AI governance and compliance
Governance that lets AI clear a board and a regulator at the same time, including AI that acts, not just advises. Built on recognized frameworks, expressed in language a non-technical board can approve.
The problem it solves
Most AI governance fails in one of two ways. It satisfies a regulator on paper and never reaches production, because the controls are too heavy to use. Or it ships fast and cannot survive the first serious review, because no one built the accountability in. The expensive failure is the gap between them: a governance document that reads well while the system stalls at the approval gate, or a system in production that no one can defend when a regulator or a board finally asks the hard question. This work closes that gap, governance built to be adopted, not filed.
Who it is for
Banks, healthcare platforms, governments, and any institution deploying AI under supervision, anywhere a wrong output has real consequences and the system has to answer to more than one authority at once.
What you get
- An AI governance framework aligned to the NIST AI Risk Management Framework and ISO/IEC 42001
- Risk and control mapping across your AI systems
- Agentic-AI controls: authority, boundaries, reversibility, and human checkpoints
- Documentation that speaks to a regulator and a board from the same source
- Pre-deployment adversarial review of each consequential system
How it works
- Assess the current AI estate and its exposure
- Design the governance framework on a recognized foundation
- Map the local and sector requirements on top
- Verify each system before it is deployed
Why this, not a generic audit
A checklist audit tells you what is wrong and leaves. This builds the governance that makes AI defensible and keeps it usable, anchored to standards a board already accepts (the NIST AI Risk Management Framework and ISO/IEC 42001), mapped onto your actual systems and your jurisdiction's real rules, and proven with a pre-deployment adversarial review rather than a hope that it holds. It is the operating model set out in AI governance for regulated institutions and scored against the Sovereign AI Governance Readiness Framework, delivered on your systems. Proven in practice: a clinical-AI platform positioned to clear a regulator and a board at once while adoption rose 25%.
Questions
Which frameworks do you align to?
Can you govern agentic AI?
Common questions
What does a board actually need to know before approving an AI strategy?
Five things. What decisions the system will influence, and how far its authority runs. Where the data comes from and where it is stored. How an outcome gets explained if a customer, an auditor, or a regulator asks. Who inside management owns it, and what happens when it is wrong. And what evidence comes back to the board, on what cadence. If a proposal cannot answer those five in plain language, it is not ready for approval, whatever the technology promises.
Should we set up a separate AI committee on the board or fold it into audit and risk?
For most institutions, fold it into risk first and give it a standing agenda item. AI risk is model risk, data risk, vendor risk, and conduct risk in a new arrangement, and those committees already exist. A separate committee makes sense when AI is central to the business model, or when your regulator expects a dedicated view. What matters more than the box on the chart is whether one named director is accountable and whether the committee receives evidence rather than assurances.
If we put customer data on an AI cloud, what are the data residency risks?
This is a design question and it is answerable before you commit. Map which data classes are involved, what your regulator and your own contracts require about where data lives, and what actually crosses a border at each step. Then choose the architecture that fits: in country hosting, private deployment, or keeping sensitive fields out of the model entirely. A great deal of useful AI can be built without moving customer records anywhere. Decide the boundary first, then build inside it.
What is the real risk of using AI in decisions if an auditor asks us to explain one?
The risk is not the model, it is the absence of a record. If you cannot show what data drove an outcome, which version of the system produced it, who reviewed it, and how an exception was handled, you have a finding regardless of how good the model is. So build the trail from day one. Documented inputs, versioned models, human review wherever the impact on a customer is material, and a written appeal path. Explainability is an operating requirement, not a feature.
As a director, how exposed am I if an AI decision goes wrong?
Take the legal answer from your own counsel in your own jurisdiction. The governance answer is the same everywhere I work. Your protection is the record of diligence. Did the board ask what the system does, require evidence, set limits on its authority, name an owner, and review it on a schedule. Boards get into difficulty when AI appears in management reports for a year with no minuted challenge. Governance is what you can show, not what you intended.
Discuss the scope
Discuss a system or workflow.
Share your objective, the decision you face, and your timeline. We can discuss the relevant work, the deliverables, and whether the engagement fits.
Contact MichaelRelated: AI governance for regulated institutions · Agentic AI governance · AI governance in the Middle East · All services