Enterprise IT
From hours of reporting to a 12-second answer
12s
Answer time, down from hours of manual reporting
Nalgo builds a working AI Management System, not a policy PDF, so when a customer, board or regulator asks how you control your AI, the evidence is already there.
Nalgo helps organisations implement ISO 42001, prepare for certification, conduct independent internal audits and build effective AI literacy programmes.
We make AI governance practical, proportionate and usable - not another layer of paperwork.
Practical AI governance services to help you manage AI responsibly, meet emerging obligations and build trust in how AI is used.
From gap analysis and implementation through to certification readiness, we help you build an AI Management System that works in practice.
Explore ISO 42001Role-based AI literacy programmes that help your people understand, use and govern AI responsibly.
Explore AI TrainingIndependent ISO 42001 audits and readiness reviews that test your controls, evidence and management system before external scrutiny.
Explore Audit & AssuranceUnderstand how the EU AI Act applies to your organisation, which obligations matter and what you need to prioritise.
Explore EU AI Act
Our audit finds your highest value AI use cases using our ADAPT framework, before you commit budget.
Production agents that run whole workflows end to end inside your systems, with guardrails and human checkpoints so you stay in control.
Audits, ISO 42001 and a working AI management system, plus EU AI Act readiness, kept current as the rules move.
Web and mobile apps, integrations and AI-powered systems completely customised to solve your unique problems.
Working out where AI fits, then building, shipping and governing it, under one roof.
From a first AI audit through a working management system, we give you control of every AI system and the evidence to show a regulator or customer how it is governed.
We take you from gap analysis through a working AI Management System to certification-readiness against ISO 42001, proportionate to your size.
We tell you what applies to your AI, what is deferred, and what to do next, with fixed-scope diagnostics and ADAPT-led delivery.
We will find your highest-value use cases and map the priorities so effort goes to the thing actually worth building.
We build agents and automations that take processes off your team, with the human checkpoints that make handing real work to an autonomous system a sensible idea rather than a leap of faith.
Web and internal apps, integrations and AI-powered systems. Built to solve your unique problems.
Tools we build with
A thorough business analysis and gap analysis that shows where AI genuinely works for you, the highest-value opportunities and the risks worth knowing, before you commit budget to a build.
Build the whole system, agents, automation and the software around them, shipped to production on infrastructure you own, with the guardrails built in.
Keep your live AI accurate, compliant and performing as your data, the models and the rules all change, so it stays trustworthy long after launch.
Three free, self-serve checks. Honest results straight away, no email needed.
Score your organisation across the five ADAPT dimensions and see where AI genuinely fits.
See how your AI governance maturity measures up. Honest results in about ten minutes.
Find out where you stand against the EU AI Act and which obligations apply to you.
Start small. Assess, Build and Monitor are independent. Plenty of clients begin with a fixed-scope assessment and act on the roadmap with or without us. You only move to a build, or to ongoing monitoring, when it earns its place.
It depends on the work, but the shape is consistent. An assessment is fixed-scope, so you get a fixed price before you start. A build, whether agents, automation or custom software, is scoped and quoted per project once we know what we are building. Governance runs as a monthly retainer so it stays current as the rules move. You always see the number before you commit.
Then we tell you, and that is a good outcome. The readiness assessment exists to find where AI genuinely helps and, just as importantly, where it does not. We would rather point you at a simpler fix, or nothing at all, than sell you a build you do not need. The roadmap is yours either way.
The repetitive, multi-step work that eats your team's time: triaging and routing requests, pulling data together from several systems, drafting and updating records, chasing the next step in a process, handling routine cases end to end and escalating the rest. The test is not "is it clever", it is "does it reliably take a real job off someone's plate". We start from where that is true for you, not from a demo.
Yes, that is the point of one. An agent works by using your existing tools: your CRM, your inbox, your databases, your internal apps. We connect it to what you already run, with its access scoped to exactly what it needs and nothing more, so it fits into how your team already works rather than becoming another system to maintain.
Every agent runs inside permission boundaries you set, with human checkpoints at the decisions that matter and an audit trail on everything it does. It acts autonomously where that is safe and asks for a human where it is not. Handing real work to an autonomous system should be a sensible decision, not a leap of faith.
Both. Alongside the AI work we build web and internal apps, integrations and the software around a system, shipped to production, clean and maintainable. Often the AI is the easy part and the real value is in the software that puts it in front of your team, so we build both together.
If you are using or building AI in any way that touches customers, staff or decisions, then yes, but it does not have to be heavy. Governance is simply knowing what your AI is doing, being able to show it is safe and compliant, and catching problems before they become incidents. It scales to your size: a small deployment needs a light framework, not a committee. Increasingly it is also what customers, insurers and regulators expect to see, so getting it right early is far cheaper than retrofitting it later.
ISO 42001 is the international standard for managing AI responsibly, the AI equivalent of ISO 27001 for information security. It sets out how an organisation governs, monitors and improves its AI systems, and it is certifiable, so you can prove your approach rather than just assert it. You do not always need full certification, but the framework is the backbone of doing AI well, and increasingly it is what enterprise customers and procurement teams ask for. We are ISO 42001 Lead Implementer certified and build to it as standard.
They solve the same problem from two directions. The EU AI Act is the law: it tells you what you must do. ISO 42001 is the management system: it gives you a practical, auditable way to actually do it and prove it. Building to ISO 42001 is one of the cleanest routes to being ready for the Act, because the governance, documentation and oversight it demands are largely the same evidence a regulator or customer will ask you for. We work across both, so compliance is built in rather than bolted on afterwards.
Very possibly. The Act reaches beyond the EU: if your AI system is used by people in the EU, or its output is used there, the obligations can apply wherever your business sits. Being outside the EU does not exempt you. The fastest way to know is the free EU AI Act check, which maps your situation to the obligations that actually attach to you in about ten minutes.
The Digital Omnibus pushed the EU AI Act's high-risk obligations out to 2027 and 2028, so many teams assumed they had breathing room. Article 50 was not part of that delay. Its transparency duties have applied since 2 August 2026, they cover ordinary chatbots and AI-generated content, and one marking deadline still lands on 2 December 2026.
If you already run ISO 27001, a large part of ISO 42001 is a system you have already built. The management structure carries over almost wholesale. What is genuinely new is the AI-specific substance: the impact assessment, the AI controls, and a risk lens that reaches beyond your own organisation.
We help you find what’s worth doing, build it for real, and keep it running - so the AI in your business is something you can rely on, long after launch. Whenever you’re ready, let’s talk.