Skip to content

Home Expertise / Secure AI

AI / AI-02

AI governance and risk assessment

Identify AI uses, owners and risks to decide what may be deployed and under which conditions. The programme links quality, security, personal data, human oversight and change monitoring.

WHEN IT HELPS

A focused response
to a defined need.

Growing AI projects, leadership requesting rules, sensitive-data processing or a decision file needed before broad rollout.

AT A GLANCE

Family
Secure AI

Engagement
Advisory and implementation

Reference
AI-02

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Inventory
  • purposes
  • stakeholders
  • impacts
  • providers
  • flows
  • risks
  • oversight
  • usage rules
  • acceptance criteria
  • incidents
  • model changes and reassessment

Deliverables

  • Use-case register
  • risk assessment
  • AI policy
  • responsibility matrix
  • requirements
  • approval checklist
  • treatment plan
  • input to relevant regulatory assessments

Acceptance evidence

Priority uses are registered; owners and acceptance criteria are named; residual risks are decided; change processes work; legal analysis is owned by competent parties.

DELIVERY

How the work is structured.

Approach

Choose a use case; classify data and access; design and pilot; test privacy, actions and cost; decide rollout and monitoring.

Prerequisites & responsibilities

Customer: business sponsor, data owners, identity team, DPO/legal where needed and budget. Provider: architecture and tests; customer retains approval of sensitive use.

Scope factors

Uses, users, models, data, connectors, permissions, actions, volumes and hosting. Separate project, licenses, tokens, search, storage and operations; no claimed savings without measurement.

Questions to clarify

Who decides acceptable use? Which errors would have significant impact? What role does the organisation play and which rules actually apply to each use case?

IMPORTANT BOUNDARIES

Regulatory classification, obligations and timing must be checked case by case. NIST/OWASP frameworks are aids, not legal certifications of the use case.

Permissions, provider data use, retention, residency and cost enforcement are assessed separately. Technical features and applicable obligations are checked for the chosen offering and use case.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A group receives AI requests from every function. Project: create a checklist distinguishing document assistance from sensitive decisions. Target outcome: proportionate approval, with limited pilots for lower-risk uses and stronger review for others.

Scenario 02

A company wants to automate a decision affecting individuals. Project: assess impacts and requirements with legal advisers and the DPO. Target outcome: an informed decision to proceed, redesign or stop, without promising compliance through a tool purchase.

Technology and reference context

References: NIST AI RMF/GenAI Profile, CNIL and OWASP GenAI; register and workflow tools tailored to the customer.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.