AI Governance & Assurance
Deploy it, and be able to defend it.
Model inventories, risk classification, evaluation evidence and human-oversight design — built to satisfy the EU AI Act and your own risk committee.
- EU AI Act aligned
- Evidence by construction
- Practitioner-built
What it is
Governance written by people who ship
AI governance fails in one of two directions: a policy document nobody can implement, or a review board that becomes a queue and gets routed around.
We build governance the way we build platforms — as a paved road. Evidence is generated by the pipeline, classification is a short form rather than a committee, and the controls scale with the risk of the use case instead of applying uniformly to everything.
- Risk-tiered, not uniform
- Evidence generated automatically
- Oversight designed to be usable
- Aligned to EU AI Act obligations
Model families we work with
- Provider-hosted models
- Open-weight models
- Classical ML
Risk classification
Controls scale to consequence
Of evidence auto-generated
Produced by the deployment pipeline
Capabilities
What we put in place
Model inventory
A live register of every model and AI feature in production, its owner, its risk tier and its evaluation status.
- Automated discovery
- Ownership register
- Risk tiering
Risk classification
A short, repeatable assessment that routes a use case to proportionate controls rather than a universal review.
- Classification framework
- Proportionate controls
- Self-service assessment
Evaluation evidence
Test results, fairness analysis and known limitations captured as an artefact of the pipeline that produced them.
- Automated evidence capture
- Model cards
- Limitation documentation
Human oversight
Review interfaces designed so the human can actually catch the error — not a checkbox on a screen of model output.
- Review UX design
- Escalation paths
- Reviewer training
Incident response
What happens when a model behaves badly in front of a customer: detection, containment, disclosure and correction.
- Detection design
- Containment playbooks
- Disclosure process
Use cases
What this looks like in practice
Deployments we have built or scoped, with the sector they landed in.
EU AI Act readiness
Classifying systems and closing the documentation gaps ahead of obligation dates.
Model risk management
Extending existing model risk frameworks to cover generative systems.
- Financial Services
Clinical safety cases
Evidence packages for AI features touching clinical workflows.
- Healthcare & Life Sciences
Stack
Technologies we use here
Sectors
Where this lands first
Assurance
How we keep this honest
The commitments that matter when the system is making or shaping decisions.
We are not your auditor
We build the controls and the evidence; independent assurance should come from someone with no stake in the outcome.
Implementable by default
Every control we specify is one we have implemented ourselves on a delivery engagement.
FAQ
Questions we are asked
If you place a system on the EU market or its output is used in the EU, very likely — regardless of where you are headquartered. The classification exercise is short and worth doing early, because the obligations differ enormously by tier.
Classify what you already have
Start with an inventory. Most organisations find more AI in production than they expected.