Startup Consultancy Services
Buy blocks of my time and tap straight into 24+ years of hands-on CTO experience. No retainer, no long contract - just the senior guidance you need, when you need it.
Read moreRisk & Assurance
AI governance fails in two directions: frameworks so heavy nothing ships, or so absent that nobody knows which tools are processing customer data. The useful middle is a proportionate framework - light controls on low-impact use, real scrutiny where decisions affect people, and evidence produced as a by-product of the work.
When this helps
How we help
Every stage produces something you can act on independently, so the engagement can stop at any point without leaving you stranded mid-programme.
Find every AI system, vendor, and shadow tool in use, and what data each one touches.
Rate each use by impact on people and on the business, so controls can be proportionate rather than uniform.
Apply the controls each tier warrants: access, logging, human oversight, testing, and vendor assurance.
Produce the artefacts an auditor or enterprise customer will ask for, generated by the process rather than assembled in a panic.
Efficiencies driven
Where teams usually start
Where the engagement leaves you
Controls by assessed impact
DPIAs and assessments
Audit evidence, not reactive
What you receive
Next step
A short call is usually enough to work out whether this is the right engagement, and what it would cost. If it is not, I will say so.
Engagement
Evidence, not intent