Skip to main content
Data Products logo

Starter Services · AI Governance Quickstart

Get the next AI decision through governance. Then keep the path.

In two to four weeks we build the review path, decision record and policy needed to process one real AI use case — then run it through with your legal, risk and security owners. Fixed scope, fixed fee, and the path is yours to keep.

Find your starting point
The review path, end to end A flow from an AI use case through intake, a named review against a standard, a decision log and a policy ready for approval, to a documented decision with a date. An orange marker travels the path on a loop. THE REVIEW PATH, END TO END START HEREAn AI use case INTAKEOne form, one owner REVIEWRisk, legal and security, against a named standard RECORDDecision log DECIDEPolicy, ready to approve Approved · with conditions · declined — on evidence, dated
Window2 to 4 weeks, scoped with you
FeeFixed fee, set in the proposal
ScopeOne organizational scope · one review path · one policy · one real use case through it
DecisionYour first use case gets a documented decision — or a precise list of what it still needs
Built on

Recognized structure, your own policies as the starting point, and the requirements that actually apply to you. Sized for your organization, not lifted from a standard.

NIST AI RMFThe structure: govern, map, measure, manage
ISO/IEC 42001The management-system shape auditors recognize
Your obligationsFederal and state requirements, sector rules, your contracts

Where you are starting from

Four places organizations arrive from. One path out of each.

If an AI initiative is waiting because nobody can define the path to approval, start there. The engagement is the same shape wherever you begin; what changes is how much we map, how much we design and how much we only sharpen.

Nothing in place yet

AI is already in use. The review process for it does not exist yet.

Teams have adopted tools, a pilot or two is in flight, and the first time anyone asked "who approved this?" the answer was silence. The next one is waiting until there is something to approve against.

What we mapEnough of the AI in scope to route the first use case correctly, who owns it, and who currently says yes or no
What we designThe whole path: intake, review tiers by risk, the record, the sign-off
What we draftA first policy in your voice, scoped to what you actually run
What gets provenThe waiting initiative, taken through the new path end to end — usually the one that prompted the call

None of these quite fit? Describe the use case and who owns the decision. We will describe the path back to you before you commit to anything.

What the path has to answer

Four questions. If the path answers them, a decision can be made on the record.

A policy is only as useful as the decisions it lets people make. Every review path we build is designed so that, for any AI use case, these four have an answer somebody will put their name to.

01

Who reviews it?

Named roles, not "the committee". Risk, legal, security and the business owner, with a tier that says which of them a given use case actually needs.

Delivered asThe review path, with owners
02

Against what?

Criteria that decide — data sensitivity, who is affected, what the system can do on its own — mapped to the framework and to your obligations.

Delivered asReview criteria and risk tiers
03

What gets recorded?

The decision, the evidence it rested on, the conditions attached, who made it — and what would make it need revisiting. Kept where an auditor, a regulator or next year's team can find it.

Delivered asThe decision log
04

Who decides?

The named role that owns the outcome at each tier, and the policy — written with your legal, risk and security owners, in your voice — that makes their decision defensible.

Delivered asDecision roles, and the policy ready for approval
What "proven" means here

A use case has been taken through the path, the decision and its conditions are in the log, and the policy the decision rests on is in front of its owners for approval. Not a slide that says governance exists — a record that shows the mechanism worked once, so it can work again without us.

You leave with

The path, the record, the policy — and proof the mechanism works.

Everything is handed over in source and is yours to run. The point is that the second use case goes through without us.

01

A named review path

Intake, risk tier, required reviewers, decision criteria and named decision roles. Written down, owned, and ready to run for the next use case.

02

A decision log

The record that shows each decision was made on evidence — decision, conditions, owner, date, and what would trigger a re-review — kept where an auditor can find it.

03

A policy drafted for sign-off

In your organization's voice, built with the legal, risk and security owners who have to approve it, so approval is the next step rather than another review.

04

One real use case through it

One live initiative taken through the path end to end, decision recorded, conditions documented — so the mechanism is proven on something real and your team has done it once.

How it runs

Four stages inside one fixed window.

Two to four weeks, set in scoping from how many systems, how many review functions and how much existing policy there is. The clock starts at kickoff, once the people and documents in the proposal are available.

STAGE 1

Map

The agreed scope: the AI in it, the people who currently say yes or no, the policies you have, and the obligations you are held to. Enough to route the first use case correctly, not an enterprise inventory.

STAGE 2

Design

The review path and the record — tiers, criteria, owners, timings — sized for your organization rather than lifted from a standard.

STAGE 3

Draft and clear

The policy, worked through with legal, risk and security until each owner is ready to approve it. Short, specific, in your voice.

STAGE 4

Prove it

One live use case goes through the path end to end. Decision recorded, conditions documented, and the policy left ready for approval. Presented live to the people who own the next one.

2 to 4 weeks · fixed scope · fixed fee

Evidence

Governance that holds on every answer, not just on paper.

