IG-Smart helps regulated and high-consequence organisations establish the governance, risk management, impact assessment and assurance arrangements needed to adopt AI responsibly and demonstrate how material risks are being controlled.
From AI inventories and decision rights to ISO/IEC 42001 readiness, EU AI Act obligations and ongoing board assurance, we turn fragmented AI activity into a governable operating model.
Board-Level AI Governance
Risk-Based Oversight
Regulatory Readiness
Independent Assurance
Defensible Evidence
When organisations engage us
When organisations engage us
AI adoption is accelerating
Teams are adopting AI without a consistent governance model.
The Board wants visibility
Leadership needs a defensible view of AI risk and controls.
EU AI Act exposure exists
Roles, classifications and obligations need determining.
ISO 42001 is being considered
Management-system readiness needs assessing.
High-impact use cases are emerging
AI affects people, decisions or regulated outcomes.
Procurement requires evidence
Buyers or investors want evidence of AI governance.
Existing policies are fragmented
Functions are reviewing AI independently.
Senior AI governance capability is missing
Experienced oversight is needed without a full-time role.
What we help solve
AI use often grows faster than the governance around it
Common patterns include:
AI tools adopted before ownership is defined
No complete inventory of AI systems or use cases
AI procured without proportionate risk assessment
Unclear provider, deployer, developer and business-owner responsibilities
Inconsistent approval criteria and no thresholds for escalating high-impact use
Privacy, security, legal and ethical reviews running separately
Model and supplier risk outside enterprise risk management
Weak records of why AI decisions were approved
Boards receiving innovation updates rather than assurance
Controls on paper that have never been tested
Meanwhile, regulatory obligations change faster than most governance processes.
The underlying issue
The problem is not AI adoption. It is AI adoption without clear accountability, evidence and assurance.
Adding more policies without knowing which AI systems exist, who owns them and how risk is assessed does not create governance.
What the engagement involves
Build the governance, evidence and assurance your AI environment requires
01
ISO 42001 Readiness
Prepare the governance, management-system controls and evidence required for an AI Management System.
02
ISO 42001 Gap Analysis
Compare the current AI governance position against ISO/IEC 42001 expectations and identify control, evidence and ownership gaps.
03
EU AI Act Readiness
Identify relevant AI roles, classifications, obligations and evidence requirements and convert them into a practical readiness plan.
04
AI Governance Framework Consultancy
Define AI roles, decision rights, policies, approvals, controls, escalation routes and assurance checkpoints.
05
Responsible AI Consultancy
Translate responsible-AI principles into operational governance, decision criteria, controls and evidence.
06
AI Risk Management Consultancy
Identify, assess, treat and monitor AI risks through structured risk registers, controls, escalation and senior reporting.
07
AI Impact Assessment Consultancy
Assess how AI may affect individuals, rights, safety, decisions, operations and accountability before material risk escalates.
08
AI Governance Officer as a Service
Access retained senior AI-governance leadership, oversight and reporting without creating a full-time internal role.
AI governance is the system of accountability, decision-making, controls and oversight through which an organisation directs the development, procurement and use of artificial intelligence. It defines who owns AI risk, how use cases are assessed and approved, what evidence is required and how performance, impacts and residual risks are monitored.
Definition
What is AI assurance?
AI assurance uses evidence, assessment, testing, review and independent challenge to determine whether AI systems and their governing controls are operating as intended and whether claims about safety, fairness, security, transparency, compliance or other relevant characteristics are sufficiently supported.
Governance, risk management and assurance overlap. Each depends on the others:
AI Governance
ownership
policies
decision rights
risk appetite
approvals
oversight
AI Risk Management
identification
assessment
treatment
monitoring
escalation
AI Assurance
evidence
review
testing
challenge
reporting
residual-risk visibility
AI Governance Control Loop
Govern AI across its lifecycle
AI governance should apply before procurement or deployment, not begin after a system is already in use.
Cross-cutting controls
Ownership & Accountability
Risk Management
Privacy & Data Protection
Security & Technical Controls
Human Oversight
Evidence & Documentation
Assurance & Reporting
01Identify
02Classify
03Assess
04Approve
05Deploy
06Monitor
07Change / Retire
Change / Retire feeds back into Identify — a continuous control loop.
IG-Smart’s practical governance model — not a sequence prescribed by any single regulation or framework.
Operating model
Who owns AI governance?
