Almost nobody can list the AI systems running inside their own organisation. Until that list exists, a policy is a statement of intent about a population nobody has counted. We start with the count.
AI governance is the set of decisions, records and controls that let an organisation say what AI it runs, who is accountable for each system, and what happens when one behaves badly. AI compliance consulting turns frameworks like the EU AI Act, ISO/IEC 42001 and the NIST AI Risk Management Framework into an inventory, a risk classification and a small number of controls an operating team can run.
Ask an engineering team what they think of governance and you will get a particular expression. It is earned. For twenty years it has meant a document written by people who had never shipped anything, enforced through a form that arrives after the decision has been made. The document describes principles. The team describes deadlines. Nothing connects.
AI made that gap expensive, because the tools arrived through the browser rather than through procurement. A finance analyst does not need a project to paste a customer list into a chatbot. A marketing team does not raise a change request to switch on an AI feature their platform shipped last month. Adoption went around the controls before anyone drafted a policy.
So we treat this as an operations problem, not a documentation problem. Governance that works is grounded in a real inventory. It is proportionate, so a marketing summariser does not carry the paperwork of a credit decision. It is embedded where people already work. And it produces evidence as a by-product of operating, not in the fortnight before an audit.
There is a commercial reason to do this now. Enterprise buyers have started asking AI questions in security reviews, and the answers are due before the contract. An organisation with an inventory, a classification and a policy answers in a day.
Seven fields, filled in from procurement data, identity logs, platform admin consoles and an amnesty survey. Resist the fifty-field register: one nobody maintains is worse than none, because it tells a comforting story about coverage.
Triage, not a legal opinion. The same model appears in several rows, which is the point of a risk-based structure: the regulator is interested in the use, not the technology.
| AI use case | Likely risk position | What that implies in practice |
|---|---|---|
| Internal search over documents staff may already read | Low risk, still in scope for inventory and policy | Permission-aware retrieval, accuracy evaluation, logging, a named owner |
| A customer-facing chatbot | Transparency obligations rather than high risk in most readings | Tell people they are talking to a machine, offer a route to a human, define refusal and retention |
| Screening or shortlisting job applicants | Widely treated as high risk in employment contexts | Documented risk management, data quality and bias testing, human review, record keeping, candidate information |
| Scoring eligibility for credit or insurance | Widely treated as high risk in essential services | Technical documentation, explainability, oversight with authority to override, logging and monitoring |
| Social scoring of individuals by public authorities | Prohibited practice | Do not build it |
| Offering a general purpose model as a platform to other teams | Obligations attach to your role, and a provider is not a deployer | Model documentation, usage policy, downstream guidance, a clear map of provider and deployer roles |
Summarised from the EU AI Act's risk-based structure. Scope, definitions, thresholds and timing vary by provision and jurisdiction and continue to develop. Confirm application with your legal advisers.
Clients ask which of these to adopt as though they compete. They do not. One is law, one is a certifiable management system, one is a method.
The Act regulates by risk. A narrow set of practices is prohibited. A defined group of uses, concentrated in employment, education, essential services, critical infrastructure, biometrics and law enforcement, is designated high risk and carries obligations covering risk management, data governance, technical documentation, record keeping, human oversight, accuracy and robustness. A further group attracts transparency duties, such as disclosing that a person is interacting with an AI system or that content is artificially generated. Providers of general purpose AI models carry their own documentation and transparency duties, which increase where a model presents systemic risk. Duties differ by role: provider, deployer, importer or distributor. Dates and thresholds vary by provision, so we describe the shape and leave interpretation to your legal advisers.
ISO/IEC 42001 specifies how an organisation governs AI as an ongoing system: leadership commitment, an AI policy, defined roles, risk and impact assessment, objectives, operational controls, internal audit, and management review. It follows the harmonised structure of ISO 27001, so a certified information security programme already has the scaffolding and the audit rhythm. Being certifiable is why it now appears in procurement questionnaires.
The NIST AI RMF is voluntary, non-certifiable and the most immediately useful of the three for getting work moving. Govern sets the culture, accountability, policies and roles the others operate inside. Map establishes context: purpose, affected people and failure modes. Measure analyses and tracks risk with methods and metrics, including uncomfortable ones like bias and robustness. Manage treats and monitors risks, and handles incidents and retirement.
Use NIST to structure the work, ISO/IEC 42001 to keep it running and evidenced, and the EU AI Act with UK GDPR and sector rules to establish what you are obliged to do. Then connect it to the technical layer, because an untested control is an assertion. That is our AI security practice.
Five answers, taught in short role-specific sessions rather than published to an intranet. A policy longer than a few pages is written for an auditor, not for the people whose behaviour it is meant to change.
