Skip to main content

AI Governance & Assurance

Managed AI Governance & Assurance

Ongoing senior governance for organisations that need to know where AI is used, who owns each use case, which risks have been accepted and whether the evidence supports continued use.
Managed AI governance cycle
  1. Discover
  2. Classify
  3. Assess
  4. Decide
  5. Govern
  6. Monitor
  7. Report
  8. Improve

A managed operating capability for accountable AI adoption — not an unlimited pool of legal, engineering or technical testing services.

For regulated and complex organisations with a growing portfolio of AI use cases, supplier AI or Board-level assurance requirements.

From AI principles to an operating governance rhythm

Managed AI Governance establishes the decisions, evidence and oversight needed to govern AI continuously. It joins the inventory, intake, risk assessment, approval, monitoring and reporting process rather than treating each use case as a standalone compliance exercise.

Management retains ownership of each use case, deployment decision and accepted risk. IG-Smart provides the governance structure, independent challenge and continuing assurance needed to make those decisions defensible.

The operating method

From AI use case to monitored decision

Each stage creates an accountable decision and an evidence trail that can be revisited when the use case, supplier or regulatory position changes.

Discover

What happens
AI use cases, owners, purpose, suppliers, affected people, data and evidence locations are identified.
What IG-Smart does
Establishes the governed inventory and intake process.
What the organisation owns
Declaring AI use and nominating accountable owners.
Typical output
AI use-case inventory and intake record.

Classify

What happens
Each use case is classified by impact, risk and relevant regulatory role.
What IG-Smart does
Applies agreed criteria and identifies specialist input required.
What the organisation owns
Confirming intended purpose and organisational risk appetite.
Typical output
Risk and regulatory classification record.

Assess

What happens
Material impacts, controls, human oversight, privacy, security and supplier dependencies are examined.
What IG-Smart does
Coordinates proportionate impact and control assessment.
What the organisation owns
Providing evidence and implementing controls.
Typical output
AI impact assessment and action plan.

Decide

What happens
Approval, conditions, remediation, rejection or escalation are recorded.
What IG-Smart does
Frames the evidence, residual risk and decision required.
What the organisation owns
Approving use, conditions and residual risk.
Typical output
Decision and risk-acceptance record.

Govern

What happens
Policy, forums, actions, exceptions and evidence requirements operate as a managed rhythm.
What IG-Smart does
Runs the agreed governance process and tracks actions.
What the organisation owns
Operational use and delivery of agreed actions.
Typical output
Governance pack, action and exception registers.

Monitor

What happens
Material changes, incidents, supplier changes and performance concerns trigger reassessment.
What IG-Smart does
Maintains review triggers and challenges changes to the assurance position.
What the organisation owns
Escalating change and operational concerns.
Typical output
Monitoring and review schedule.

Report

What happens
Management and the Board see adoption, exposure, open actions and accepted risk.
What IG-Smart does
Produces decision-ready reporting with evidence reliability made clear.
What the organisation owns
Acting on reported exposure and decisions.
Typical output
Management and Board AI assurance summary.

Improve

What happens
Findings are closed and the operating model adapts as AI and regulation change.
What IG-Smart does
Tracks improvement and recommends proportionate changes.
What the organisation owns
Funding and implementing agreed improvements.
Typical output
Prioritised improvement plan.

IG-Smart governs and assures the process. The organisation remains accountable for AI use, deployment, controls, decisions and accepted risk.

When organisations engage us

Signals that it is time to act

  1. AI tools are in use but no complete inventory exists
  2. Use-case approvals vary between teams
  3. The Board cannot see material AI exposure or accepted risk
  4. Supplier AI is entering the organisation without proportionate assurance
  5. Privacy, cyber, legal and technology reviews are disconnected
  6. Regulatory-readiness evidence must be maintained, not assembled once

What the service covers

Outcomes the service is built to deliver

Governance operating model
Roles, decision rights, policy, governance forums, escalation and evidence requirements.
AI inventory and use-case governance
A governed record of AI purpose, owner, supplier, affected people, data, decisions and status.
Risk and impact governance
Proportionate classification and assessment of legal, privacy, cyber, human, operational and supplier risks.
Decisions and oversight
Approval conditions, remediation, exceptions, accepted risk and monitoring triggers recorded for accountability.
Supplier and third-party AI
Governance and assurance of material supplier claims, dependencies, change commitments and evidence.
Executive reporting and improvement
Decision-ready visibility of adoption, evidence, material exposure, open actions and changes.

How we deliver

Assess → Build → Manage → Assure → Improve

  1. Assess

    Establish use cases, ownership, obligations, evidence and material gaps.

  2. Build

    Define the inventory, decision rights, controls, assessments and reporting.

  3. Manage

    Operate intake, forums, reviews, decisions, actions and exceptions.

  4. Assure

    Challenge whether evidence supports the reported position and accepted risk.

  5. Improve

    Close findings and adapt governance as use, suppliers and requirements change.

