← AI compliance services

AI Governance
Starter Pack.

Turn an incomplete collection of tools and policies into an organised governance system your compliance owner can understand, maintain and demonstrate.

Structured implementationDocuments plus working controlsManagement handover

What this solves.

An assessment identifies gaps. The Starter Pack builds the practical baseline: ownership, registers, assessments, policies, training and an indexed evidence pack that connects the organisation's AI use to its controls.

Outcome: the compliance owner can open a controlled folder and explain what AI is used, why it is used, how risks were assessed, who owns each control and what work remains.

How it is done.

The programme moves from discovery to documented decisions, then checks that the resulting controls can work in the organisation.

  1. Define scope and governance

    Agree entities, departments, locations and systems; name accountable owners; create the approval and escalation route.

  2. Discover and map AI use

    Run stakeholder workshops, review tools and identify shadow AI and AI features embedded in existing platforms.

  3. Build the AI Systems Register

    Document each use case, owner, purpose, users, affected people, inputs, outputs, vendor, status and review date.

  4. Classify roles and risks

    Assess provider/deployer roles, prohibited practices, potential high-risk uses, transparency, human oversight and AI literacy.

  5. Map data and vendors

    Connect personal-data uses to the RoPA, screen for DPIA needs and review processors, transfers, retention and data-training terms.

  6. Create policies and procedures

    Develop an acceptable-use policy, approved-tools process, new-use-case assessment, incident route and human-review procedure.

  7. Train the people involved

    Deliver practical AI literacy training, record attendance and give higher-risk roles tailored examples and escalation guidance.

  8. Assemble and hand over the evidence pack

    Index documents, link them to systems and risks, assign actions and brief management on the current position and roadmap.

What you receive.

A practical governance baseline tailored to the agreed scope—not a generic bundle of templates.

01

Governance charter

Named responsibilities, decision rights, approval route, escalation process and review cadence.

02

AI Systems Register

A working, maintainable register covering systems, features, use cases, owners, data, risks and evidence links.

03

Risk register and classifications

Documented screening results, material risks, safeguards, owners and outstanding decisions.

04

AI-related RoPA mapping

Mapping between AI uses and relevant processing activities, plus lawful-basis and DPIA questions requiring confirmation.

05

Vendor and transfer review

A documented review of contracts, processors, hosting, transfers, retention, security and data-training arrangements.

06

AI Acceptable Use Policy

Clear employee rules for approved tools, personal and confidential data, verification, transparency and incidents.

07

Operational procedures

New-use-case assessment, human oversight, incident escalation, exceptions and change-management records.

08

AI literacy pack

Training content, delivery session, attendance record and practical guidance for relevant roles.

09

Prioritised remediation plan

Actions grouped by urgency with owners, dependencies, target dates and closure evidence.

10

Indexed evidence pack

A logical folder structure and status index connecting systems, decisions, policies, contracts, training and actions.

The benefit.

The organisation finishes with more than documents: it has a repeatable way to govern AI.

Answer assurance questions

Respond more confidently to regulators, customers, insurers, boards and procurement teams.

Reduce uncontrolled use

Give staff a safe route to use AI and make unapproved tools and risky behaviour easier to identify.

Connect AI and GDPR

Avoid maintaining disconnected registers that tell different stories about the same processing.

Create accountable decisions

Know who approved each material use, on what basis and when it must be reviewed.

What we need from you

  • A senior sponsor and day-to-day owner
  • Access to relevant departments and system owners
  • Existing policies, registers, vendor records and contracts
  • Timely factual review and management decisions
  • Participation in training and handover

Separately scoped where needed

  • Formal legal opinions
  • Complete organisation-wide GDPR remediation
  • Full DPIAs or fundamental-rights impact assessments
  • High-risk provider conformity work
  • Major technical or cybersecurity implementation

Build the evidence behind your AI governance.

Discuss your current position, intended scope and whether the Starter Pack fits the organisation.

Discuss the Starter Pack