AI Governance & Risk
Governance done early is what lets AI move quickly. We set out who decides what, classify each use case by its potential impact, and build review procedures so that a drafting assistant is approved in days while a credit model gets the scrutiny it needs.

Strategy & governance
Why leadership teams bring this to us
Without agreed rules, every AI initiative is negotiated from scratch. Low-risk tools wait in the same queue as consequential ones, so adoption slows, while high-impact uses move ahead without the controls that regulators and boards now expect. Both are failures of governance, and both are avoidable.
What the service covers
Decision rights
Who approves a use case, sets its risk tier, approves its data use and signs it off for go-live, across business, technology, risk and legal.
Risk tiers
A tiering model, following the logic of the EU AI Act's risk categories, that sets how much review, testing and monitoring each use case gets.
Policies
Policies for data use, third-party and generative AI, and acceptable use by employees, written to be followed rather than filed.
Intake and review
The procedures, forms and forums that put the policies into practice, run alongside your team through the first review cycles.
Regulatory readiness
Your AI use mapped against the EU AI Act, the NIST AI Risk Management Framework, ISO/IEC 42001 and sector rules, with a gap register and remediation plan.
How we deliver it
- 01
Inventory
Catalogue the AI in use and in flight, including vendor features already switched on.
- 02
Design
Decision rights, risk tiers and policies drafted with business, technology, risk and legal leaders.
- 03
Operate
Intake and review procedures run with your team on real use cases, and adjusted where they slow things down.
- 04
Monitor
Monitoring for performance, drift and incidents after deployment, and periodic re-approval for high-tier uses.
What you should expect to change
Faster approvals for low-risk tools
Most use cases move quickly because the review they need is defined in advance.
Proper scrutiny where it matters
Consequential uses get impact assessment, testing and human oversight by design.
Clear accountability
Every AI system has a named owner and a known approver.
Readiness for regulators and boards
One internal process, mapped to each external framework.
What you receive, and where it is used
Deliverables
- AI inventory and risk classification
- Governance framework and decision-rights matrix
- Policies for data use, third-party AI and acceptable use
- Intake and review procedures
- Regulatory obligations map and gap register
Typical situations
- Turning an existing AI policy into a working review process
- Preparing for EU AI Act obligations across business units
- Aligning AI governance with an existing model risk framework
Talk to us about AI Governance & Risk
Send a short description of the decision or program in front of you. A senior advisor from this practice will reply within two business days.


