Skip to content

AI governance & implementation

Govern your AI.
Prove it.

AI is already in use across your business. We give you control of every system, and the evidence to show a regulator, auditor or customer exactly how it is controlled. Start with a free check, then Assess, Build, Monitor. One step or all three.

ISO 42001 Lead Implementer certified
ai-register / live.tsxRegister · Live
AI systemOwnerStatus
Customer support chatbotSupport OpsUnclassified
CV screening modelPeople teamUnclassified
Demand forecastingOperationsUnclassified
Marketing copy generatorMarketingUnclassified
0 / 4 evidenced✓ build passing

Three ways to work with us. One step or all three.

Assess

See what you’re running. Every AI system found and classified against ISO 42001 and the EU AI Act, with the obligations that attach. A fixed-scope audit, where most clients start.

from £1,500 · one-off

Build

Stand it up. A working AI Management System: register, classification, policies, accountability. Audit-ready on handover.

from £4,000 · one-off

Monitor

Keep it defensible. We run it month to month: reviews, risk register, board-ready assurance, on-call advice.

from £1,500/mo · ongoing

Not sure where you sit? Start with a free check →

Why now

AI moved faster than your governance did.

It arrived in tools you bought, tools your teams adopted on their own, and processes nobody formally signed off, and the obligations came with it. Regulators are applying existing law to AI now, not waiting for new rules. Procurement increasingly wants ISO 42001 before they will sign.

Free ISO 42001 check

See how your AI governance maturity measures up. Honest results in about ten minutes.

10 min No email
Take the check

Free EU AI Act check

Find out where you stand against the EU AI Act and which obligations apply to you.

10 min No email
Take the check

These are the ten-minute version. The full Assess audit goes deeper.

The reality

The exposure is already here.

0%
barely one in four

Only 24% of organisations can control what their AI agents actually do, with proper guardrails and live monitoring.

Source: Cisco AI Readiness Index 2025
0%
shadow AI is the norm

Staff at over 90% of companies use personal AI tools for work, while only 40% have official ones. Your data, in tools you don’t govern.

Source: MIT Project NANDA, The GenAI Divide, 2025
0M
or 7% of global turnover

The maximum penalty under the EU AI Act for the most serious breaches, whichever figure is higher.

Source: EU AI Act (Reg. (EU) 2024/1689), Art. 99

The problem

Knowing isn’t the same as proving.

ai-registerscanning…
?
?
?
?
?
?
?
?
?

No complete picture.

No single register of what AI is in use, who owns it, or what it touches. You can’t govern what you can’t see.

risk-tiersuntriaged
UNCLASSIFIED
UNCLASSIFIED
UNCLASSIFIED

No risk classification.

Without classifying each system against ISO 42001 and the EU AI Act, you don’t know which need real oversight and which don’t.

evidence.log0 records

No evidence trail.

When a regulator, auditor or customer asks you to demonstrate control, you need documentation, not a reassuring conversation.

We close all three: visibility, classification, and a standing evidence trail that holds up under scrutiny.

The stakes

Ungoverned AI is a risk you’re already carrying.

How we help

Start where you need to.

Some organisations need one thing done well. Others want it run for them as the rules keep moving. We do both, mapped to how we work across Nalgo: Assess, Build, Monitor. Take one step or all three. New to the standard? Start with our ISO 42001 implementation guide.

Here’s what that looks like in practice:

Assess

Classify the risk. Don’t guess it.

Every system scored against ISO 42001 and EU AI Act tiers, with the obligations that attach, so oversight lands where the risk actually is.

Free EU AI Act check
risk-classifier
System
CV screening model
High-risk· Employment
Obligations attached
Human oversight on every decision
Logging & traceability
Bias & fairness testing
Technical documentation
EU AI Act · Annex IIIISO 42001 · A.6 controls
deployment-gateAssessed before go-live
New AI tool requested
Notion AI
Requested by Marketing
Assessing…
·Data residency confirmed
·Vendor AI terms reviewed
·Usage controls applied

Monitor

New tools, assessed before they go live.

Every new AI tool runs the gate first: approved with controls, or sent for a DPIA. Risk gets caught before it’s in production, not after.

Talk to us

Monitor

Prove control on demand.

A standing evidence trail and board-ready reporting, ready the moment a regulator, auditor or customer asks, not assembled in a panic afterwards.

Free ISO 42001 check
assurance / March 2026Evidence · On
0governance decisions logged this quarter
Decision log
09:14CV screening, bias test logged
11:02New tool: Notion AI, approved w/ controls
14:37Risk register reviewed, 2 changes

The managed service

AI Governance as a Service (AIGaaS), end to end.

The Monitor track, in full.

A managed governance service that keeps your use of AI visible, controlled and defensible. It pairs a one-time AIMS set-up with an ongoing monthly service: regular reviews, risk register updates, assurance reporting and on-call advice. Add bolt-ons whenever you need them.

