← Consultancy
AI governance

Use AI safely, and prove it

Find the AI your people already use, set the rules, and build a governance programme aligned to the EU AI Act, ISO 42001 and NIST AI RMF.

EU AI ActISO/IEC 42001NIST AI RMFShadow AI discovery
AI inventory27 tools found
Chat General-purpose chat assistantsUsed by 61% of staff Review
Code AI coding assistantsSource code shared High
HR CV screening toolHigh-risk under EU AI Act High
Sales Meeting transcriptionApproved, DPA signed OK
Why it's different

Governance that lets people use AI, not bans it

The usual way With Touchpoint
A policy nobody reads A short acceptable-use policy, trained and signed
No idea which AI tools are in use Shadow AI discovered from your own logs
Every use case treated the same Risk-tiered against the EU AI Act categories
Vendors trusted on their word AI suppliers assessed like any other supplier
Governance as a one-off project Controls reviewed quarterly
What we cover

From discovery to certification

Shadow AI discovery Which AI tools are in use, by whom, with what data.
Acceptable-use policy Clear rules staff can follow.
Risk classification Use cases tiered under the EU AI Act.
AI supplier assessments Data handling, training use and model risk.
ISO 42001 readiness Gap assessment and management-system build.
Technical controls DLP, access controls and logging for AI tools, implemented by our engineers.
How it works

Four weeks to a working AI programme

  1. 01 Discover Inventory AI use from logs, surveys and interviews.
  2. 02 Classify Tier each use case by risk and regulation.
  3. 03 Govern Policy, roles, approval process and training.
  4. 04 Control DLP and access controls implemented where needed.
  5. 05 Assure Controls owned and reviewed quarterly.
What you get

Evidence the board and regulators will ask for

A programme you can show, not just describe.

✓ AI inventoryEvery tool and use case, with owners.
✓ Acceptable-use policyApproved and trained.
✓ Risk registerUse cases tiered against the EU AI Act.
✓ Supplier assessmentsFor your AI vendors.
✓ ISO 42001 gap reportWhere you stand against certification.
✓ Board briefingAI risk in plain language.
Engagement options

Where to start

Quick start AI risk review A fast view of AI use and risk.
  • ✓Shadow AI discovery
  • ✓Top risks
  • ✓Acceptable-use policy
  • ✓Board briefing
Get a fixed quote →
Most chosen Governance programme A working AI management system.
  • ✓Everything in the review
  • ✓Risk classification
  • ✓Supplier assessments
  • ✓Controls implemented
Get a fixed quote →
Certification ISO 42001 readiness For organisations seeking certification.
  • ✓Gap assessment
  • ✓Management-system build
  • ✓Internal audit
  • ✓Certification support
Get a fixed quote →
Questions

Before you ask

Does the EU AI Act apply to us?+

If you use or sell AI in the EU, parts of it likely do. We’ll tell you which obligations apply to your use cases.

Will you ban tools?+

Only where the risk warrants it. The goal is safe use, not no use.

Can you certify us to ISO 42001?+

We prepare you; an accredited certification body issues the certificate.

Can you implement the controls?+

Yes. Our engineers can deploy DLP, access and logging controls for AI tools.

Get ahead of AI risk

Tell us how your teams use AI today. We’ll show you what needs governing first.

Start an AI review
Other consultancy services Penetration testing→ Cloud security→ Tabletop exercises→ vCISO→