Skip to main content
IG-Smart — Governance, Risk & Assurance

AI Governance & Assurance

Board-Ready AI Governance and Assurance

Govern AI with clear accountability, proportionate controls and evidence that can withstand scrutiny.

Talk to a Senior PractitionerNeed to understand the current position
Submit a RequirementDefined scope, tender or RFP

IG-Smart helps regulated and high-consequence organisations establish the governance, risk management, impact assessment and assurance arrangements needed to adopt AI responsibly and demonstrate how material risks are being controlled.

From AI inventories and decision rights to ISO/IEC 42001 readiness, EU AI Act obligations and ongoing board assurance, we turn fragmented AI activity into a governable operating model.

When organisations engage us

When organisations engage us

  • AI adoption is accelerating

    Teams are adopting AI without a consistent governance model.

  • The Board wants visibility

    Leadership needs a defensible view of AI risk and controls.

  • EU AI Act exposure exists

    Roles, classifications and obligations need determining.

  • ISO 42001 is being considered

    Management-system readiness needs assessing.

  • High-impact use cases are emerging

    AI affects people, decisions or regulated outcomes.

  • Procurement requires evidence

    Buyers or investors want evidence of AI governance.

  • Existing policies are fragmented

    Functions are reviewing AI independently.

  • Senior AI governance capability is missing

    Experienced oversight is needed without a full-time role.

What we help solve

AI use often grows faster than the governance around it

Common patterns include:

  • AI tools adopted before ownership is defined
  • No complete inventory of AI systems or use cases
  • AI procured without proportionate risk assessment
  • Unclear provider, deployer, developer and business-owner responsibilities
  • Inconsistent approval criteria and no thresholds for escalating high-impact use
  • Privacy, security, legal and ethical reviews running separately
  • Model and supplier risk outside enterprise risk management
  • Weak records of why AI decisions were approved
  • Boards receiving innovation updates rather than assurance
  • Controls on paper that have never been tested

Meanwhile, regulatory obligations change faster than most governance processes.

The underlying issue

The problem is not AI adoption. It is AI adoption without clear accountability, evidence and assurance.

Adding more policies without knowing which AI systems exist, who owns them and how risk is assessed does not create governance.

What the engagement involves

Build the governance, evidence and assurance your AI environment requires

  • 01

    ISO 42001 Readiness

    Prepare the governance, management-system controls and evidence required for an AI Management System.

  • 02

    ISO 42001 Gap Analysis

    Compare the current AI governance position against ISO/IEC 42001 expectations and identify control, evidence and ownership gaps.

  • 03

    EU AI Act Readiness

    Identify relevant AI roles, classifications, obligations and evidence requirements and convert them into a practical readiness plan.

  • 04

    AI Governance Framework Consultancy

    Define AI roles, decision rights, policies, approvals, controls, escalation routes and assurance checkpoints.

  • 05

    Responsible AI Consultancy

    Translate responsible-AI principles into operational governance, decision criteria, controls and evidence.

  • 06

    AI Risk Management Consultancy

    Identify, assess, treat and monitor AI risks through structured risk registers, controls, escalation and senior reporting.

  • 07

    AI Impact Assessment Consultancy

    Assess how AI may affect individuals, rights, safety, decisions, operations and accountability before material risk escalates.

  • 08

    AI Governance Officer as a Service

    Access retained senior AI-governance leadership, oversight and reporting without creating a full-time internal role.

Talk to a Senior Practitioner

Definition

What is AI governance?

AI governance is the system of accountability, decision-making, controls and oversight through which an organisation directs the development, procurement and use of artificial intelligence. It defines who owns AI risk, how use cases are assessed and approved, what evidence is required and how performance, impacts and residual risks are monitored.

Definition

What is AI assurance?

AI assurance uses evidence, assessment, testing, review and independent challenge to determine whether AI systems and their governing controls are operating as intended and whether claims about safety, fairness, security, transparency, compliance or other relevant characteristics are sufficiently supported.

Governance, risk management and assurance overlap. Each depends on the others:

  • AI Governance

    • ownership
    • policies
    • decision rights
    • risk appetite
    • approvals
    • oversight
  • AI Risk Management

    • identification
    • assessment
    • treatment
    • monitoring
    • escalation
  • AI Assurance

    • evidence
    • review
    • testing
    • challenge
    • reporting
    • residual-risk visibility

AI Governance Control Loop

Govern AI across its lifecycle

AI governance should apply before procurement or deployment, not begin after a system is already in use.

Cross-cutting controls
  • Ownership & Accountability
  • Risk Management
  • Privacy & Data Protection
  • Security & Technical Controls
  • Human Oversight
  • Evidence & Documentation
  • Assurance & Reporting
  1. 01Identify
  2. 02Classify
  3. 03Assess
  4. 04Approve
  5. 05Deploy
  6. 06Monitor
  7. 07Change / Retire

Change / Retire feeds back into Identify — a continuous control loop.