The hardest version of this problem is an AI system that talks to regulated audiences. This is what controls look like when they are built into the system rather than written beside it.

Life sciences · Regulated communications

A life-sciences data and communications provider

Teams answering pharmacists, providers, hospitals and patients had to stitch together CRM records, approved product labels and market data on the fly — and any mismatch with the label was a compliance exposure. We built an assistant that answers only from the approved source, tied to the right account, with the rules enforced on every response:

Answers drawn from the approved label and inserts, never the open web
Audience rules applied to every response — what a pharmacist may be told differs from a patient, a provider, a hospital
Every interaction auditable: which source, which rule, which account

Scattered, compliance-sensitive information became an on-demand assistant that was faster to use and easier to audit — because the governance was in the system, not in a binder next to it.

Read the story →

The same principle runs through every Quickstart: a review path only works if its decisions can be applied where the AI actually operates. We design the path so the controls it specifies are the kind a system can enforce and a log can show — which is what makes it clearable.

Fit

Right-sized when one decision is waiting and someone specific can make it.

Two short lists. If you recognise yourself in the first, the Quickstart is the right size. If the second reads truer, we will point you at the engagement that answers your actual next question.

This is a good fit when

  • An AI use case is waiting for a decision and nobody can say what would clear it — or one is coming that needs a defensible answer.
  • Legal, risk or security owners exist and can be in the room.
  • You can list the AI in use and in flight, even roughly.
  • You want the path to work for the next use case without us.
  • An auditor, regulator or board is going to ask how decisions were made.

Start somewhere else when

  • You are still deciding whether to use AI at all — that is the Assessment Sprint.
  • No one owns risk, legal or security decisions yet, so there is nobody to sign.
  • The real exposure is security posture rather than review process — that is the Cyber Risk Sprint.
  • You need governance operated continuously, with tooling — that is the Strategy & Governance practice.
Deliberately outside the windowAn enterprise-wide governance operating model · a full AI inventory across every business unit · ISO/IEC 42001 implementation or certification preparation · governance tooling · continuous monitoring · a model validation program · an enterprise control library · ongoing governance operation · legal advice. Those are the practice, and the Quickstart is built to lead into it — which is why this is two to four weeks and not a transformation.

Where it sits

Find it, prove it, run it. Use the smallest engagement that answers the next question.

The Assessment Sprint scores governance as one of six dimensions. A weak score is the usual reason to come here. Governance as an operating function lives in the practice.

Don't know where the problem is?

AI & Data Assessment Sprint

Two weeks that score six readiness dimensions — governance and review path among them — against your own systems.

See the Assessment Sprint
Know governance is the problem and need one path working?

AI Governance Quickstart

The path, the record and the policy, proven on one real use case, and left with you to run.

Tell us what is waiting for a decision
Need governance operated across the enterprise?

Strategy & Governance practice

Operating models, responsible-AI programs and the tooling that keeps the review path running at scale.

See the practice

Before you ask

The buying questions that matter.

The six things the sponsor, counsel and the risk owner ask before a governance engagement is approved, answered the way we answer them in the proposal.

Will this slow AI work down?

It replaces an undefined review with a defined one. Work that is currently waiting for an answer nobody can give gets an answer with a date on it — and a fast lane for the low-risk majority, so the heavy review is spent where it is warranted.

Does this cover the AI we already have running?

Within the agreed scope, yes. Mapping what is in use there is the first stage, and existing systems are brought under the same path rather than grandfathered around it. An enterprise-wide inventory is a practice engagement, not this one.

Which frameworks do you build on?

The NIST AI Risk Management Framework and ISO/IEC 42001 as the structure, your existing policies as the starting point, and the federal and state requirements that apply to you as the constraint. The path is sized for your organization, not lifted from a standard.

Who writes the policy, you or us?

We draft it, in your organization's voice, from the review path we design together. Your legal, risk and security owners work through it with us until it is ready for their approval. Your counsel reviews it; this is not legal advice and we do not replace them.

What does it cost?

The fee is fixed in writing before work starts and depends on how many AI systems are in scope, how many review functions are involved and how much existing policy there is to build on. Work inside that boundary is not billed hourly.

What do you need from us before kickoff?

Access to the people who currently say yes or no, your existing policies, and a rough list of the AI in the agreed scope. The specifics are written into the proposal before you commit.

Start from the decision

Tell us what is waiting for a governance decision.

Not a framework name. Give us the use case, who owns the decision, what is unresolved, and what already exists. We will describe the review path back — tiers, owners, window and fixed fee — before you commit to anything.

The use caseWhat needs a decision
The decision ownerWho has to be able to say yes
What is unresolvedThe question nobody can answer yet
What already existsPolicies, reviews, AI in use

Not sure governance is the weak dimension? Score all six free in seven minutes and bring us the result.

A decision waiting? Tell us the use case and who owns the call.