Skip to main content

What we do

AI Governance & Risk

Practical guardrails that let your organisation move with responsible speed while managing privacy, security, compliance, operational and reputational risk.

The leadership challenge

Innovation needs guardrails.

Uncontrolled AI use creates hidden data, vendor, regulatory, security and reputational exposure.

The goal is not to slow AI down. It is to make responsible speed possible.

  • Employees use unapproved public tools
  • Sensitive information enters uncontrolled systems
  • Vendors are adopted without consistent review
  • No escalation or incident process exists

Scope

A proportionate governance operating model

Decision rights

Clarify who may approve tools, data use, pilots and production deployment.

Risk controls

Create proportionate controls for privacy, security, compliance, reputation and human oversight.

AI inventory

Establish visibility of tools, vendors, models, use cases, owners and material risks.

Executive reporting

Give leadership a repeatable view of exposure, decisions, progress and exceptions.

Operating model

Governance designed around real work

We avoid theoretical policy packs. Controls are connected to the decisions teams actually make.

  1. 01

    Discover

    Identify current use, shadow AI, data flows, vendors and material obligations.

  2. 02

    Classify

    Define risk tiers for use cases, data, autonomy and impact.

  3. 03

    Decide

    Establish approval routes, responsibilities and human oversight requirements.

  4. 04

    Enable

    Create approved-tool guidance, training and usable policies.

  5. 05

    Monitor

    Maintain inventories, reporting, incidents and periodic review.

Relevant experience

Governance experience didn't start with AI.

Darren's career includes work across enterprise security, compliance, governance, service management, contractual obligations, standards, policies, SLAs and third-party performance in regulated and operationally complex environments.

That context includes exposure to SOC 1, SOC 2 and ISO-related control environments, supported by professional credentials and training that include COBIT, ITIL and TOGAF.

Meet Darren

Enterprise security and compliance

Policies, standards and controls

SLAs and third-party performance

SOC and ISO-related environments

COBIT, ITIL and TOGAF

Fit

This work is right when

  • AI use already exists without clear policy
  • Sensitive or regulated information is involved
  • Leadership needs confidence before scaling
  • UK or South African privacy obligations matter
  • Customers, insurers or boards expect evidence of control

Measurement

What you receive

Outcome 01

AI acceptable-use policy

Outcome 02

AI inventory and ownership model

Outcome 03

Vendor and use-case assessment approach

Outcome 04

Risk classification and approval workflow

Outcome 05

Human oversight principles

Outcome 06

Executive reporting and review cadence

A clear next step

Create guardrails that enable responsible speed.

Discuss your current AI use, data obligations and the governance decisions that need executive ownership.