SERVICE
AI governance and compliance
Being able to show how an automated decision was made, months later.
What this actually is
AI governance is the ability to answer, months afterwards, why a specific automated decision was made about a specific person — and to show that a human could have intervened. That is now a legal requirement in several jurisdictions rather than a matter of good practice.
It is an engineering problem before it is a policy one. A policy that says decisions will be explainable, sitting over a system that logged nothing, is a liability rather than a control. The logging, versioning and evaluation have to be designed in.
What we do
Inventory and risk classification
Which AI systems exist, what they decide, and which fall into a regulated category — a list most organisations discover is longer than expected.
Audit trails
Inputs, model version, retrieved context and output, recorded so a decision can be reconstructed rather than described.
Evaluation and bias testing
Held-out sets, subgroup performance and documented thresholds, versioned with the system.
Human oversight
Where a person must approve, how they see the reasoning, and how an override is recorded so oversight is real rather than nominal.
The stack
What it connects to
Integration surface is the honest driver of effort — ten systems is not ten times one system.
- Model and prompt versioning systems
- Logging and observability stacks
- Identity and access management
- GRC and risk register tooling
- Data catalogues and lineage
How a project runs
Inventory
1–2 weeks
Every AI system, what it decides, and its risk classification.
Gap analysis
1–2 weeks
What is required versus what exists, in engineering terms rather than policy language.
Implementation
4–10 weeks
Logging, evaluation, versioning and oversight built into the systems themselves.
Documentation
1–2 weeks
Technical documentation that satisfies a reviewer without requiring one of us in the room.
Where teams use it
Financial services
Credit and fraud decisions where an explanation may be demanded by a regulator or a customer.
Healthcare
Clinical decision support where oversight and audit are conditions of use, not features.
HR
Screening and assessment tools, which sit in a high-risk category in most emerging regimes.
Insurance
Pricing and claims decisions requiring demonstrable consistency across groups.
Any EU-facing product
AI Act obligations that depend on documentation existing from the start rather than being assembled later.
When this is the wrong answer
We are engineers, not your legal counsel. We build to the standard your legal team sets and tell you plainly what the system can and cannot currently demonstrate.
Governance retrofitted onto a system that logged nothing means rebuilding parts of it. The cost of designing this in is a fraction of the cost of adding it.
A policy document without technical enforcement is worse than none, because it creates a written commitment you are demonstrably not meeting.
Frequently asked questions
Does the EU AI Act apply to us?
If you serve EU users with a system making or supporting decisions about them, probably. The classification determines the obligations, and that is the first thing the inventory establishes.
Can you make an existing system compliant?
Usually — the work is adding logging, evaluation and oversight. How much rebuilding that requires depends entirely on what was recorded originally, which is why the gap analysis comes before any estimate.
Is this just documentation?
No. Documentation describing controls that do not exist is a liability. The engineering comes first and the documentation describes it.
Who owns the code?
You do, from the first commit — work happens in your repository under your licence, and the contract assigns IP outright. We keep no rights and build no dependency that makes leaving expensive.
What does it cost?
We do not publish a number, because the honest one depends on scope, integrations and the accuracy bar. Tell us the budget you are working with and we will say what it buys — or say plainly if it does not buy enough.
Is this only for the EU?
No. The EU AI Act is the most prescriptive regime so far, but sector regulators in finance and healthcare already require explainability and audit, and several other jurisdictions are moving the same way.
What if we do not know what AI we have?
That is the normal starting point and it is what the inventory is for. Shadow AI — a team using a model through a SaaS product nobody registered — is usually the largest single finding.
Does governance slow delivery down?
Designed in, barely. Retrofitted, considerably — because it means rebuilding systems that logged nothing. The cost difference between the two is the argument for doing it early.
Can you certify us?
No. We are engineers, not an auditor or a notified body, and anyone offering both the build and the certification has a conflict you should be wary of. We build to the standard and document it for whoever assesses you.
How do we start?
A scoping call, then a short written proposal with scope, sequence and the assumptions it rests on. If we think you should not do this, or should do a smaller version first, that is what the proposal says.
Can our team take it over afterwards?
That is the intended end state. Standard technology, decisions documented as they are made, and handover sessions with your engineers. If a system can only be maintained by us, we built it wrong.
Related
Before you choose anyone
Written to be useful whether or not you hire us — including the parts that argue against hiring an agency at all.
How to choose an AI development company
ReadAI agency vs in-house team
ReadCustom AI vs off-the-shelf
ReadOffshore vs local AI development
ReadAI Voice Agents: The Complete Guide for Businesses (2026)
ReadRAG vs Fine-Tuning: Which Does Your Business Need?
ReadHow Much Does AI Development Cost in 2026?
ReadAI Governance & Compliance — tell us the scope
Tell us what you are building. We reply within one business day.
