sending AI-specific security questionnaires you can't yet answer.
- Nobody can say what data leaves the building through which model, on what terms.
What we do
- Inventory AI use across the business: including the shadow usage that already exists
- Stand up an AI governance framework on NIST AI RMF and ISO/IEC 42001
- Define an intake and risk-tiering process that approves low-risk use in days, not quarters
- Threat model AI systems: prompt injection, data leakage, model and agent abuse (OWASP LLM Top 10)
- Set data handling rules for training, fine-tuning, RAG corpora and vendor retention terms
- Review AI vendor and model contracts for the terms that actually matter
- Design controls for agentic systems: tool permissions, human-in-the-loop, blast radius, audit trail
- Prepare for the AI clauses now appearing in SOC 2, ISO and enterprise customer reviews
What you actually receive.
Artefacts your team can operate after we leave, not a slide deck and a wave goodbye.
| Deliverable | What it contains |
|---|---|
| AI use inventory | What's running, who owns it, what data it touches, what the exposure is |
| AI governance framework | Policy, standards, risk tiers and the approval path, mapped to ISO 42001 |
| AI threat models | Per high-risk system, with mitigations and residual risk written down |
| Control set for AI | Data, model, prompt, output and agent controls that engineering can implement |
| Vendor review standard | The questions and contract terms to require of every AI vendor |
| Customer-facing AI trust content | Answers to the AI questionnaire before it arrives |
Sized to the problem in front of you.
AI risk baseline
Inventory, risk tiering and the top exposures with fixes.
Governance build
Full framework, intake process and control set operationalised.
ISO 42001 program
Certification-track AI management system, run end to end.
Talk it through with someone senior
Thirty minutes on your situation specifically, what is driving the timeline, what you have already tried, and what we would do first.