Governance, Risk & Compliance

AI regulation, data residency, and sector-specific compliance are moving targets. Get it wrong and a project stalls in due diligence or fails an audit. Get it right, and governance becomes a trust signal that speeds procurement up rather than slowing it down.

The problem

Organisations in the public sector, life sciences, telecom, and financial services face an expanding web of regulation — the EU AI Act, GDPR and data regionality, GxP in life sciences, sector-specific reporting obligations — alongside internal pressures to adopt AI and modernise quickly. The governance gap between "we want to use AI" and "we can prove to a regulator that we're using it responsibly" is where projects stall or, worse, proceed without adequate safeguards.

What I do

  • Design governance frameworks aligned to the EU AI Act, data regionality requirements, and sector-specific regulation — not generic policy templates, but frameworks that reflect how your organisation actually works.
  • Build the policy chain from board-level oversight down to day-to-day operational practice, so governance is actually followed rather than filed away in a SharePoint folder nobody opens.
  • Integrate risk management into delivery and PMO structures, so compliance is designed in from the start rather than checked at the end.

Governance that's defensible under audit, faster sign-off from security and procurement teams, and materially lower regulatory risk — without adding months to delivery.

Get a governance framework reviewed or built

Other services

Technology & Product Leadership

Choosing, building, and roadmapping technology that meets real user and organisational need.

Delivery & Transformation Assurance

Risk-managed delivery for complex, multi-stakeholder programmes.