Phase 01
Discovery & Risk Baseline
We map the AI systems, obligations and controls in scope, and agree what has to be evidenced.
- Stakeholder alignment
- AI and obligation inventory
- Risk baseline
- Evidence requirements
- Framework scoping
Prevents scope drift and governance blind spots.
Phase 02
Classify & Approve
Each AI system is classified by risk and routed through structured approval, with named owners.
- Risk classification
- Approval gates and criteria
- Committee workflow
- Ownership assignment
- Policy mapping
Prevents unassessed AI systems reaching production.
Phase 03
Sandbox & Policy Review
Systems are tested in a controlled sandbox and reviewed against policy and obligations before release.
- Sandbox testing
- Control design and testing
- Policy and obligation review
- Human oversight points
- Documentation and sign-off
Prevents untested models touching production data or customers.
Phase 04
Deploy, Monitor & Evidence
Go live with runtime monitoring, reporting and evidence captured as the work happens.
- Runtime telemetry
- Continuous control testing
- Evidence capture
- Regulatory reporting
- Periodic review
Prevents governance decay after go-live.
Engagement Transparency
- Defined timelines
- Measurable milestones
- Clear ownership
- No black-box delivery