WeConsulting.

Join us.

Two different routes in, depending on how you want to work with us.

All Join us

TechnologyService

AI Governance and Risk

AI Governance and Risk Services help organisations adopt artificial intelligence deliberately: with a documented inventory of where it is used, clear accountability for each system, and controls proportionate to the decisions the model influences.

Overview

AI has entered most organisations sideways. A team licenses a tool, a vendor ships a model inside an existing product, someone automates a review step. By the time governance is asked about it, nobody can produce a list of where AI is being used, let alone who owns it.

That gap is now a supervisory question. The Qatar Central Bank's AI Guideline requires licensed entities to maintain an AI register and to obtain approval for high-risk systems. The EU AI Act's transparency obligations are live. We help organisations get in front of this: find the AI already in use, classify it by risk, and put governance around it that does not stop the business using it.

What this covers

  • 01

    AI inventory and discovery

    Finding every AI and machine-learning system actually in use, including models embedded in third-party products, and recording them in a register that can be shown to a supervisor.

  • 02

    AI governance framework

    Accountability for each system, an approval pathway for new use cases, human oversight requirements, and the escalation route when a model behaves unexpectedly.

  • 03

    Risk classification and impact assessment

    Tiering systems by the consequence of the decisions they influence, with impact assessments for the ones that affect customers, credit, employment or safety.

  • 04

    Model and data controls

    Controls over training data provenance, bias testing, drift monitoring, versioning and the records needed to explain a decision after the fact.

  • 05

    Third-party and generative AI risk

    Due diligence over AI vendors, contractual protections, and acceptable-use controls for generative tools including data leakage and confidentiality exposure.

  • 06

    Regulatory readiness

    Mapping obligations under the QCB AI Guideline, the EU AI Act and applicable data protection law, and building the evidence pack each one expects.

How we can help

What a full engagement typically produces. Scope is agreed up front and adjusted to what your organisation actually needs.

  • AI system inventory and register
  • AI governance framework and policy
  • Risk classification methodology and tiering
  • AI impact assessments for high-risk systems
  • Model and data control set
  • Third-party AI due diligence standard
  • Acceptable-use policy for generative AI
  • Regulatory gap assessment and remediation roadmap

Standards and frameworks

Work is delivered against recognised standards so that findings are defensible to your auditors, your board and your regulator.

ISO/IEC 42001ISO/IEC 23894ISO/IEC 42005NIST AI Risk Management FrameworkNIST Generative AI ProfileOECD Recommendation on AIEU AI ActQCB Artificial Intelligence GuidelineNCSA Guidelines for Secure Adoption and Usage of AIUAE Charter for the Development and Use of AI

Questions we get asked

We only use off-the-shelf tools. Does this apply to us?
Almost certainly. Most AI exposure sits in purchased software rather than models an organisation built itself, and the accountability does not transfer to the vendor. The inventory work usually surfaces more systems than management expected.
Will this slow down adoption?
The opposite, when it is done properly. Teams stall because nobody will approve a use case and there is no defined route to a decision. A tiered framework lets low-risk uses proceed quickly and concentrates scrutiny where the consequences are real.

Talk to us about ai governance and risk.

Tell us what you are trying to resolve. We will tell you honestly whether we are the right firm for it.