As an AI governance consultant, I help firms put AI tools into daily use without losing control: clear rules, named owners and evidence you can show your board. I have done it inside a regulated firm.
I help you put the rules, owners and evidence in place so AI tools can move from trial to daily use, and stay there.
Most firms already use AI, often without anyone deciding to. Staff try ChatGPT or Microsoft 365 Copilot, a supplier switches on an AI feature, a team builds a small automation. Governance is how you find out what is in use, decide what is allowed and show that someone is in control. Done well, it is short, practical and run by your own people.
- An AI use policy. What staff may use, what they must never paste in and who checks the output. The free AI policy template is a good place to start.
- A register of approved tools and use cases. One list of what is in use, who owns it, what data it touches and how much risk it carries.
- Data boundaries. Agreed limits on which client and personal data each tool can reach, and which supplier terms are acceptable.
- Review and approval points. Sign-offs set by risk, so low-risk drafting moves quickly and anything irreversible waits for a named approver.
- Evaluation evidence. Tests on real examples before a tool goes live, with the failures and limits written down.
- A small governance group. A few named people with clear decision rights, so a new request gets a clear answer without waiting months.
- Regulatory mapping. Where relevant, how your controls line up with the EU AI Act and with what your own regulator expects.
- Staff training. Short, practical sessions so people know the rules and why they exist.
In a regulated firm, good controls are the reason AI tools reach production, not the thing that stops them.
At Alter Domus, a global fund administrator, I founded the AI Governance Committee that let our AI tools run under the EU AI Act. The same idea works in a smaller firm: agree the boundaries first, and approvals stop being a negotiation, because everyone knows what “safe enough” means.
The rest of the Alter Domus record is on the AI for financial services page.
It suits firms that want to use AI properly and need to show they are in control.
- Regulated firms, such as fund administrators, asset and wealth managers, advisers, accountants and law firms, where clients and regulators expect evidence
- Growing businesses where staff already use AI tools and nobody has agreed the rules
- Firms with an AI pilot that has stalled at the risk or compliance sign-off
- Companies that sell into the EU, or whose AI output is used there, and need to know where the EU AI Act applies
It is probably not for you if:
- You want a certificate. I don’t certify anything
- You need a legal opinion. That comes from a solicitor, and I am happy to work alongside one
- You want a thick policy manual for the shelf rather than rules people follow
- You don’t use AI yet and have no plans to
Each engagement is shaped around your firm, but most follow the same pattern.
- A free 30-minute AI consultation. We talk through how AI is used in your firm today and what worries you about it.
- A written proposal. Scope, fees, responsibilities and timeline are agreed in writing before any work starts.
- Find out what is in use. Short conversations with the people doing the work, and a first draft of the register.
- Draft the rules with you. Policy, data boundaries and review points, written in plain English and tested against real cases.
- Set up the group. Agree who sits on it, what it can decide and how often it meets.
- Train and hand over. Sessions for staff and for the group, so your own people can run it without me.
A working governance set-up that your own people run, not a report.
- An AI use policy that staff have read and understood
- A register of approved tools and use cases, each with an owner and a risk level
- A one-page record for each higher-risk use case: its purpose, data, review points and test results
- A written remit for the governance group: who sits on it and what it can decide on its own
- Where relevant, a map of your controls against the EU AI Act and your regulator’s expectations
- Trained staff, and a date in the diary for the first review
Want a second opinion on how your firm uses AI? Book a free 30-minute AI consultation and we can look at where governance would help first.
Read the responsible AI principles, or ask directly.
Book a free 30-minute AI consultationIs this legal advice?
No. It is practical guidance on running AI safely in your firm, not legal advice. I work alongside your solicitor, compliance team or data protection officer, and I say plainly when a question needs a legal view.
Can you certify us against ISO 42001 or the EU AI Act?
No. I don’t certify anything. ISO/IEC 42001 is the international standard for AI management systems, and certification against it comes from an independent certification body. I can design your governance with that standard in mind, so the groundwork is there if you decide to seek certification later.
Does the EU AI Act apply to a UK firm?
It can. It reaches UK firms that place AI systems on the EU market, or whose AI output is used in the EU. The guide to the EU AI Act for UK businesses explains when it applies and the current timetable.
We are a small firm. Isn’t this overkill?
It shouldn’t be. Governance should grow with the risk. A small firm using AI for drafting and research may need little more than a policy, a register and a named owner, with more controls only where the stakes rise. The guide to building an AI governance framework sets out the order to do it in.
How much does it cost?
It depends on the size of the firm and how much is already in place. After a free 30-minute AI consultation, the scope, fees and timeline are set out in a written proposal before any work starts.
How is our data handled during the work?
Data boundaries, access and retention are agreed before I see anything sensitive, and most of the work needs no client data at all. The responsible AI principles set out the approach used on every engagement.
