Policy people will actually follow
Short, specific and written for roles rather than for lawyers: what you may use, on what data, what must be checked, and what is never permitted. One page per role, not forty for everyone.
An AI policy nobody reads is not governance. We build the version that works: rules people can follow, classification that matches real risk, and an evidence trail that answers a procurement questionnaire, an ICO enquiry or an assessor without a fire drill.
The failure mode is almost never a missing document. It is a document with no connection to how work happens.
Proportionate by design. A 40-person firm and a 4,000-person authority need the same components at very different weights.
Short, specific and written for roles rather than for lawyers: what you may use, on what data, what must be checked, and what is never permitted. One page per role, not forty for everyone.
Every AI use case recorded with purpose, data, owner and risk tier, reviewed on a schedule. This register is the spine everything else hangs from.
Where your systems sit in the risk tiers, which obligations apply to you as deployer or provider, and a staged plan against the timetable - for any organisation serving EU users or customers.
The AI management system mapped onto your existing ISO 27001 or quality processes rather than built beside them, whether or not you pursue certification.
DPIAs for real usage, lawful basis, transparency wording, retention and the transfer position - aligned to current ICO guidance and written so your DPO can defend it.
Monitoring, periodic review, a defined incident route with named owners, and a standing answer to customer due-diligence questions.
The engagement runs with the people who do the work, not around them. Sessions are short, scheduled around delivery, and every stage ends with something you can act on.
You get a named consultant for the whole engagement - the person in the room is the person doing the work.
What you run, what applies to you, and what you can currently evidence. Where no audit exists, this stage includes one.
Use cases registered and risk-tiered, so effort goes where the exposure is instead of being spread evenly.
Policy, register, DPIAs, controls and the incident route - drafted with you, sized to your organisation.
Training for staff and approvers, a walkthrough of the incident route, and a schedule that keeps the register alive.
Over-governance fails the same way under-governance does: people route around it. The framework has to be light enough to survive contact with a busy week.
Most obligations already have a home. Your existing information governance, clinical governance, SRA or FCA processes usually extend to AI more cleanly than a parallel structure would.
The test we design to is simple: when a customer, an assessor or a regulator asks how a decision was made, someone can answer within a day, with evidence, without calling us.
CedarGuard is a risk and compliance operating system for UK social housing delivery, built to the point where it is a live product at cedarguard.co.uk rather than a pilot that ended at a demo.
It is what this service looks like when it is built into the software rather than written beside it: obligations identified against the regulations that actually apply, decisions attributed to a named owner, and the evidence assembled as the work happens.
Governance built on an audit is quicker to produce, cheaper to maintain and much harder to pick apart.