# AI Governance and AI Compliance Consulting | GreenArrow

> AI governance and AI compliance consulting: build an AI inventory, classify risk, and turn the EU AI Act, ISO/IEC 42001 and the NIST AI RMF into controls people run.

Source: https://greenarrow.app/services/ai-governance/
Last updated: 2026-09-04
Publisher: Green Arrow Consultancy Ltd, Cardiff, Wales, United Kingdom

---

Services · AI governance

# AI governance an operating team can actually run

Almost nobody can list the AI systems running inside their own organisation. Until that list exists, a policy is a statement of intent about a population nobody has counted. We start with the count.

EU AI Act ISO/IEC 42001 NIST AI RMF IAPP member 
 Start with an AI inventory → See the security practice 
 
 
 
 Prohibited High risk Transparency Minimal 
 
 inventory · classify · control · evidence

“How many AI systems are live, and who owns each one?”

Answered from the register, with owner, tier and last review evidenced

Quick answer

AI governance is the set of decisions, records and controls that let an organisation say what AI it runs, who is accountable for each system, and what happens when one behaves badly. AI compliance consulting turns frameworks like the EU AI Act, ISO/IEC 42001 and the NIST AI Risk Management Framework into an inventory, a risk classification and a small number of controls an operating team can run.

## Key points

- The AI inventory is the first deliverable and the one almost nobody has. Everything else depends on it.

- The EU AI Act is structured by risk, not technology, so one model can be unregulated in one use and high risk in another.

- ISO/IEC 42001 is the management system standard for AI and reuses most of what ISO 27001 already gives you.

- The NIST AI Risk Management Framework organises the work into four functions: Govern, Map, Measure and Manage.

- Shadow AI is found through procurement records, sign-on logs and an honest amnesty survey, not a ban.

- Human oversight is only real when the reviewer has the authority and the time to say no.

## On this page

- Why governance has a bad name

- The inventory nobody has

- Use case, risk tier, controls

- The three frameworks, and what each is for

- What an AI policy should actually say

- The artefacts that make it real

- How a programme is stood up

- Frequently asked questions

Starting position

## Why governance has a bad name

Ask an engineering team what they think of governance and you will get a particular expression. It is earned. For twenty years it has meant a document written by people who had never shipped anything, enforced through a form that arrives after the decision has been made. The document describes principles. The team describes deadlines. Nothing connects.

AI made that gap expensive, because the tools arrived through the browser rather than through procurement. A finance analyst does not need a project to paste a customer list into a chatbot. A marketing team does not raise a change request to switch on an AI feature their platform shipped last month. Adoption went around the controls before anyone drafted a policy.

So we treat this as an operations problem, not a documentation problem. Governance that works is grounded in a real inventory. It is proportionate, so a marketing summariser does not carry the paperwork of a credit decision. It is embedded where people already work. And it produces evidence as a by-product of operating, not in the fortnight before an audit.

There is a commercial reason to do this now. Enterprise buyers have started asking AI questions in security reviews, and the answers are due before the contract. An organisation with an inventory, a classification and a policy answers in a day.

First deliverable

## The inventory nobody has

Seven fields, filled in from procurement data, identity logs, platform admin consoles and an amnesty survey. Resist the fifty-field register: one nobody maintains is worse than none, because it tells a comforting story about coverage.

- What the system is and what it is for. One sentence in business language. If nobody can write it, that is the first finding.

- Who owns it. A named person, not a department. Ownership is what makes every other control enforceable.

- What data goes in. Personal data, confidential material, customer content, source code. Where the privacy assessment hooks in.

- Which model and which provider. Vendor, model family, hosting region, and whether inputs may be retained or used for training under the contract you actually signed.

- Who or what it affects. Customers, employees, candidates, patients, the public. This drives the risk tier far more than the technology does.

- What decision it influences. Informs, recommends, or decides. The step from recommends to decides changes both your obligations and your exposure.

- How it was procured. Contract, expense claim, free tier, or a feature that appeared in a product you already licence. The last category is the largest and the least recorded.

Classification

## Use case, risk tier, controls

Triage, not a legal opinion. The same model appears in several rows, which is the point of a risk-based structure: the regulator is interested in the use, not the technology.

| AI use case | Likely risk position | What that implies in practice |
|---|---|---|
| Internal search over documents staff may already read | Low risk, still in scope for inventory and policy | Permission-aware retrieval, accuracy evaluation, logging, a named owner |
| A customer-facing chatbot | Transparency obligations rather than high risk in most readings | Tell people they are talking to a machine, offer a route to a human, define refusal and retention |
| Screening or shortlisting job applicants | Widely treated as high risk in employment contexts | Documented risk management, data quality and bias testing, human review, record keeping, candidate information |
| Scoring eligibility for credit or insurance | Widely treated as high risk in essential services | Technical documentation, explainability, oversight with authority to override, logging and monitoring |
| Social scoring of individuals by public authorities | Prohibited practice | Do not build it |
| Offering a general purpose model as a platform to other teams | Obligations attach to your role, and a provider is not a deployer | Model documentation, usage policy, downstream guidance, a clear map of provider and deployer roles |

Summarised from the EU AI Act's risk-based structure. Scope, definitions, thresholds and timing vary by provision and jurisdiction and continue to develop. Confirm application with your legal advisers.

