Skip to content

AI governance consultancy

AI Governance Consultancy UK

Governance AI is a UK AI governance consultancy for boards: a scored diagnostic (from £3,950), policy and control design, and engineered evidence, mapped to ISO 42001, NIST AI RMF, UK GDPR and your sector regulator — led by Dr Karl George MBE, founder of The Governance Forum.

  • 24,676.

    resident messages handled in productionas of 20 April 2026

  • 1,313.

    maintenance jobs created from more than 20,000 inspection photosas of 20 April 2026

  • 14 / 14.

    validation scenarios returning the expected decision and query codecontrolled test, 20 May 2026

  • Six.

    AI systems designed and built, from a governance platform to public-sector evidence

Every figure above is drawn from systems we have built and run. The detail sits in our case studies.

Who this applies to.

UK boards, company secretaries, risk and audit committees, and executives in regulated or public-facing organisations who are evaluating or buying AI governance help — from a first scorecard through to implementation. We work most often with:

What the board needs to decide.

Before you engage anyone, five decisions shape what you should buy and in what order.

  • Whether the immediate need is diagnosis (where do we stand) or implementation (build and prove the controls).
  • Whether ISO/IEC 42001 certification readiness or EU AI Act scope is in play for you this year.
  • Who owns AI governance internally, and what evidence they will need to show a regulator or auditor.
  • Advisory alone, or an adviser who has also shipped governed AI systems into production.
  • Budget tier: the free Board AI Scorecard, then GovernIQ Lite (£3,950), the full diagnostic (£9,950), or diagnostic plus roadmap (from £18,000).

For the numbers in full, see our AI governance consultancy pricing guide.

What Governance AI does.

We run two service lines. The first is a board-level advisory programme — Foundation, Development and Accreditation — that takes a board from AI literacy to a defensible governance position and, where it fits, the Governance AI Quality Mark. The second is governance-first builds: we design and ship production AI with the controls written into the code, not bolted on to pass a review.

Most firms do one or the other. We do both, with one team, so the governance and the system are never lost in a handoff between adviser and developer.

How an engagement works

From baseline to evidence a regulator can inspect.

An engagement is a sequence of controls, each producing evidence with a named owner. This is the same discipline we apply at the model level, one rung up.

ControlEvidence producedOwner
AI inventory and scorecard baselineBoard AI Scorecard result and a first inventory of where AI is already in useCompany secretary / board
GovernIQ™ diagnosticA scored readiness report across five areas, presented at a board readoutRisk or audit committee
Policy and rolesAn AI governance policy, an acceptable-use standard, and a named accountable ownerNamed AI owner (executive)
Engineered controlsRead-only data access, an append-only audit ledger, confidence floors and human approval gates, written into the codeCTO / delivery team
Assurance and Quality Mark preparationControls mapped to ISO/IEC 42001 and the NIST AI RMF, and an evidence pack a board or auditor can inspectBoard / external auditor

At system level, this becomes a specific set of AI model governance controls.

The frameworks we map your governance to.

AI does not create a separate rulebook. It runs through the standards and regulators you already answer to.

FrameworkWhat it governsHow we map to it
ISO/IEC 42001The AI management system: policy, roles, risk process and continual improvement.We prepare you for certification and leave the evidence in place. We do not issue the certificate.
NIST AI RMFThe risk function across Govern, Map, Measure and Manage.We map each control we design to the four functions, so the work is legible to a US-facing or model-risk audience.
UK GDPR / ICOPersonal data, automated decisions and the duty to complete a DPIA where the risk is high.We review where AI touches personal data and what a data protection impact assessment must record.
EU AI ActRole-based scope (provider or deployer) and risk tiers, which can reach a UK-only organisation.We assess whether the Act applies to you and, if it does, what your role obliges you to hold.
Sector regulatorThe duties you already answer to: FCA, RICS, DfE/ESFA, the RSH or the ICO for local authorities.We score the diagnostic against your regulator, not a generic checklist.

Going deeper on one of these? See our guides to the ISO 42001 consultant question and EU AI Act consultancy scope.

Exhibits

Three engagements, read as evidence.

Each one follows the same line: the exposure a board carried, the control we implemented, the evidence that control now produces, and what it changed operationally. Clients are anonymised.