Scope boundaries

Included, and separately scoped where required

Included in the core service

  • AI inventory and intake governance
  • Risk classification and impact-assessment governance
  • Policy, roles and decision records
  • Governance forums, actions and exceptions
  • Supplier AI governance where relevant
  • Monitoring, executive reporting and improvement

Separately scoped where required

  • Formal external legal opinions
  • Model penetration testing or red teaming
  • Deep technical model or algorithmic evaluation
  • Large-scale implementation or remediation
  • Specialist bias, safety or performance testing outside agreed capability

Sample outputs

Example outputs you may receive

Representative reports, registers and records, so you can picture the output before you engage.

Illustrative structure — not a client document. Examples show the type, format and level of detail clients may receive. Exact outputs depend on the agreed scope.

Illustrative output

AI Use-Case / Inventory Register

A decision-led inventory of AI use, not a list of tools.

  • Use case
  • Owner
  • Purpose
  • Risk class

Likely format

  • IG-Smart branded spreadsheet / register
  • IG-Smart branded PDF

The structure, format and level of detail depend on the agreed scope. This is not a client document.

Illustrative output

AI Risk / Impact Governance Record

How each material use case was assessed, the controls relied on and the residual risk.

  • Impact
  • Evidence
  • Control
  • Residual risk

Likely format

  • IG-Smart branded spreadsheet / register
  • IG-Smart branded PDF

The structure, format and level of detail depend on the agreed scope. This is not a client document.

Illustrative output

AI Governance Decision Register

Approvals, conditions and declines, with the rationale and owner behind each.

  • Decision
  • Conditions
  • Owner
  • Review trigger

Likely format

  • IG-Smart branded spreadsheet / register
  • IG-Smart branded PDF

The structure, format and level of detail depend on the agreed scope. This is not a client document.

Illustrative output

AI Supplier / Third-Party Review Record

Evidence requested from AI suppliers, what was shown and what was challenged.

  • Supplier
  • Evidence requested
  • Evidence shown
  • Challenge

Likely format

  • IG-Smart branded spreadsheet / register
  • Evidence pack / supporting records

The structure, format and level of detail depend on the agreed scope. This is not a client document.

Illustrative output

Board / Executive AI Governance Summary

What is in use, what is exposed and what leadership must decide.

  • Measure
  • Position
  • Evidence
  • Action

Likely format

  • IG-Smart branded PDF
  • Evidence pack / supporting records

The structure, format and level of detail depend on the agreed scope. This is not a client document.

Illustrative output

Improvement / Remediation Plan

Findings and conditions sequenced to closure, with owners and evidence of completion.

  • Action
  • Owner
  • Due
  • Closure evidence

Likely format

  • IG-Smart branded spreadsheet / register
  • IG-Smart branded PDF

The structure, format and level of detail depend on the agreed scope. This is not a client document.

Relevant evidence

Relevant governance & assurance capability

IG-Smart's Managed AI Governance & Assurance service draws on established capability in governance, privacy, data, cybersecurity, risk and independent assurance across regulated and complex organisations. This evidence demonstrates transferable capability; it is not presented as completed client AI-governance work unless the underlying case expressly says so.

  • Anonymised engagement

    A FTSE 100 organisation

    Three-stage governance and audit-readiness plan

    Audit-ready UK policies ahead of a third-party maturity assessment

    View the evidence: A FTSE 100 organisation
  • Named client · Financial Services

    AIG

    Supplier data-governance audit

    Nationwide supplier audit

    View the evidence: AIG
  • Named client · Healthcare / NHS

    NHS England

    Strategic data-privacy and data-sharing advisory

    National privacy-by-design framework · multiple national workstreams

    View the evidence: NHS England

Explore all case studies →Request Relevant Evidence →

Evidence relevance

Your IG-Smart team

Specialist expertise, coordinated around your requirement

Subject-matter expertise is paired with a clear client and programme contact from initial scoping through delivery.

Subject-matter expert

Michael Abtar

CEO and Founder

Governance, risk and assurance specialist with more than 18 years' experience spanning privacy, cyber resilience, AI governance, digital transformation, healthcare and complex regulated organisations.

View profile

Client & programme contact

Julia Andrade

Head of Client & Programme Success

A key point of contact from prospective-client scoping through programme and project delivery, coordinating practitioners, workstreams and client stakeholders.

View profile

Related needs

Where this naturally leads

Investment

Starting investment: £5,000 + VAT per month

Scope, deliverables, assumptions and fees are agreed in writing before work begins.

Talk to a Senior Practitioner How engagements & investment work

The fee depends on

  • Number and risk of AI use cases
  • Entities and jurisdictions
  • Supplier-AI volume and dependencies
  • Governance and reporting cadence
  • Evidence maturity and remediation load
  • Specialist input required

Questions

Frequently asked questions

Is this a technical AI testing service?

No. It is a managed governance and assurance capability. Deep technical evaluation, red teaming, penetration testing and specialist algorithmic testing are separately scoped where required.

Who approves an AI use case?

The organisation does. IG-Smart structures and challenges the evidence, risk and decision; management retains accountability for approval, deployment and accepted risk.

Does every AI use case need the same assessment?

No. Assessment depth is proportionate to purpose, impact, affected people, data, supplier dependency and regulatory exposure.

Can this support ISO/IEC 42001 or EU AI Act readiness?

Yes, where relevant to the agreed scope. Readiness support does not constitute certification or formal legal opinion.

Next step

Need AI governance that stays current as adoption grows?

Not sure what applies?Find the Right Service