Starter Services · AI Governance Quickstart
Get the next AI decision through governance. Then keep the path.
In two to four weeks we build the review path, decision record and policy needed to process one real AI use case — then run it through with your legal, risk and security owners. Fixed scope, fixed fee, and the path is yours to keep.
Find your starting pointRecognized structure, your own policies as the starting point, and the requirements that actually apply to you. Sized for your organization, not lifted from a standard.
Where you are starting from
Four places organizations arrive from. One path out of each.
If an AI initiative is waiting because nobody can define the path to approval, start there. The engagement is the same shape wherever you begin; what changes is how much we map, how much we design and how much we only sharpen.
Nothing in place yet
AI is already in use. The review process for it does not exist yet.
Teams have adopted tools, a pilot or two is in flight, and the first time anyone asked "who approved this?" the answer was silence. The next one is waiting until there is something to approve against.
A policy nobody can apply
There is an AI policy. It says "responsible" and "appropriate" and nobody can tell you whether a use case passes.
Written early, often from a template, it reads well and decides nothing. Every request becomes a judgment call by whoever is in the room, so teams either route around it or wait indefinitely.
A review that takes months
The review exists. It takes a quarter, every request goes through the same gate, and nobody can say what it is checking.
A single heavy review for everything means a low-risk internal assistant waits behind a customer-facing agent. The backlog is the governance problem now.
A decision coming that nobody owns
Nothing is stuck yet. Something is about to need a defensible answer.
Your first customer-facing agent is going live. Procurement wants an answer on a copilot licence. A business unit wants to put sensitive data through a model. The board has asked who approves AI use. Nobody has said no — but somebody needs to be able to say yes, on the record, before it moves.
None of these quite fit? Describe the use case and who owns the decision. We will describe the path back to you before you commit to anything.
What the path has to answer
Four questions. If the path answers them, a decision can be made on the record.
A policy is only as useful as the decisions it lets people make. Every review path we build is designed so that, for any AI use case, these four have an answer somebody will put their name to.
Who reviews it?
Named roles, not "the committee". Risk, legal, security and the business owner, with a tier that says which of them a given use case actually needs.
Against what?
Criteria that decide — data sensitivity, who is affected, what the system can do on its own — mapped to the framework and to your obligations.
What gets recorded?
The decision, the evidence it rested on, the conditions attached, who made it — and what would make it need revisiting. Kept where an auditor, a regulator or next year's team can find it.
Who decides?
The named role that owns the outcome at each tier, and the policy — written with your legal, risk and security owners, in your voice — that makes their decision defensible.
A use case has been taken through the path, the decision and its conditions are in the log, and the policy the decision rests on is in front of its owners for approval. Not a slide that says governance exists — a record that shows the mechanism worked once, so it can work again without us.
You leave with
The path, the record, the policy — and proof the mechanism works.
Everything is handed over in source and is yours to run. The point is that the second use case goes through without us.
A named review path
Intake, risk tier, required reviewers, decision criteria and named decision roles. Written down, owned, and ready to run for the next use case.
A decision log
The record that shows each decision was made on evidence — decision, conditions, owner, date, and what would trigger a re-review — kept where an auditor can find it.
A policy drafted for sign-off
In your organization's voice, built with the legal, risk and security owners who have to approve it, so approval is the next step rather than another review.
One real use case through it
One live initiative taken through the path end to end, decision recorded, conditions documented — so the mechanism is proven on something real and your team has done it once.
How it runs
Four stages inside one fixed window.
Two to four weeks, set in scoping from how many systems, how many review functions and how much existing policy there is. The clock starts at kickoff, once the people and documents in the proposal are available.
Map
The agreed scope: the AI in it, the people who currently say yes or no, the policies you have, and the obligations you are held to. Enough to route the first use case correctly, not an enterprise inventory.
Design
The review path and the record — tiers, criteria, owners, timings — sized for your organization rather than lifted from a standard.
Draft and clear
The policy, worked through with legal, risk and security until each owner is ready to approve it. Short, specific, in your voice.
Prove it
One live use case goes through the path end to end. Decision recorded, conditions documented, and the policy left ready for approval. Presented live to the people who own the next one.
