SERVICE

AI governance and compliance

Being able to show how an automated decision was made, months later.

What this actually is

AI governance is the ability to answer, months afterwards, why a specific automated decision was made about a specific person — and to show that a human could have intervened. That is now a legal requirement in several jurisdictions rather than a matter of good practice.

It is an engineering problem before it is a policy one. A policy that says decisions will be explainable, sitting over a system that logged nothing, is a liability rather than a control. The logging, versioning and evaluation have to be designed in.

What we do

  1. Inventory and risk classification

    Which AI systems exist, what they decide, and which fall into a regulated category — a list most organisations discover is longer than expected.

  2. Audit trails

    Inputs, model version, retrieved context and output, recorded so a decision can be reconstructed rather than described.

  3. Evaluation and bias testing

    Held-out sets, subgroup performance and documented thresholds, versioned with the system.

  4. Human oversight

    Where a person must approve, how they see the reasoning, and how an override is recorded so oversight is real rather than nominal.

The stack

PythonMLflowOpenTelemetryPostgreSQLEvaluation harnessesModel and prompt versioning

What it connects to

Integration surface is the honest driver of effort — ten systems is not ten times one system.

How a project runs

Inventory

1–2 weeks

Every AI system, what it decides, and its risk classification.

Gap analysis

1–2 weeks

What is required versus what exists, in engineering terms rather than policy language.

Implementation

4–10 weeks

Logging, evaluation, versioning and oversight built into the systems themselves.

Documentation

1–2 weeks

Technical documentation that satisfies a reviewer without requiring one of us in the room.

Where teams use it

Financial services

Credit and fraud decisions where an explanation may be demanded by a regulator or a customer.

Healthcare

Clinical decision support where oversight and audit are conditions of use, not features.

HR

Screening and assessment tools, which sit in a high-risk category in most emerging regimes.

Insurance

Pricing and claims decisions requiring demonstrable consistency across groups.

Any EU-facing product

AI Act obligations that depend on documentation existing from the start rather than being assembled later.

When this is the wrong answer

We are engineers, not your legal counsel. We build to the standard your legal team sets and tell you plainly what the system can and cannot currently demonstrate.

Governance retrofitted onto a system that logged nothing means rebuilding parts of it. The cost of designing this in is a fraction of the cost of adding it.

A policy document without technical enforcement is worse than none, because it creates a written commitment you are demonstrably not meeting.

Frequently asked questions

Does the EU AI Act apply to us?

If you serve EU users with a system making or supporting decisions about them, probably. The classification determines the obligations, and that is the first thing the inventory establishes.

Can you make an existing system compliant?

Usually — the work is adding logging, evaluation and oversight. How much rebuilding that requires depends entirely on what was recorded originally, which is why the gap analysis comes before any estimate.

Is this just documentation?

No. Documentation describing controls that do not exist is a liability. The engineering comes first and the documentation describes it.

Who owns the code?

You do, from the first commit — work happens in your repository under your licence, and the contract assigns IP outright. We keep no rights and build no dependency that makes leaving expensive.

What does it cost?

We do not publish a number, because the honest one depends on scope, integrations and the accuracy bar. Tell us the budget you are working with and we will say what it buys — or say plainly if it does not buy enough.

Is this only for the EU?

No. The EU AI Act is the most prescriptive regime so far, but sector regulators in finance and healthcare already require explainability and audit, and several other jurisdictions are moving the same way.

What if we do not know what AI we have?

That is the normal starting point and it is what the inventory is for. Shadow AI — a team using a model through a SaaS product nobody registered — is usually the largest single finding.

Does governance slow delivery down?

Designed in, barely. Retrofitted, considerably — because it means rebuilding systems that logged nothing. The cost difference between the two is the argument for doing it early.

Can you certify us?

No. We are engineers, not an auditor or a notified body, and anyone offering both the build and the certification has a conflict you should be wary of. We build to the standard and document it for whoever assesses you.

How do we start?

A scoping call, then a short written proposal with scope, sequence and the assumptions it rests on. If we think you should not do this, or should do a smaller version first, that is what the proposal says.

Can our team take it over afterwards?

That is the intended end state. Standard technology, decisions documented as they are made, and handover sessions with your engineers. If a system can only be maintained by us, we built it wrong.

Related

Before you choose anyone

Written to be useful whether or not you hire us — including the parts that argue against hiring an agency at all.

AI Governance & Compliance — tell us the scope

Tell us what you are building. We reply within one business day.