A named list with the use each is approved for, and a route to request additions with a stated response time. Ambiguity pushes people back to shadow tools.
Specific categories in your language: customer records, unreleased financials, source code, special category personal data. Abstract wording gets interpreted generously under deadline.
Tied to the decision, not the department. Anything that reaches a customer, affects a person or moves money gets a reviewer with authority to reject it.
Customer-facing conversations, generated media, and automated decisions affecting a person. Put the wording in the policy so nobody invents it at speed.
One channel, one contact, and an explicit statement that reporting in good faith is not a disciplinary matter. Unreported incidents are the ones customers report for you.
Darren Tyler has been doing work for me on Energizer's website compliance. Not only has he met our teams expectations but exceeded them.
Governance is judged on evidence. Each of these is small enough to actually maintain.
Timings overlap deliberately, because classification always uncovers more inventory.
Procurement, expense, identity logs, platform admin consoles and an amnesty survey. Output is a populated register with owners assigned, plus anything needing attention now.
Each entry assessed on use, affected people and decision influence, then mapped against your obligations. Output is a tiered population and a gap list ranked by exposure, not by effort.
The policy people can follow, oversight design for the higher tiers, an intake process for new systems, and controls implemented in the workflow, not in a document.
Model cards, risk assessments, incident procedures, vendor records and training. Where the target is ISO/IEC 42001, also the internal audit and management review scaffolding.
New systems registered at intake, re-assessment triggered by change, incidents handled through the process, and a scheduled review of the population. This part decides whether the other four survive.
Green Arrow Consultancy has run privacy and compliance programmes for global consumer brands since around 2017, when GDPR pulled that work into the centre of every client web estate we managed. We are a member of the International Association of Privacy Professionals, hold ICO registration ZA822868, and have implemented privacy management platforms across Osano, Securiti.ai and OneTrust for Circana. The difference from a pure compliance firm is that we also build the systems: seven production AI applications from this team are generalised into the live demonstrations on this site. When we say a control is workable we have implemented it, which is why this work stays joined to AI delivery and privacy consulting.
One boundary, stated plainly. We are not a law firm and nothing here is legal advice. We build the inventory, the classification, the controls and the evidence; your legal advisers decide what the law requires, and they can do that far faster once the first three exist.
Wider questions on privacy, security and delivery are in the full FAQ, and terms are defined in the glossary.
It is knowing what AI your organisation runs, who owns each system, what could go wrong, what controls are in place, and who decides when something changes. Everything else is detail. A programme that produces a policy but cannot answer the first question has not started.
Shadow AI is the AI in use that nobody registered: a chatbot subscription on a personal card, a note taker joining meetings, a plugin summarising customer records. The risk is real while the oversight is absent. Find it through expense data, identity logs showing which third-party apps were authorised, network telemetry, platform admin consoles and an honest amnesty survey. Bans do not work. A sanctioned alternative does.
By risk rather than by technology. A small set of practices is prohibited outright. A defined group of uses, largely in employment, education, essential services, critical infrastructure, biometrics and law enforcement, is treated as high risk and carries obligations on risk management, data governance, documentation, logging, human oversight, accuracy and robustness. A further group carries transparency duties, such as telling people they are dealing with a machine. Obligations also depend on your role, provider or deployer, and detail and timing vary by provision. This is a summary of the structure and not legal advice.
It can. The Act reaches organisations placing AI systems on the EU market or whose system output is used in the EU, which catches many companies established elsewhere. Whether it applies to a given system depends on the facts and your role, which is a question for your legal advisers. Our job is to have the inventory, classification and evidence ready so that question is answered quickly.
ISO/IEC 42001 is the international management system standard for artificial intelligence: policy, roles, risk assessment, objectives, controls, internal audit and management review, in the same structural style as ISO 27001. You need it if customers or regulators will ask for independent assurance, or if you want an external cadence that keeps the programme alive. If you already hold ISO 27001, much of the machinery is reusable.
Govern, Map, Measure and Manage. Govern establishes the culture, accountability and policy the other three operate inside. Map builds context: what the system is for, who it affects, how it could fail. Measure analyses and tracks those risks with methods and metrics. Manage treats risks and responds to incidents. It is voluntary and not a certification, and it is the most useful vocabulary available for work spanning legal, security and engineering.
No. Green Arrow Consultancy is a technical and compliance consultancy, not a law firm. We describe the shape of obligations and build the inventory, evidence and controls that let you meet them, alongside your legal advisers. Dates, thresholds and definitions vary by provision and jurisdiction and continue to move. Take the legal question to a lawyer and bring us the operating problem.
Most AI governance conversations improve once the inventory exists. We can put a populated register and a first risk classification in front of you inside a month.