03/ AI GOVERNANCE
Chances are, your team is already using AI. Make sure the business is ready.
ChatGPT, Claude, Copilot, and dozens of embedded AI features are now part of how your team works. AI Governance is about putting enough structure around it that you get the productivity gains without giving away client data, making bad decisions on bad outputs, or failing an audit.
On this page
The problem with “Shadow AI”
In most small organizations, AI adoption has outpaced AI governance. Staff are pasting client information into chatbots, uploading confidential documents into LLMs and vendors are shipping AI features nobody approved. Funders and regulators are starting to ask pointed questions. Nobody’s doing anything wrong on purpose, there’s just no clear line between “use this” and “don’t use this”.
AI Governance is what we call the work of drawing that line, in a way your team will actually follow.
What we do
- AI inventory — what's in use, where, and by whom (including embedded SaaS features nobody signed off on)
- AI risk assessment mapped to NIST AI RMF and ISO/IEC 42001 principles
- Acceptable-use policy for generative AI — written for humans, not lawyers
- Vendor due-diligence support for AI-enabled tools and platforms
- Staff training on safe, effective use of AI in day-to-day work
- Board- and funder-ready summary of your AI governance posture
Frameworks we draw from
Our work is grounded in NIST AI RMF, ISO/IEC 42001. We translate, we don’t drop framework documents on your desk and leave.
What you walk away with
A clear picture of how AI is already being used in your organization, a policy that fits your culture, and a short list of controls that cut real risk without killing the productivity story. Plus a defensible answer when a client, funder, or auditor asks “So, what’s your AI policy?”
If a funder asked for your AI policy tomorrow, would you have one?