Service 03
Governance & Policy
Written rules for what your AI systems may do, turned into controls that actually run - approval gates, scoped permissions, retention - plus the inventory and records an auditor or a customer will ask you for.
Policy documents fail in a predictable way. They describe intent, nothing enforces them, and the gap between the two only becomes visible during an incident or a security review. A rule that lives in a PDF is a preference.
So the work has two halves and needs both. The written half is the part organisations know they need: an inventory of every AI system in use, what data each one touches, who owns it, what it may and may not do, and a durable record of the decisions and who made them. The enforced half is those same rules expressed as controls - which tool calls require a human before they run, what each agent identity is scoped to, what is retained and for how long, what happens when a check fails.
The inventory is usually the part that surprises people. AI arrives in an organisation through a dozen doors - a feature in a SaaS product, a script somebody wrote, a copilot enabled by default - and the first honest census tends to find systems in production that the people accountable for AI did not know existed.
We are not an auditor and we certify nothing. What we do is get the inventory, the controls and the evidence into a state where an audit against ISO/IEC 42001, an EU AI Act obligation or a customer security questionnaire is a matter of producing records that already exist rather than reconstructing them under time pressure.
Questions About This Work
What does AI governance actually involve?
Two halves. The written half is an inventory of every AI system in use, what data it touches, who owns it, what it may do, and a record of the decisions made about it. The enforced half is those same rules as running controls: approval gates on irreversible actions, scoped agent identities, retention limits. A policy with nothing enforcing it is a preference.
Can you get us ISO/IEC 42001 certified?
No. We are not a certification body and would not want to be, since preparing you and certifying you is a conflict. What we do is get the inventory, the controls and the evidence into the state the standard asks for, so that a certification audit becomes a matter of producing records that already exist.
Does the EU AI Act apply to a company in India?
It can, if a system is placed on the EU market or its output is used in the EU - the Act applies by where the system is used, not by where the company sits. Whether a particular system falls into a regulated category is a legal question we would scope with counsel rather than answer alone. What we do is make sure the technical evidence those obligations ask for exists either way.
What is an AI system inventory, and why does the audit start there?
A census of every AI system in production, including the ones that arrived through a SaaS feature, a default-on copilot or a script nobody registered, with its owner, its data, its permissions and its purpose. Everything else in governance is per-system, so an incomplete inventory leaves systems ungoverned by definition. First audits routinely find production systems nobody accountable knew about.
Reading On This
Start With the Audit
No engagement is scoped before a read-only review of the systems you actually run. The roadmap it produces is yours either way.