01
The inventory.
You cannot govern what you have not listed. Every engagement starts with the AI inventory: the systems you bought, the systems you built, and the AI embedded in standard software you may not think of as AI. Most organisations are surprised by their own list.
02
The classification.
Which risk category each system actually sits in. For most organisations, most systems land in the lighter categories, and knowing that is the point: it tells you where the real duties are, and frees you from worrying about the wrong things.
03
The policy people actually follow.
A good AI policy is not a ban. It tells your people what they can do, with which data, in which tools, and who to ask when the answer is unclear. The alternative to a workable policy is not compliance. It is quiet, ungoverned use that nobody sees until it becomes a problem.
04
Processes with owners.
Risk management, incident handling, documentation, and where the law requires it, a fundamental rights impact assessment built as a working process. Every process gets a named owner, because a process without one is a document.
05
Competence, the whole ladder.
The Article 4 duty to take measures supporting AI literacy starts where accountability sits. We deliver leadership sessions in the management team, and role-specific programmes for the wider organisation through AIUC, our education arm.