Skip to content

AI governance built around your business

Two colleagues reviewing a laptop and documents at a meeting table

Nalgo builds a working AI Management System, not a policy PDF, so when a customer, board or regulator asks how you control your AI, the evidence is already there.

Build trust in AI with practical governance that stands up to scrutiny.

Nalgo helps organisations implement ISO 42001, prepare for certification, conduct independent internal audits and build effective AI literacy programmes.

We make AI governance practical, proportionate and usable - not another layer of paperwork.

What we do

Practical AI governance services to help you manage AI responsibly, meet emerging obligations and build trust in how AI is used.

ISO 42001 Consulting

From gap analysis and implementation through to certification readiness, we help you build an AI Management System that works in practice.

Explore ISO 42001

AI Literacy & Training

Role-based AI literacy programmes that help your people understand, use and govern AI responsibly.

Explore AI Training

Internal Audit & Assurance

Independent ISO 42001 audits and readiness reviews that test your controls, evidence and management system before external scrutiny.

Explore Audit & Assurance

EU AI Act Readiness

Understand how the EU AI Act applies to your organisation, which obligations matter and what you need to prioritise.

Explore EU AI Act

Outcomes we’ve shipped

Enterprise IT

From hours of reporting to a 12-second answer

12s

Answer time, down from hours of manual reporting

Read story

Private equity

Turned manual prospect research into qualified, ready-to-pitch leads

73%

More qualified pipeline from the same headcount

Read story

B2B SaaS

Gave product managers a portal to ask anything of their customer data

2,000+

Customer signals behind each roadmap decision

Read story

How we help

Working out where AI fits, then building, shipping and governing it, under one roof.

AI governance

From a first AI audit through a working management system, we give you control of every AI system and the evidence to show a regulator or customer how it is governed.

ISO 42001 consulting

We take you from gap analysis through a working AI Management System to certification-readiness against ISO 42001, proportionate to your size.

EU AI Act consulting

We tell you what applies to your AI, what is deferred, and what to do next, with fixed-scope diagnostics and ADAPT-led delivery.

AI readiness

We will find your highest-value use cases and map the priorities so effort goes to the thing actually worth building.

AI agent development and automation

We build agents and automations that take processes off your team, with the human checkpoints that make handing real work to an autonomous system a sensible idea rather than a leap of faith.

Custom Software development

Web and internal apps, integrations and AI-powered systems. Built to solve your unique problems.

Tools we build with

Assess. Build. Monitor.

Assess

A thorough business analysis and gap analysis that shows where AI genuinely works for you, the highest-value opportunities and the risks worth knowing, before you commit budget to a build.

Build

Build the whole system, agents, automation and the software around them, shipped to production on infrastructure you own, with the guardrails built in.

Monitor

Keep your live AI accurate, compliant and performing as your data, the models and the rules all change, so it stays trustworthy long after launch.

See where you stand

Three free, self-serve checks. Honest results straight away, no email needed.

Free AI readiness check

Score your organisation across the five ADAPT dimensions and see where AI genuinely fits.

Free ISO 42001 check

See how your AI governance maturity measures up. Honest results in about ten minutes.

Free EU AI Act check

Find out where you stand against the EU AI Act and which obligations apply to you.

Nalgo FAQs

Can we start small, or do we have to commit to everything?

Start small. Assess, Build and Monitor are independent. Plenty of clients begin with a fixed-scope assessment and act on the roadmap with or without us. You only move to a build, or to ongoing monitoring, when it earns its place.

What does an engagement cost?

It depends on the work, but the shape is consistent. An assessment is fixed-scope, so you get a fixed price before you start. A build, whether agents, automation or custom software, is scoped and quoted per project once we know what we are building. Governance runs as a monthly retainer so it stays current as the rules move. You always see the number before you commit.

What if the assessment finds AI isn't worth doing?