IG-Smart’s practical governance model — not a sequence prescribed by any single regulation or framework.

Operating model

Who owns AI governance?

No single model suits every organisation. The right structure depends on whether the organisation builds, buys or deploys AI, its sector, regulatory exposure, scale, risk profile and use cases, and the privacy, security, risk and procurement functions already in place.

The objective is not another committee. It is clear decision rights and accountable ownership.

Example only — adapted to each organisation
  1. Board / Executive Oversight
  2. AI Governance Committee / Executive AI Forum
  3. Specialist input:
    • Risk
    • Legal
    • Privacy
    • Cyber
    • Procurement
    • Technology
    • Clinical / Operational SMEs
  4. AI System / Use-Case Owners
  5. Developers · Suppliers · Operational Teams

AI inventory & classification

You cannot govern AI you cannot see

A practical governance baseline, adapted to scope, typically records enough to decide how each system or use case should be governed.

An AI inventory should support decisions — not become another static register.

Typical inventory fields

  • Use case and owner
  • Business purpose
  • Supplier / provider
  • Affected individuals
  • Data involved
  • Automation and human oversight
Show all typical fields (10)
  • Decisions influenced
  • Regulatory classification and risk rating
  • Approval and monitoring status
  • Evidence location

AI risk

AI risk is multidimensional

Assessment should be proportionate to the use case, affected people and potential consequences. Not every category applies to every system.

  • Legal & accountability

    • Legal & Regulatory
    • Transparency & Explainability
    • Human Oversight
  • Data & security

    • Privacy & Data
    • Cybersecurity
    • Supplier / Model Dependency
  • People & outcomes

    • Bias & Fairness
    • Safety
    • Accuracy & Reliability
  • Organisational

    • Operational Resilience
    • Reputational
    • Financial / Commercial

Board-level AI assurance

What should the Board be able to see?

  • AI inventory

    What AI is being developed, bought or used?

  • Accountability

    Who owns each material use case and its risks?

  • Risk classification

    Which AI uses present greater legal, operational or human impact?

  • Controls

    What safeguards and approval requirements apply?

  • Evidence

    What supports claims about how the AI operates and how risk is controlled?

  • Monitoring

    What has changed since approval and what issues have emerged?

  • Residual risk

    What remains unresolved and who has accepted it?

Board assurance should show the position, not simply count AI projects or policies.

Regulatory and standards context

How the EU AI Act, ISO/IEC 42001 and UK guidance fit together

EU AI Act readiness

Applicability depends on the organisation's role, the AI system, the use case and territorial scope. Not all AI is high risk. Current position:

  • AI literacy provisions have applied since February 2025.
  • Governance and general-purpose AI model obligations began applying in August 2025.
  • Article 50 transparency obligations have applied from 2 August 2026.
  • From 2 August 2026, the AI Office and national competent authorities became responsible for implementing, supervising and enforcing the Act within their respective competences.
  • Most high-risk AI system obligations apply later: from 2 December 2027 for relevant Annex III use cases and from 2 August 2028 for AI embedded in regulated products.

European Commission: AI Act (opens in a new tab)

AI management systems and ISO/IEC 42001

ISO/IEC 42001:2023 specifies requirements for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System. It is an organisational management-system standard, not a technical model-performance standard.

IG-Smart provides readiness, gap analysis and implementation support. Certification is carried out by an independent certification body.

ISO/IEC 42001 on iso.org (opens in a new tab)

AI governance in the UK

The UK does not have a single horizontal AI Act. Its environment combines existing cross-cutting law, sector-specific regulation, regulator-led AI governance, government risk-management guidance and emerging assurance practice, including the Trusted Third-Party AI Assurance Roadmap.

Organisations may need to govern the same AI use case against several overlapping obligations rather than a single AI-specific law.

In September 2026, the UK Department for Science, Innovation and Technology published an AI Risk Management Toolkit to support teams designing, operating, procuring or delivering AI products. IG-Smart can use relevant current guidance as one input into an organisation-specific approach; it is not in itself a mandatory compliance framework.

International reference

NIST AI Risk Management Framework

A voluntary framework for managing AI risk across design, development, deployment and use. NIST AI RMF 1.0 remains available; NIST has stated that it is being revised. IG-Smart treats it as a version-controlled reference, not a dependency.

NIST AI RMF (opens in a new tab)

Responsible AI

Responsible AI should become operational governance

Responsible AI principles only become meaningful when translated into:

  1. Owners
  2. Decision criteria
  3. Controls
  4. Evidence
  5. Monitoring
  6. Escalation

AI impact assessment

Assess impact before approval

An assessment may need to consider:

  • Affected individuals
  • Purpose and decision significance
  • Rights and privacy
  • Bias and fairness
  • Safety and security
  • Explainability and oversight
  • Foreseeable misuse
  • Residual risk

It should be proportionate to the use case and connect directly to approval, mitigation and monitoring decisions.

