AI / AI-02
AI governance and risk assessment
Identify AI uses, owners and risks to decide what may be deployed and under which conditions. The programme links quality, security, personal data, human oversight and change monitoring.

WHEN IT HELPS
A focused response
to a defined need.
Growing AI projects, leadership requesting rules, sensitive-data processing or a decision file needed before broad rollout.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Inventory
- purposes
- stakeholders
- impacts
- providers
- flows
- risks
- oversight
- usage rules
- acceptance criteria
- incidents
- model changes and reassessment
Deliverables
- Use-case register
- risk assessment
- AI policy
- responsibility matrix
- requirements
- approval checklist
- treatment plan
- input to relevant regulatory assessments
Acceptance evidence
Priority uses are registered; owners and acceptance criteria are named; residual risks are decided; change processes work; legal analysis is owned by competent parties.
DELIVERY
How the work is structured.
Approach
Choose a use case; classify data and access; design and pilot; test privacy, actions and cost; decide rollout and monitoring.
Prerequisites & responsibilities
Customer: business sponsor, data owners, identity team, DPO/legal where needed and budget. Provider: architecture and tests; customer retains approval of sensitive use.
Scope factors
Uses, users, models, data, connectors, permissions, actions, volumes and hosting. Separate project, licenses, tokens, search, storage and operations; no claimed savings without measurement.
Questions to clarify
Who decides acceptable use? Which errors would have significant impact? What role does the organisation play and which rules actually apply to each use case?
IMPORTANT BOUNDARIES
Regulatory classification, obligations and timing must be checked case by case. NIST/OWASP frameworks are aids, not legal certifications of the use case.
Permissions, provider data use, retention, residency and cost enforcement are assessed separately. Technical features and applicable obligations are checked for the chosen offering and use case.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A group receives AI requests from every function. Project: create a checklist distinguishing document assistance from sensitive decisions. Target outcome: proportionate approval, with limited pilots for lower-risk uses and stronger review for others.
Scenario 02
A company wants to automate a decision affecting individuals. Project: assess impacts and requirements with legal advisers and the DPO. Target outcome: an informed decision to proceed, redesign or stop, without promising compliance through a tool purchase.
Technology and reference context
References: NIST AI RMF/GenAI Profile, CNIL and OWASP GenAI; register and workflow tools tailored to the customer.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