Evidence
Governance that holds on every answer, not just on paper.
The hardest version of this problem is an AI system that talks to regulated audiences. This is what controls look like when they are built into the system rather than written beside it.
Life sciences · Regulated communications
A life-sciences data and communications provider
Teams answering pharmacists, providers, hospitals and patients had to stitch together CRM records, approved product labels and market data on the fly — and any mismatch with the label was a compliance exposure. We built an assistant that answers only from the approved source, tied to the right account, with the rules enforced on every response:
Scattered, compliance-sensitive information became an on-demand assistant that was faster to use and easier to audit — because the governance was in the system, not in a binder next to it.
Read the story →The same principle runs through every Quickstart: a review path only works if its decisions can be applied where the AI actually operates. We design the path so the controls it specifies are the kind a system can enforce and a log can show — which is what makes it clearable.
Fit
Right-sized when one decision is waiting and someone specific can make it.
Two short lists. If you recognise yourself in the first, the Quickstart is the right size. If the second reads truer, we will point you at the engagement that answers your actual next question.
This is a good fit when
- An AI use case is waiting for a decision and nobody can say what would clear it — or one is coming that needs a defensible answer.
- Legal, risk or security owners exist and can be in the room.
- You can list the AI in use and in flight, even roughly.
- You want the path to work for the next use case without us.
- An auditor, regulator or board is going to ask how decisions were made.
Start somewhere else when
- You are still deciding whether to use AI at all — that is the Assessment Sprint.
- No one owns risk, legal or security decisions yet, so there is nobody to sign.
- The real exposure is security posture rather than review process — that is the Cyber Risk Sprint.
- You need governance operated continuously, with tooling — that is the Strategy & Governance practice.
Where it sits
Find it, prove it, run it. Use the smallest engagement that answers the next question.
The Assessment Sprint scores governance as one of six dimensions. A weak score is the usual reason to come here. Governance as an operating function lives in the practice.
AI & Data Assessment Sprint
Two weeks that score six readiness dimensions — governance and review path among them — against your own systems.
See the Assessment SprintAI Governance Quickstart
The path, the record and the policy, proven on one real use case, and left with you to run.
Tell us what is waiting for a decisionStrategy & Governance practice
Operating models, responsible-AI programs and the tooling that keeps the review path running at scale.
See the practiceBefore you ask
The buying questions that matter.
The six things the sponsor, counsel and the risk owner ask before a governance engagement is approved, answered the way we answer them in the proposal.
Will this slow AI work down?
It replaces an undefined review with a defined one. Work that is currently waiting for an answer nobody can give gets an answer with a date on it — and a fast lane for the low-risk majority, so the heavy review is spent where it is warranted.
Does this cover the AI we already have running?
Within the agreed scope, yes. Mapping what is in use there is the first stage, and existing systems are brought under the same path rather than grandfathered around it. An enterprise-wide inventory is a practice engagement, not this one.
Which frameworks do you build on?
The NIST AI Risk Management Framework and ISO/IEC 42001 as the structure, your existing policies as the starting point, and the federal and state requirements that apply to you as the constraint. The path is sized for your organization, not lifted from a standard.
Who writes the policy, you or us?
We draft it, in your organization's voice, from the review path we design together. Your legal, risk and security owners work through it with us until it is ready for their approval. Your counsel reviews it; this is not legal advice and we do not replace them.
What does it cost?
The fee is fixed in writing before work starts and depends on how many AI systems are in scope, how many review functions are involved and how much existing policy there is to build on. Work inside that boundary is not billed hourly.
What do you need from us before kickoff?
Access to the people who currently say yes or no, your existing policies, and a rough list of the AI in the agreed scope. The specifics are written into the proposal before you commit.
Start from the decision
Tell us what is waiting for a governance decision.
Not a framework name. Give us the use case, who owns the decision, what is unresolved, and what already exists. We will describe the review path back — tiers, owners, window and fixed fee — before you commit to anything.
Not sure governance is the weak dimension? Score all six free in seven minutes and bring us the result.
A decision waiting? Tell us the use case and who owns the call.