Reference points

## The three frameworks, and what each is for

Clients ask which of these to adopt as though they compete. They do not. One is law, one is a certifiable management system, one is a method.

### The EU AI Act: the legal shape

The Act regulates by risk. A narrow set of practices is prohibited. A defined group of uses, concentrated in employment, education, essential services, critical infrastructure, biometrics and law enforcement, is designated high risk and carries obligations covering risk management, data governance, technical documentation, record keeping, human oversight, accuracy and robustness. A further group attracts transparency duties, such as disclosing that a person is interacting with an AI system or that content is artificially generated. Providers of general purpose AI models carry their own documentation and transparency duties, which increase where a model presents systemic risk. Duties differ by role: provider, deployer, importer or distributor. Dates and thresholds vary by provision, so we describe the shape and leave interpretation to your legal advisers.

### ISO/IEC 42001: the management system

ISO/IEC 42001 specifies how an organisation governs AI as an ongoing system: leadership commitment, an AI policy, defined roles, risk and impact assessment, objectives, operational controls, internal audit, and management review. It follows the harmonised structure of ISO 27001, so a certified information security programme already has the scaffolding and the audit rhythm. Being certifiable is why it now appears in procurement questionnaires.

### NIST AI Risk Management Framework: the method

The NIST AI RMF is voluntary, non-certifiable and the most immediately useful of the three for getting work moving. Govern sets the culture, accountability, policies and roles the others operate inside. Map establishes context: purpose, affected people and failure modes. Measure analyses and tracks risk with methods and metrics, including uncomfortable ones like bias and robustness. Manage treats and monitors risks, and handles incidents and retirement.

Use NIST to structure the work, ISO/IEC 42001 to keep it running and evidenced, and the EU AI Act with UK GDPR and sector rules to establish what you are obliged to do. Then connect it to the technical layer, because an untested control is an assertion. That is our AI security practice.

Policy

## What an AI policy should actually say

Five answers, taught in short role-specific sessions rather than published to an intranet. A policy longer than a few pages is written for an auditor, not for the people whose behaviour it is meant to change.

### Which tools are approved, and for what

A named list with the use each is approved for, and a route to request additions with a stated response time. Ambiguity pushes people back to shadow tools.

### What data must never go into a model

Specific categories in your language: customer records, unreleased financials, source code, special category personal data. Abstract wording gets interpreted generously under deadline.

### When a human must review output

Tied to the decision, not the department. Anything that reaches a customer, affects a person or moves money gets a reviewer with authority to reject it.

### When you must disclose that AI was involved

Customer-facing conversations, generated media, and automated decisions affecting a person. Put the wording in the policy so nobody invents it at speed.

### What to do when something goes wrong

One channel, one contact, and an explicit statement that reporting in good faith is not a disciplinary matter. Unreported incidents are the ones customers report for you.

> Darren Tyler has been doing work for me on Energizer's website compliance. Not only has he met our teams expectations but exceeded them.

, Kathy Senior Corporate Privacy Manager, Energizer Holdings

Evidence

## The artefacts that make it real

Governance is judged on evidence. Each of these is small enough to actually maintain.

**Model and system cards**

One short document per system: purpose, model and version, data sources, known limitations, evaluation results, oversight arrangement, last review date. It answers most of what a buyer or auditor asks.

**Human oversight design**

Not a sentence saying a human is in the loop. A named role, the information they see, authority to override, and evidence that overrides happen. Oversight that never disagrees is a rubber stamp.

**AI incident response**

Existing processes miss the AI cases: a harmful output, a hallucinated answer acted on, a leak through a prompt, a model update that quietly changed behaviour. Add those categories and name who can take a system offline.

**Vendor and model provider due diligence**

Where data is processed, whether inputs are retained or used for training, subprocessors, deprecation notice periods, indemnities and exit. Read the enterprise terms, not the marketing page.

**Transparency records and evaluation history**

What you disclose, where and since when, plus accuracy, refusal and bias results per release. Algorithmic transparency is far easier to evidence when it was logged at the time.

Delivery

## How a programme is stood up

Timings overlap deliberately, because classification always uncovers more inventory.

- 01

### Discovery and inventory, weeks one to three

Procurement, expense, identity logs, platform admin consoles and an amnesty survey. Output is a populated register with owners assigned, plus anything needing attention now.

- 02

### Classification and gap analysis, weeks three to six

Each entry assessed on use, affected people and decision influence, then mapped against your obligations. Output is a tiered population and a gap list ranked by exposure, not by effort.

