Governance charter
Named responsibilities, decision rights, approval route, escalation process and review cadence.
Turn an incomplete collection of tools and policies into an organised governance system your compliance owner can understand, maintain and demonstrate.
An assessment identifies gaps. The Starter Pack builds the practical baseline: ownership, registers, assessments, policies, training and an indexed evidence pack that connects the organisation's AI use to its controls.
Outcome: the compliance owner can open a controlled folder and explain what AI is used, why it is used, how risks were assessed, who owns each control and what work remains.
The programme moves from discovery to documented decisions, then checks that the resulting controls can work in the organisation.
Agree entities, departments, locations and systems; name accountable owners; create the approval and escalation route.
Run stakeholder workshops, review tools and identify shadow AI and AI features embedded in existing platforms.
Document each use case, owner, purpose, users, affected people, inputs, outputs, vendor, status and review date.
Assess provider/deployer roles, prohibited practices, potential high-risk uses, transparency, human oversight and AI literacy.
Connect personal-data uses to the RoPA, screen for DPIA needs and review processors, transfers, retention and data-training terms.
Develop an acceptable-use policy, approved-tools process, new-use-case assessment, incident route and human-review procedure.
Deliver practical AI literacy training, record attendance and give higher-risk roles tailored examples and escalation guidance.
Index documents, link them to systems and risks, assign actions and brief management on the current position and roadmap.
A practical governance baseline tailored to the agreed scope—not a generic bundle of templates.
Named responsibilities, decision rights, approval route, escalation process and review cadence.
A working, maintainable register covering systems, features, use cases, owners, data, risks and evidence links.
Documented screening results, material risks, safeguards, owners and outstanding decisions.
Mapping between AI uses and relevant processing activities, plus lawful-basis and DPIA questions requiring confirmation.
A documented review of contracts, processors, hosting, transfers, retention, security and data-training arrangements.
Clear employee rules for approved tools, personal and confidential data, verification, transparency and incidents.
New-use-case assessment, human oversight, incident escalation, exceptions and change-management records.
Training content, delivery session, attendance record and practical guidance for relevant roles.
Actions grouped by urgency with owners, dependencies, target dates and closure evidence.
A logical folder structure and status index connecting systems, decisions, policies, contracts, training and actions.
The organisation finishes with more than documents: it has a repeatable way to govern AI.
Respond more confidently to regulators, customers, insurers, boards and procurement teams.
Give staff a safe route to use AI and make unapproved tools and risky behaviour easier to identify.
Avoid maintaining disconnected registers that tell different stories about the same processing.
Know who approved each material use, on what basis and when it must be reviewed.
Discuss your current position, intended scope and whether the Starter Pack fits the organisation.
Discuss the Starter Pack ↗