From zero AI visibility to audit-ready governance in 14 weeks
A UK-regulated asset manager with AUM exceeding £8bn had deployed AI across investment research, AML screening, client suitability assessment, and document review. No central inventory existed. No accountability framework had been built. The compliance team had identified the EU AI Act as a material risk but had no clear path to readiness.
The organisation could not answer three basic questions: which AI systems were in use, who was accountable for the decisions they influenced, and whether any of those systems met the EU AI Act's high-risk classification threshold. Shadow AI (tools adopted by teams without central oversight) was widespread.
- AI Surface Mapping™ across all departments, including a structured shadow AI amnesty process that surfaced 7 previously undisclosed tools
- EU AI Act risk classification for all 15 registered AI systems. Three classified as high-risk, requiring full Article 9 compliance programmes.
- Decision Accountability Matrix built for 12 AI-influenced decision types, with named human owners and documented oversight methods
- Risk register populated with 13 quantified risks, prioritised by likelihood and impact, with mitigation owners assigned
- Governance Playbook developed covering AI use policy, incident response, escalation procedures, and board reporting templates
- Maturity Assessment completed, establishing a Level 3 baseline with a structured roadmap to Level 4
"We went from not knowing what AI we were running to having a board-ready governance report in under four months. The methodology is rigorous. It does not let you take shortcuts."