AI Governance & Readiness Assessment

Know your governance exposure before the regulator does

Structured gap analysis against EU AI Act risk tiers, NIST AI RMF, and ISO 42001 — for teams actually building and deploying AI systems.

"Practical AI governance for teams shipping AI, not just committees writing policy about it."

EU AI Act NIST AI RMF ISO 42001 12+ Years Engineering Fixed-Scope Engagements

Your AI systems are accumulating governance debt

The EU AI Act is not a future concern — it is live regulation. If you are building or deploying AI systems in the EU, or processing EU residents' data with AI, your systems are already in scope. Most organisations don't know which of their AI use cases qualify as "high-risk" under Annex III, or what specific obligations that classification triggers.

This creates compounding exposure:

Governance debt compounds. Every month a high-risk system operates without its obligations mapped is a month of undocumented liability.

An assessment now costs a fraction of a regulatory incident later.

Four Tiers. Different Obligations.

The EU AI Act organises AI systems into four risk tiers. Tier classification determines which obligations apply — and what you are required to demonstrate.

Unacceptable Risk

Prohibited

AI applications explicitly banned by the Act — subliminal manipulation, social scoring by public authorities, real-time biometric surveillance in public spaces.

  • Social scoring systems
  • Subliminal manipulation
  • Biometric categorisation by protected attributes
High Risk

Strict Obligations

AI systems listed in Annex III — including employment screening, creditworthiness, critical infrastructure, education, and safety-critical components.

  • Job-applicant screening (Annex III §4)
  • Credit risk scoring
  • Medical device components
Limited Risk

Transparency Duties

AI systems with specific transparency obligations — chatbots must disclose they are AI; deepfakes must be labelled. Lower burden but still in scope.

  • Customer-facing chatbots
  • AI-generated content
  • Emotion recognition systems
Minimal Risk

Voluntary Codes

The majority of AI applications fall here — AI in spam filters, AI-enabled video games. No mandatory obligations, but voluntary codes of conduct apply.

  • Spam filters
  • AI-enabled games
  • Recommendation engines (most)

From Exposure to Roadmap

Three steps. Fixed scope. You walk away knowing exactly where you stand and what to do next.

Step 01

Free AI Governance Quick-Scan

15–30 Min · No Cost · No Commitment

A short conversation to map out your AI systems and flag the biggest exposure areas. Is anything likely to hit "high-risk" under EU AI Act Annex III? Are there obvious policy gaps? You'll leave with a clear picture of whether a structured assessment makes sense.

Step 02

AI Governance & Readiness Assessment

Fixed Scope · Remote · Paid

Structured assessment of your AI systems against the three major governance frameworks. Deliverables are concrete — not a generic advisory report.

  • Stakeholder workshop — product, engineering, risk/compliance
  • Gap analysis: EU AI Act risk tiers, NIST AI RMF, ISO 42001 AIMS
  • Risk register: each AI system classified by tier, mapped to obligations
  • Written report: maturity rating, gaps, prioritised remediation roadmap
  • Live readout session with your team
Step 03

Ongoing Support

Optional · Retainer

Policy development support, governance retainer, and ongoing compliance monitoring as your AI systems evolve.

Available after completing the Assessment.

Assessment Methodology in Practice

A real worked example — not a hypothetical. EU AI Act risk classification and obligation mapping for a job-applicant screening system.

View Full Case Study →
System AI-Powered Job-Applicant Screening Tool Classification High Risk Framework EU AI Act Annex III
Obligation Reference Framework Status Control Summary
Risk Management System
Article 9 EU AI Act Implemented Documented risk register with identified failure modes, probability ratings, and mitigation controls. Reviewed quarterly.
Data Governance
Article 10 EU AI Act Partial Training data lineage documented. Bias testing performed at training time. Ongoing monitoring controls partially implemented.
Human Oversight
Article 14 EU AI Act Implemented All AI-generated screening decisions require human reviewer sign-off before action. Override mechanism documented and tested.

Three Frameworks. One Assessment.

The assessment maps your systems against all three major AI governance frameworks simultaneously — so you get a joined-up view of obligations rather than three separate reports.

Regulation

EU AI Act

The world's first comprehensive AI regulation. Mandatory for any organisation operating in the EU or processing EU residents' data using AI. Risk-tier based — obligations scale with the stakes of the application.

  • Annex III high-risk classification criteria
  • Articles 9–15 conformity obligations
  • CE marking pathway for high-risk systems
  • GPAI model provisions (GPT-class models)
US Framework

NIST AI RMF

The National Institute of Standards and Technology AI Risk Management Framework. Voluntary but increasingly referenced in procurement and regulatory guidance globally. Structured around four functions.

  • Govern — policies, culture, accountability
  • Map — context, risk categorisation
  • Measure — analysis and monitoring
  • Manage — prioritisation and response
International Standard

ISO 42001

The international standard for AI Management Systems (AIMS). Certifiable — organisations can achieve third-party accreditation. Complements ISO 27001 and provides a governance structure for AI across an organisation.

  • AI management system requirements
  • Leadership and accountability structure
  • Impact assessment process
  • Supplier and third-party AI oversight

Engineering-Grounded Governance

12+ years in IT — hands-on DevSecOps engineering, AWS cloud architecture, and delivery management — now applied to AI governance and readiness. I understand how AI systems are actually built and deployed, which means the governance advice is grounded in engineering reality rather than theoretical compliance frameworks.

I approach AI governance from an engineering background, not decades of GRC consulting. That means I ask different questions — what does this obligation actually require at the systems level? What does a compliant implementation look like in code and infrastructure? — and I translate regulatory language into things engineering teams can act on.

I work with product organisations and engineering teams navigating their first structured AI governance assessment — helping them understand their real exposure, not a vendor-inflated version of it.

Background & Focus Areas

  • EU AI Act — risk classification & obligation mapping
  • NIST AI RMF — Govern / Map / Measure / Manage
  • ISO 42001 AI Management Systems
  • DevSecOps & AWS cloud engineering
  • AI risk register development
  • Technical documentation & conformity evidence
  • Human oversight mechanism design
  • Delivery management & stakeholder facilitation

Stay ahead of AI governance developments

Practical AI governance analysis for CTOs, engineering managers, and technical leaders — covering EU AI Act developments, NIST RMF updates, and production deployment controls.

Weekly No hype Free
  • EU AI Act implementation updates and practical implications
  • NIST AI RMF guidance with real engineering context
  • Governance controls mapped to production AI systems
AI Security Brief Free
  • Weekly AI governance and regulatory analysis
  • EU AI Act obligation breakdowns
  • Practical controls for production AI systems
  • No vendor content — independent perspective

✓  No spam. Unsubscribe any time.

Book Your Free Governance Quick-Scan

A 15–30 minute conversation to flag your biggest governance exposure areas. Is anything you're building likely to be classified as high-risk under EU AI Act Annex III? Are there obvious policy gaps? No commitment — I'll tell you honestly what the picture looks like.

Fixed-scope engagements. Written deliverables you can act on. No open-ended retainers or vague advisory reports.