Responsible AI · The Trust stage
Governance that speeds you up, not a gate at the end.
Most AI programs treat governance as the thing that happens the week before launch. That's why they stall there. I design guardrails in from the start, so your teams can move quickly and you can answer for what they ship.
The questions you'll be asked
Four questions, and the answer can't be “we're looking into it”.
Boards, regulators, auditors and your own customers ask the same four things. A governance program is just the ability to answer them on the day they're asked.
Who owns this?
One named executive accountable for AI outcomes and AI risk, not a committee. Ownership without a name is how initiatives stall between departments and how incidents go unanswered.
What data goes in?
A plain-language line between what may be used, what is restricted and what is prohibited, mapped to how your data is actually classified, and enforced in the tools people already have.
What happens when it's wrong?
Where a human reviews before output reaches a customer or a contract, who is called when something goes wrong, and how you pause a system without stopping the business.
How do we know it's still working?
What gets monitored after launch, how often, and what triggers a review. Models, vendors and the data underneath them all change after you sign.
Four minutes
Score your guardrails, and see which one to fix first.
Twelve questions across the six areas below. Nothing is sent anywhere, and you get the move I would make this week.
Where it actually breaks
Governance rarely fails on principle. It fails on timing.
Week 12
Legal sees it last
What should have been a design constraint in week one becomes a blocker the week before launch, and the pilot quietly dies in review.
Everywhere
Shadow AI
People already use AI on company work through personal accounts. You cannot govern what nobody has inventoried, and a ban moves it further out of sight.
At signature
Vendor terms nobody read
Training on your data, subprocessors you never approved, and model changes with no notice. Criteria agreed before the sales call cost nothing; afterwards they cost the contract.
Day one of an incident
No off switch
A system in production with no owner, no logs and no agreed way to pause it turns a small error into an executive escalation.
The operating model
Eight controls that fit on a page each.
This is what I install with clients. Every item is something a mid-market organization can actually run, with a named owner and a review date, not a policy nobody opens.
Acceptable use
One page on allowed, restricted and prohibited data and uses, in language your people will follow.
You end up withA policy staff have acknowledged
A named risk owner
One accountable executive for AI risk, privacy and compliance, with an escalation path behind them.
You end up withA name against every system
Data boundaries and security
Where company data may go, how access is controlled, what is logged, and what never leaves your tenancy.
You end up withBoundaries written into the build
Vendor criteria
What you require on security, data handling, training use, subprocessors and model change notice, decided before the sales call.
You end up withA due-diligence checklist
Human review where it matters
Review tiered by consequence: spot checks internally, mandatory sign-off before anything customer-facing, contractual or regulated.
You end up withA human-review matrix
Shadow-AI inventory
An honest picture of what is already running, gathered without a witch hunt, then brought inside the guardrails.
You end up withAn AI system register
Monitoring after launch
What gets checked, how often, who reviews it, and what triggers a pause. Drift and errors do not announce themselves.
You end up withA monitoring plan and risk register
Incident response
How a system is paused, who is told, what gets recorded, and how you decide whether to resume.
You end up withA tested pause-and-notify path
Standards, translated
What the frameworks ask for, in language your team can act on.
I work to these frameworks and translate them into the controls above. I am not an auditor or a certification body, and none of this is legal advice; where you need a legal opinion, I work alongside your counsel.
| Framework | What it is | What it asks of you |
|---|---|---|
| NIST AI RMF | A voluntary US risk framework built on four functions: govern, map, measure and manage. | Know your systems and their context, measure the risks that matter, and manage them on a cycle rather than once. |
| ISO/IEC 42001 | A certifiable management system standard for AI, in the same family as ISO 27001. | Policy, roles, objectives, documented controls and internal audit: governance you can evidence, not just describe. |
| EU AI Act | Risk-tiered regulation with obligations that differ by role and by how the system is used. | Classify each system, know whether you are a provider or a deployer, and hold transparency, oversight and record-keeping to the tier it sits in. |
How I work
Responsible AI is a leadership discipline.
The guardrails are the easy part. These are the positions underneath them.
A person stays accountable
AI assists decisions; it doesn't own them. Every system has a human who answers for its output, by name.
Say when it's AI
Customers and staff are told when they are reading or being assessed by AI output. Disclosure is cheaper than discovery.
Data dignity
Someone's data is used for what they'd expect it to be used for. If explaining the use would embarrass you, that is the answer.
Look for harm before launch
Ask who this could be wrong about, and what it costs them, while the design can still change.
What you end up holding
Governance you can hand to an auditor, a board or a new hire.
- A one-page acceptable-use policy, acknowledged by staff
- An AI system register, including what was already running
- A vendor due-diligence checklist used before contracts are signed
- A human-review matrix by output type and consequence
- An AI risk register with owners and review dates
- A monitoring plan and an incident pause-and-notify path
- An AI council charter, where the council advises and one owner decides
- A board-ready summary of where you stand and what changes next
Working together
Three ways in, depending on where you are.
Find out where you stand
The readiness assessment scores governance alongside five other dimensions, and names the one to fix first. Free, about seven minutes.
Take the assessmentRead what I'm seeing
Guardrails is my newsletter on AI strategy, governance and transformation, written for the people accountable for getting it right.
Subscribe to GuardrailsBring me in
I work with leadership teams to install the controls above, with your counsel and security team in the room. It starts with a conversation.
Book a conversationBefore you ask
Questions worth answering.
Do you certify or audit us?
No. I design and install governance, and prepare you for an audit or certification if you want one. The certificate comes from an accredited body, not from me.
Is this legal advice?
No. I work alongside your counsel, and I write controls your lawyers can review. Where a legal opinion is needed, you need a lawyer.
Won't governance slow my teams down?
Done late, it stops them entirely. Done early, it removes the question that blocks launch, because the answer is already written down and owned.
We've already got AI running with no guardrails. Too late?
No, and that's the common case. We start with an honest inventory of what's live, put the highest-consequence uses behind review first, and work outwards from there.
You can't govern what nobody owns. Start by naming it.
Score where your governance actually stands, then decide what to fix first.