Procurement & third-party AI

Buying AI does not outsource accountability

Third-party AI may require governance around:

  • Purpose and permitted use
  • Supplier role and dependencies
  • Training or input data
  • Security and data protection
  • Performance limitations
  • Transparency and human oversight
  • Contractual and change commitments
  • Monitoring and exit

Supplier assurance should feed the organisation's own AI risk position rather than end with a completed questionnaire. See also Cyber Governance & Assurance.

How we deliver

How IG-Smart approaches an AI governance and assurance engagement

  1. 01

    Assess

    Establish the AI inventory, use cases, stakeholders, applicable obligations, risk profile, existing controls and material governance gaps.

  2. 02

    Build

    Define roles, decision rights, risk methodology, approval criteria, policies, controls, impact-assessment processes and evidence requirements.

  3. 03

    Manage

    Support the operating rhythm — AI registers, governance forums, risk reviews, approvals, actions, reporting and regulatory change.

  4. 04

    Assure

    Test whether governance and controls are operating as intended and whether evidence supports the organisation's claims and decisions.

  5. 05

    Improve

    Close findings, strengthen maturity and adapt the governance model as AI systems, regulation, standards and risk change.

Improvement feeds the next assessment cycle, keeping the AI governance position current rather than rebuilding it from scratch.

What you receive

What does an AI Governance & Assurance engagement produce?

Depending on scope and maturity, outputs may include:

  1. 01AI governance current-state assessmentA documented view of AI use, accountability, controls, evidence and material gaps.
  2. 02AI inventory and classification modelA governable record of AI use cases, ownership, risk and approval status.
  3. 03AI governance frameworkRoles, decision rights, policies, approval routes, escalation and assurance requirements.
  4. 04AI risk methodology and registerProportionate assessment criteria, risk ownership, treatment and residual-risk visibility.
  5. 05AI impact-assessment frameworkStructured assessment of material impacts before approval or deployment.
  6. 06Board / executive assurance reportingDecision-ready visibility of AI adoption, material risk, findings, remediation and residual exposure.
  7. 07Regulatory / standards readiness roadmapPrioritised actions against relevant obligations or frameworks such as the EU AI Act or ISO/IEC 42001.
  8. 08Evidence packRelevant governance evidence organised for procurement, customer, audit, certification-readiness or regulatory scrutiny.

Scope

AI governance, legal advice, technical testing and certification are connected — but different

  • IG-Smart's focus

    AI Governance & Assurance

    Governance design, risk oversight, evidence, impact assessment, assurance and executive reporting.

  • Legal Advice

    Where formal legal advice or legal opinion is required, it should be obtained from appropriately qualified legal counsel. IG-Smart can work alongside the client's legal advisers so that legal interpretation, governance design and assurance remain appropriately connected.

  • Technical AI Testing

    Model evaluation, red teaming, bias testing, security testing or specialist validation may require separate technical expertise depending on scope.

  • ISO Certification

    IG-Smart supports ISO/IEC 42001 readiness and implementation. Accredited certification is carried out by an independent certification body.

Common engagement models

Assessment, build or managed governance?

  • AI governance assessment

    A defined-scope review of AI use, inventory, risk controls and evidence against relevant frameworks.

    Suits

    Organisations that need to understand their AI governance position before scaling or procurement.

  • AI governance build programme

    Phased design of roles, policies, risk processes, inventory and assurance arrangements.

    Suits

    Organisations establishing AI governance or preparing for ISO/IEC 42001 readiness.

  • Managed AI governance

    Ongoing senior oversight of the AI inventory, new use cases, risk reviews and board reporting.

    Suits

    Organisations with a growing portfolio of AI use cases that need continuing independent oversight.

Typical investment

Indicative investment

  • AI Governance assessment / assurance

    Starting investment: £12,500 + VAT

    Typical investment: £12,500–£15,000 + VAT

    Model: Defined-scope engagement

  • AI governance build / programme

    Starting investment: £25,000 + VAT

    Larger programmes individually scoped

    Model: Phased programme

  • Managed AI Governance

    Starting investment: £5,000 + VAT per month

    Subject to service scope

    Model: Managed & retained service

Scope, deliverables, assumptions and fees are agreed in writing before work begins. What changes the fee is set out on the investment page; the exact fee is confirmed after scoping.

How engagements and investment work

FAQ

Frequently asked questions

Regulatory and standards references reviewed September 2026. This page is reviewed every 3 months.

Discuss an AI governance requirement

Need a clearer, more defensible view of your AI position?

Whether you need to establish governance, assess risk, prepare for ISO/IEC 42001, understand EU AI Act obligations or build ongoing assurance, start with the position you need to understand or demonstrate.