Core · included

Core services

The set-up plus the running of it, what every engagement includes.

AIMS set-up
One-off build of your AI Management System, audit-ready on handover.
Monthly governance operation
We run the system month to month so your team does not have to.
Policy & control framework
Proportionate controls kept current as your estate changes.
Quarterly assurance reporting
Board-ready reporting and a re-prioritised roadmap each quarter.
Risk register dashboard
A live view of every AI system, its owner and its status.
Bolt-on · as needed

Bolt-on services

Add to any engagement, one-off or ongoing, whenever the need arises.

EU AI Act advisory
AI DPIA advisory
Bias & explainability review
Third-party / vendor AI governance
Training & culture pack
Incident response
ISO 42001 certification support

What we do

Everything the management system needs.

Every deliverable, across Assess, Build and Monitor.

Assess Build Monitor
Assess

AI system discovery & register

Find every model, tool and integration in use, and who owns it.

Assess

Risk classification

Tier each system against ISO 42001 and the EU AI Act.

Build

Policy & control framework

Proportionate controls written to how you actually work.

Build

AIMS implementation

A complete management system, stood up audit-ready.

Monitor

Ongoing assurance (AIGaaS)

Kept live as your estate and the rules keep moving.

Monitor

Fractional AI governance lead

A named, embedded owner accountable to your board.

Build

Certification-readiness support

Prepared to pass when you choose to certify.

Recognised, not bespoke

ISO/IEC 42001EU AI ActNIST AI RMFUK GDPR & ICO

We anchor your governance to the frameworks your auditors, regulators and customers already trust, so the work is recognised, not invented.

Investment

Priced to your size, not a guess.

Every figure is a starting point. Final scope and price are confirmed after a short, no-obligation assessment, so you never pay for governance you don’t need.

Foundation

Smaller firms, lighter AI use

Assess · readiness audit
from £1,500
AIMS build (one-off)
from £4,000
Managed service (monthly)
from £1,500 / mo
Recommended

Growth

Mid-market, multiple AI systems

Assess · readiness audit
from £3,000
AIMS build (one-off)
from £8,000
Managed service (monthly)
from £3,000 / mo

Enterprise

Embedded ownership, board-facing, fractional lead

Assess · readiness audit
from £6,000 (scoped)
AIMS build (one-off)
scoped from £15,000
Managed service (monthly)
from £5,000 / mo

The path in

From first check to governed in weeks, not quarters.

01

Assess

We discuss your real footprint, the right step, and a fixed scope.

02

Build

We stand up your AIMS: register, classification, policies, accountability, literacy baseline.

03

Monitor

Keep it current with the ongoing service and board-ready reporting, and a named lead, if you want one.

Questions

The things people ask first.

There is no AI-specific UK law yet, why act now? +

The obligations already apply through existing rules. Regulators do not need a new AI law to hold you to account, and they do not need to find a problem first. Guidance is tightening through 2026, so getting ahead now means being ready rather than scrambling.

Do we have to sign up to a retainer? +

No. You can take a one-off assessment or a full implementation and walk away with everything we build; it is yours, no lock-in. Most clients move to the ongoing service once the system is in place, but that is a choice, not a condition.

What is the difference between a fractional lead and a consultant? +

A consultant delivers a report and leaves. A fractional lead is embedded and accountable for the outcome, working inside your team, so there is no gap the moment a project ends.

Why fractional rather than a full-time hire? +

Most mid-market firms cannot yet justify a full-time AI lead at six figures, and the talent is scarce. Fractional gives you the same accountable leadership at a fraction of the cost, scaling as your AI use grows, or handing over to a permanent hire later.

Do we need ISO 42001 certification? +

Not necessarily. The framework gives you a recognised, auditable backbone whether or not you certify, and it increasingly shows up as a procurement requirement. We implement the management system either way and support certification as a bolt-on.

We only use off-the-shelf AI tools, does this still apply? +

Yes. Most of your exposure comes from tools you have bought or staff are using, not models you have built, and that is exactly where ungoverned risk hides. The question is not whether you built the AI; it is what you are doing with it.

How do you handle our data? +

Under a clear data processing agreement, with your data kept in your environment wherever possible and nothing shared externally without agreement. We run the engagement to the standards we help you put in place.

How long and how much? +

Build runs 4 to 6 weeks; the ongoing service is monthly. Pricing scales with your size and AI footprint, with starting points above and a fixed scope and price confirmed after a short assessment.

How do we get started? +

With a free check. It is low-commitment, useful immediately, and tells us both whether there is a fit before anyone commits to more.

What's the difference between the free check and the Assess audit? +

The free checks are a ten-minute self-serve triage you can run right now. The Assess audit is the paid, fixed-scope version: we find and classify every system, confirm which obligations apply, and hand you a prioritised starting point.

See where you stand in ten minutes.

Take a free ISO 42001 or EU AI Act check. Honest results straight away, no email needed.