01
Discovery & scoping
Use cases, stakeholders, regulatory exposure
02
Gap assessment
Current state against a regulatory framework
03
Process governance
Controls, roles and decision rights
04
Implementation
Tooling, evidence and reporting live
Framework refreshed annually against regulatory change.
Leadership
Committee, sponsorship, decision rights
Named owner for every AI decision
Policies
Principles, policy suite, procedures
Ratified and version-controlled
Risk
Taxonomy, assessments, register
Treatment plans with due dates
Controls
Gates, monitoring, human review
Release blocked without evidence
Training
AI literacy, role-based enablement
Certification pathway for key staff
Reporting
Evidence, lineage, external reporting
Audit pack produced on demand
Organisational
Oversight, structure, culture
System
Lifecycle, risk, incidents, gates
Model
Registry, drift, monitoring, evidence
Packaged engagements with fixed scope, milestones and deliverables.
Each mapped to ISO/IEC 42001, NIST AI RMF and the local regulator.
G1
4–6 weeks
Assessment & Risk Tiering
Inventory and risk-tier the AI estate, score maturity, price the gap.
Risk-tiered inventory, maturity scorecard
G2
6–8 weeks
Policy, Framework & Literacy
Policy suite, committee, decision rights, GRC literacy.
Policy suite, committee charter, intake gate
G3
8–10 weeks
Risk & Impact Assessment
ISO 42005 impact assessments, FRIA, risk register, controls.
Impact assessments, risk register
G4
8–12 weeks
Testing, Evaluation & Red-Teaming
Evals, red-teaming, bias and drift testing, evidence platform.
Eval results, red-team findings
G5
10–14 weeks
Audit, Certification & Assurance
Internal audit, conformity audit, vendor audit, attestation.
Audit report, control scores, attestation
G6
Annuity · 12 months+
AIOps & Managed Governance
Continuous monitoring, evidence on demand, retained expertise.
Monthly dashboards, incident register