No single model suits every organisation. The right structure depends on whether the organisation builds, buys or deploys AI, its sector, regulatory exposure, scale, risk profile and use cases, and the privacy, security, risk and procurement functions already in place.
The objective is not another committee. It is clear decision rights and accountable ownership.
Example only — adapted to each organisation
Board / Executive Oversight
AI Governance Committee / Executive AI Forum
Specialist input:
Risk
Legal
Privacy
Cyber
Procurement
Technology
Clinical / Operational SMEs
AI System / Use-Case Owners
Developers · Suppliers · Operational Teams
AI inventory & classification
You cannot govern AI you cannot see
A practical governance baseline, adapted to scope, typically records enough to decide how each system or use case should be governed.
An AI inventory should support decisions — not become another static register.
Typical inventory fields
Use case and owner
Business purpose
Supplier / provider
Affected individuals
Data involved
Automation and human oversight
Show all typical fields (10)Hide detail
Decisions influenced
Regulatory classification and risk rating
Approval and monitoring status
Evidence location
AI risk
AI risk is multidimensional
Assessment should be proportionate to the use case, affected people and potential consequences. Not every category applies to every system.
Legal & accountability
Legal & Regulatory
Transparency & Explainability
Human Oversight
Data & security
Privacy & Data
Cybersecurity
Supplier / Model Dependency
People & outcomes
Bias & Fairness
Safety
Accuracy & Reliability
Organisational
Operational Resilience
Reputational
Financial / Commercial
Board-level AI assurance
What should the Board be able to see?
AI inventory
What AI is being developed, bought or used?
Accountability
Who owns each material use case and its risks?
Risk classification
Which AI uses present greater legal, operational or human impact?
Controls
What safeguards and approval requirements apply?
Evidence
What supports claims about how the AI operates and how risk is controlled?
Monitoring
What has changed since approval and what issues have emerged?
Residual risk
What remains unresolved and who has accepted it?
Board assurance should show the position, not simply count AI projects or policies.
Regulatory and standards context
How the EU AI Act, ISO/IEC 42001 and UK guidance fit together
EU AI Act readiness
Applicability depends on the organisation's role, the AI system, the use case and territorial scope. Not all AI is high risk. Current position:
AI literacy provisions have applied since February 2025.
Governance and general-purpose AI model obligations began applying in August 2025.
Article 50 transparency obligations have applied from 2 August 2026.
From 2 August 2026, the AI Office and national competent authorities became responsible for implementing, supervising and enforcing the Act within their respective competences.
Most high-risk AI system obligations apply later: from 2 December 2027 for relevant Annex III use cases and from 2 August 2028 for AI embedded in regulated products.
ISO/IEC 42001:2023 specifies requirements for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System. It is an organisational management-system standard, not a technical model-performance standard.
IG-Smart provides readiness, gap analysis and implementation support. Certification is carried out by an independent certification body.
The UK does not have a single horizontal AI Act. Its environment combines existing cross-cutting law, sector-specific regulation, regulator-led AI governance, government risk-management guidance and emerging assurance practice, including the Trusted Third-Party AI Assurance Roadmap.
Organisations may need to govern the same AI use case against several overlapping obligations rather than a single AI-specific law.
In September 2026, the UK Department for Science, Innovation and Technology published an AI Risk Management Toolkit to support teams designing, operating, procuring or delivering AI products. IG-Smart can use relevant current guidance as one input into an organisation-specific approach; it is not in itself a mandatory compliance framework.
International reference
NIST AI Risk Management Framework
A voluntary framework for managing AI risk across design, development, deployment and use. NIST AI RMF 1.0 remains available; NIST has stated that it is being revised. IG-Smart treats it as a version-controlled reference, not a dependency.
Responsible AI should become operational governance
Responsible AI principles only become meaningful when translated into:
Owners
Decision criteria
Controls
Evidence
Monitoring
Escalation
AI impact assessment
Assess impact before approval
An assessment may need to consider:
Affected individuals
Purpose and decision significance
Rights and privacy
Bias and fairness
Safety and security
Explainability and oversight
Foreseeable misuse
Residual risk
It should be proportionate to the use case and connect directly to approval, mitigation and monitoring decisions.
Procurement & third-party AI
Buying AI does not outsource accountability
Third-party AI may require governance around:
Purpose and permitted use
Supplier role and dependencies
Training or input data
Security and data protection
Performance limitations
Transparency and human oversight
Contractual and change commitments
Monitoring and exit
Supplier assurance should feed the organisation's own AI risk position rather than end with a completed questionnaire. See also Cyber Governance & Assurance.
