02 · Governance & Risk

Be able to defend what you built.

A governance framework your organisation can actually operate, mapped against the regulation that binds you, and a per-system assessment that ends in a decision somebody can sign.

Something is about to go live, and somebody has to answer for it.

Discipline
Governance & Risk
Engagements
02
Typically bought by
CISO · CRO · DPO · AI Governance lead
Anchors
£6,000 – £12,000+

Set every figure below against the build it protects — and against paying for that build a second time. That comparison is the whole argument for hiring an architect, and it is why the fees are published rather than quoted on request.

What is actually at stake

The ceilings are published. The exposure is yours.

Article 99 of the EU AI Act sets administrative fines by tier — whichever is higher, the fixed sum or the share of turnover. For SMEs and start-ups the calculation reverses and the lower figure applies.

€35M or 7% of worldwide turnover

Prohibited AI practices under Article 5.

€15M or 3% of worldwide turnover

Provider, importer, distributor and deployer obligations.

€7.5M or 1% of worldwide turnover

Supplying incorrect, incomplete or misleading information to authorities.

Regulatory footing

Mapped against what actually applies.

We identify which of these bind you before mapping anything — the value is in the obligations that land, not the frameworks that get cited.

EU AI Act

Regulation

Likely role and classification per use case, the technical and organisational obligations that follow, existing controls mapped against them, and the evidence gaps that remain.

ISO/IEC 42001

Management system standard

An AI management system structure — policy, objectives, roles, lifecycle controls and internal audit hooks — shaped so certification is achievable rather than assumed.

NIST AI RMF

Risk framework

Govern, Map, Measure and Manage translated into named owners, stage gates and measurable evaluation requirements rather than a reading exercise.

UK regulatory expectations

Principles-based regime

The cross-sector principles and the expectations of the regulators that actually supervise you, reconciled with the controls you already operate.

Sector-specific requirements

Supervisory rules

Financial services, insurance, health and public sector obligations — model risk management, operational resilience, safeguarding and procurement rules — folded into the same control catalogue.

Governance & Risk

Tell us what you are building, or what you have to defend.

A scoping conversation ends with a written view of the engagement, its deliverables, its duration and its fee. No obligation on either side.