- 03

### Policy, oversight and controls, weeks five to nine

The policy people can follow, oversight design for the higher tiers, an intake process for new systems, and controls implemented in the workflow, not in a document.

- 04

### Documentation and evidence, weeks eight to twelve

Model cards, risk assessments, incident procedures, vendor records and training. Where the target is ISO/IEC 42001, also the internal audit and management review scaffolding.

- 05

### Operate, review and re-run

New systems registered at intake, re-assessment triggered by change, incidents handled through the process, and a scheduled review of the population. This part decides whether the other four survive.

Why us

## The consultancy behind this

Green Arrow Consultancy has run privacy and compliance programmes for global consumer brands since around 2017, when GDPR pulled that work into the centre of every client web estate we managed. We are a member of the International Association of Privacy Professionals, hold ICO registration ZA822868, and have implemented privacy management platforms across Osano, Securiti.ai and OneTrust for Circana. The difference from a pure compliance firm is that we also build the systems: seven production AI applications from this team are generalised into the live demonstrations on this site. When we say a control is workable we have implemented it, which is why this work stays joined to AI delivery and privacy consulting.

One boundary, stated plainly. We are not a law firm and nothing here is legal advice. We build the inventory, the classification, the controls and the evidence; your legal advisers decide what the law requires, and they can do that far faster once the first three exist.

Questions

## Frequently asked questions

Wider questions on privacy, security and delivery are in the full FAQ, and terms are defined in the glossary.

### What is AI governance, in practical terms?

It is knowing what AI your organisation runs, who owns each system, what could go wrong, what controls are in place, and who decides when something changes. Everything else is detail. A programme that produces a policy but cannot answer the first question has not started.

### What is shadow AI and how do we find it?

Shadow AI is the AI in use that nobody registered: a chatbot subscription on a personal card, a note taker joining meetings, a plugin summarising customer records. The risk is real while the oversight is absent. Find it through expense data, identity logs showing which third-party apps were authorised, network telemetry, platform admin consoles and an honest amnesty survey. Bans do not work. A sanctioned alternative does.

### How does the EU AI Act classify AI systems?

By risk rather than by technology. A small set of practices is prohibited outright. A defined group of uses, largely in employment, education, essential services, critical infrastructure, biometrics and law enforcement, is treated as high risk and carries obligations on risk management, data governance, documentation, logging, human oversight, accuracy and robustness. A further group carries transparency duties, such as telling people they are dealing with a machine. Obligations also depend on your role, provider or deployer, and detail and timing vary by provision. This is a summary of the structure and not legal advice.

### Does the EU AI Act apply to a UK or US company?

It can. The Act reaches organisations placing AI systems on the EU market or whose system output is used in the EU, which catches many companies established elsewhere. Whether it applies to a given system depends on the facts and your role, which is a question for your legal advisers. Our job is to have the inventory, classification and evidence ready so that question is answered quickly.

### What is ISO/IEC 42001 and do we need it?

ISO/IEC 42001 is the international management system standard for artificial intelligence: policy, roles, risk assessment, objectives, controls, internal audit and management review, in the same structural style as ISO 27001. You need it if customers or regulators will ask for independent assurance, or if you want an external cadence that keeps the programme alive. If you already hold ISO 27001, much of the machinery is reusable.

### What are the four functions of the NIST AI Risk Management Framework?

Govern, Map, Measure and Manage. Govern establishes the culture, accountability and policy the other three operate inside. Map builds context: what the system is for, who it affects, how it could fail. Measure analyses and tracks those risks with methods and metrics. Manage treats risks and responds to incidents. It is voluntary and not a certification, and it is the most useful vocabulary available for work spanning legal, security and engineering.

### Is this legal advice?

No. Green Arrow Consultancy is a technical and compliance consultancy, not a law firm. We describe the shape of obligations and build the inventory, evidence and controls that let you meet them, alongside your legal advisers. Dates, thresholds and definitions vary by provision and jurisdiction and continue to move. Take the legal question to a lawyer and bring us the operating problem.

Written and reviewed by the Green Arrow Consultancy team, led by Darren Tyler, founder and chief executive.

Green Arrow Consultancy Ltd, Cardiff, Wales. Company number 12491770. ICO registration ZA822868. Member of the International Association of Privacy Professionals. Last reviewed 04 September 2026.

Keep reading

## Related

### AI Security

The testing that proves a governance control exists in the system and not only in the document.

Read this →

### Privacy Consulting

Lawful basis, data flow, retention and impact assessments, the foundation AI governance is built on.

Read this →

### AI Consulting & Development

How we design and build AI systems with the governance requirements engineered in from week one.

Read this →

## Start with the list you do not have

Most AI governance conversations improve once the inventory exists. We can put a populated register and a first risk classification in front of you inside a month.

Start an AI inventory → 
 See all services