How we deliver
How IG-Smart approaches an AI governance and assurance engagement
01
Assess
Establish the AI inventory, use cases, stakeholders, applicable obligations, risk profile, existing controls and material governance gaps.
Where formal legal advice or legal opinion is required, it should be obtained from appropriately qualified legal counsel. IG-Smart can work alongside the client's legal advisers so that legal interpretation, governance design and assurance remain appropriately connected.
Technical AI Testing
Model evaluation, red teaming, bias testing, security testing or specialist validation may require separate technical expertise depending on scope.
ISO Certification
IG-Smart supports ISO/IEC 42001 readiness and implementation. Accredited certification is carried out by an independent certification body.
Common engagement models
Assessment, build or managed governance?
AI governance assessment
A defined-scope review of AI use, inventory, risk controls and evidence against relevant frameworks.
Suits
Organisations that need to understand their AI governance position before scaling or procurement.
AI governance build programme
Phased design of roles, policies, risk processes, inventory and assurance arrangements.
Suits
Organisations establishing AI governance or preparing for ISO/IEC 42001 readiness.
Managed AI governance
Ongoing senior oversight of the AI inventory, new use cases, risk reviews and board reporting.
Suits
Organisations with a growing portfolio of AI use cases that need continuing independent oversight.
Typical investment
Indicative investment
AI Governance assessment / assurance
Starting investment: £12,500 + VAT
Typical investment: £12,500–£15,000 + VAT
Model: Defined-scope engagement
AI governance build / programme
Starting investment: £25,000 + VAT
Larger programmes individually scoped
Model: Phased programme
Managed AI Governance
Starting investment: £5,000 + VAT per month
Subject to service scope
Model: Managed & retained service
Scope, deliverables, assumptions and fees are agreed in writing before work begins. What changes the fee is set out on the investment page; the exact fee is confirmed after scoping.
AI governance is the system of accountability, decision-making, controls and oversight through which an organisation directs the development, procurement and use of AI — including who owns AI risk, how use cases are approved and what evidence is required.
AI assurance uses evidence, assessment, testing, review and independent challenge to determine whether AI systems and their governing controls operate as intended, and whether claims made about them are sufficiently supported.
Typically: defined roles and decision rights, an AI inventory, risk and impact-assessment criteria, approval routes, policies and controls, escalation thresholds, monitoring, evidence requirements and board reporting — proportionate to the organisation's AI use.
It may. Applicability depends on the organisation's role (for example provider or deployer), the AI system, the use case and territorial scope — such as placing systems on the EU market or using AI outputs in the EU. There is no universal yes or no; it needs assessing case by case.
ISO/IEC 42001:2023 specifies requirements for establishing, implementing, maintaining and continually improving an AI Management System. It is an organisational management-system standard, not a technical model-performance standard.
Governance sets ownership, decision rights, risk appetite and oversight. Risk management identifies, assesses, treats and monitors specific AI risks within that structure. Each depends on the other.
In practice, yes. Without knowing which AI systems and use cases exist, who owns them and how they are used, an organisation cannot apply proportionate governance, assess obligations or report credibly to its board.
A structured assessment of how an AI use case may affect individuals, groups, rights, safety, decisions and operations, carried out before approval and connected directly to mitigation and monitoring decisions.
Yes. IG-Smart can help assess third-party AI through procurement governance, supplier evidence, contractual considerations and ongoing monitoring, so supplier assurance feeds the organisation's own AI risk position.
Yes. IG-Smart connects those functions into one governance model. Formal legal opinion and specialist technical AI testing remain distinct and may require separate expertise depending on scope.
Not necessarily. What matters is clear, accountable ownership. Some organisations assign it to an existing role; others use retained senior support, such as AI Governance Officer as a Service.
Yes. Where it is part of the agreed scope, outputs can include structured evidence prepared for customer due diligence, procurement questionnaires, tenders, audit or regulatory scrutiny.
Regulatory and standards references reviewed September 2026. This page is reviewed every 3 months.
Need a clearer, more defensible view of your AI position?
Whether you need to establish governance, assess risk, prepare for ISO/IEC 42001, understand EU AI Act obligations or build ongoing assurance, start with the position you need to understand or demonstrate.