Strategy & operating model
Where AI governance sits in your org chart, who owns which decisions, and how risk, product, security, and legal stop talking past each other.
Strategy, controls, and ongoing advisory for organisations that have to govern AI well because the consequences of getting it wrong are real. EU AI Act, ISO/IEC 42001, NIST AI RMF, DORA — implemented, not summarised.
Most clients start with one track and expand. Engagements run 4 to 12 weeks for project work, or a fixed monthly retainer for advisory.
Where AI governance sits in your org chart, who owns which decisions, and how risk, product, security, and legal stop talking past each other.
A control framework built around the systems you actually run — not a generic library. Implemented inside your existing SDLC, MLOps, and risk processes.
On-call advisory for the moments that matter: board papers, vendor reviews, incident response, regulator correspondence, and high-stakes go/no-go decisions.
Workshops for boards, engineering teams, and risk functions — so the governance you build outlives the engagement.
Half an hour, no slides. We discuss what you're trying to govern, what's already working, and whether an outside practitioner moves the needle.