Then we tell you, and that is a good outcome. The readiness assessment exists to find where AI genuinely helps and, just as importantly, where it does not. We would rather point you at a simpler fix, or nothing at all, than sell you a build you do not need. The roadmap is yours either way.

What kind of work can an agent actually take on?

The repetitive, multi-step work that eats your team's time: triaging and routing requests, pulling data together from several systems, drafting and updating records, chasing the next step in a process, handling routine cases end to end and escalating the rest. The test is not "is it clever", it is "does it reliably take a real job off someone's plate". We start from where that is true for you, not from a demo.

Can an agent work with the tools and systems we already use?

Yes, that is the point of one. An agent works by using your existing tools: your CRM, your inbox, your databases, your internal apps. We connect it to what you already run, with its access scoped to exactly what it needs and nothing more, so it fits into how your team already works rather than becoming another system to maintain.

How do we stay in control of an agent that acts on its own?

Every agent runs inside permission boundaries you set, with human checkpoints at the decisions that matter and an audit trail on everything it does. It acts autonomously where that is safe and asks for a human where it is not. Handing real work to an autonomous system should be a sensible decision, not a leap of faith.

Do you build ordinary software, or only AI?

Both. Alongside the AI work we build web and internal apps, integrations and the software around a system, shipped to production, clean and maintainable. Often the AI is the easy part and the real value is in the software that puts it in front of your team, so we build both together.

Do we actually need AI governance?

If you are using or building AI in any way that touches customers, staff or decisions, then yes, but it does not have to be heavy. Governance is simply knowing what your AI is doing, being able to show it is safe and compliant, and catching problems before they become incidents. It scales to your size: a small deployment needs a light framework, not a committee. Increasingly it is also what customers, insurers and regulators expect to see, so getting it right early is far cheaper than retrofitting it later.

What is ISO 42001, and do we need it?

ISO 42001 is the international standard for managing AI responsibly, the AI equivalent of ISO 27001 for information security. It sets out how an organisation governs, monitors and improves its AI systems, and it is certifiable, so you can prove your approach rather than just assert it. You do not always need full certification, but the framework is the backbone of doing AI well, and increasingly it is what enterprise customers and procurement teams ask for. We are ISO 42001 Lead Implementer certified and build to it as standard.

How do ISO 42001 and the EU AI Act fit together?

They solve the same problem from two directions. The EU AI Act is the law: it tells you what you must do. ISO 42001 is the management system: it gives you a practical, auditable way to actually do it and prove it. Building to ISO 42001 is one of the cleanest routes to being ready for the Act, because the governance, documentation and oversight it demands are largely the same evidence a regulator or customer will ask you for. We work across both, so compliance is built in rather than bolted on afterwards.

Does the EU AI Act apply to us if we're based in the UK?

Very possibly. The Act reaches beyond the EU: if your AI system is used by people in the EU, or its output is used there, the obligations can apply wherever your business sits. Being outside the EU does not exempt you. The fastest way to know is the free EU AI Act check, which maps your situation to the obligations that actually attach to you in about ten minutes.

Words from the team

7 min read

EU AI Act Article 50: the transparency rules are now in force

The Digital Omnibus pushed the EU AI Act's high-risk obligations out to 2027 and 2028, so many teams assumed they had breathing room. Article 50 was not part of that delay. Its transparency duties have applied since 2 August 2026, they cover ordinary chatbots and AI-generated content, and one marking deadline still lands on 2 December 2026.

EU AI Act AI transparency AI governance
Read story
9 min read

How ISO 42001 fits onto your existing ISO 27001

If you already run ISO 27001, a large part of ISO 42001 is a system you have already built. The management structure carries over almost wholesale. What is genuinely new is the AI-specific substance: the impact assessment, the AI controls, and a risk lens that reaches beyond your own organisation.

ISO 42001 ISO 27001 AI governance
Read story

Nalgo, Your AI partner

We help you find what’s worth doing, build it for real, and keep it running - so the AI in your business is something you can rely on, long after launch. Whenever you’re ready, let’s talk.