Property management

A UK residential property management company

In production

Board exposure
Repetitive, time-sensitive operations work: resident questions out of hours, faults to triage, inspections to turn into jobs, and staff check-ins that vanish into chat. The load had to be absorbed without losing human control of the decisions that matter.
Control implemented
Analytics is read-only by construction, so the database itself rejects any write the model attempts. A cost-approval gate holds any landlord spend above £200 for a human decision, and tenants never see cost figures.
Evidence produced
An action ledger recording every tool action with explicit terminal states, including intentionally aborted stale messages, and a full stored transcript for every voice session.
Operational result
24,676 resident messages and 5,164 logged AI actions handled in production, and more than 20,000 inspection photos turned into 1,313 maintenance and operations jobs, as of 20 April 2026.
Read the full case study

Public sector

A policy and social-impact advisory organisation, with a UK regional public authority

Deployed to our infrastructure · pre go-live

Board exposure
A public body needed to turn a large evidence base into defensible analysis without letting an AI make or influence decisions it has no business making, and had to show a regulator exactly how the system works before go-live.
Control implemented
Advisory-only by hard constraint in the system prompt: no bid scoring, no contract influence, no automated decisions, aggregated and anonymised data only. Row-level tenant isolation designed to fail closed, with UK data residency for embeddings and storage.
Evidence produced
Chunk-level citation provenance, page, character offset, source tier and link, so every answer is traceable to the exact passage, alongside a compliance pack mapping the system to the standards a UK combined authority asks for before go-live.
Operational result
A compliance posture mapped to the NCSC 14 Cloud Security Principles, UK GDPR (DPIA and Article 30), the Algorithmic Transparency Recording Standard and Cyber Essentials, with 36 automated tests and citation provenance verified end to end.
Read the full case study

Finance operations

A UK residential interiors business

In production · internal tool

Board exposure
Invoices arriving as PDFs, images, forwarded email chains and mixed submissions, with references scattered across the message and the attachment. The finance team needed confidence that an invoice was genuinely safe to post, not simply that text had been extracted faster.
Control implemented
The AI never executes ERP writes. It returns structured data and deterministic code decides whether to post, with a configurable confidence floor (default 0.9) that can turn an AI recommendation to post into a manual query.
Evidence produced
An enumerated catalogue of query codes, so every held invoice records exactly why it was held, with raw payloads and decisions persisted with timestamps.
Operational result
14 of 14 validation scenarios returned the expected decision and query code (20 May 2026), and batch extraction on a real multi-invoice document separated 25 of 25 invoices (27 May 2026).
Read the full case study

What each kind of provider can and cannot do.

Boards often shortlist a management consultancy, a development firm and a certification body side by side, as though they were the same purchase. They are not. This is what each can actually sign up to.

ProviderAdvisesBuildsImplements controls in codePrepares board evidenceCertifies ISO 42001
General management consultancyYesNoNoSometimesNo
Software development firmNoYesSometimesNoNo
Certification bodyNoNoNoNoYes
Governance AIYesYesYesYesNo

Our last column is a deliberate no: certification against ISO/IEC 42001 can only be issued by an accredited certification body after an audit. We prepare you for that audit and leave the evidence in place, and we will not imply our own sign-off is the same thing.

Why Governance AI

Board authority, and systems we have actually shipped.

Our advisory is grounded in the practice of our founder, Dr Karl George MBE — founder of The Governance Forum, creator of the TGF Governance Code and the RACE Equality Code, and Partner and Head of Governance at RSM UK. No UK boutique in this market leads with a board-governance figure of that standing.

That authority sits on top of an AI-native operating model and systems we have built and governed: read-only data access, append-only audit ledgers and confidence floors that overrule the model, engineered into production rather than described in a policy.

Engagement and procurement

What buying this actually involves.

The detail a procurement or governance lead needs before putting a paper to the board. The GovernIQ diagnostic runs in five steps over two to four weeks.

What you provide

  • Access to the people who shape AI decisions for structured interviews: two to three on GovernIQ Lite, five to eight on the full diagnostic.
  • The policies, registers and controls you already have, however partial.
  • A named internal owner who can chase documents and answers.
  • A board or committee slot for the readout, 60 minutes on GovernIQ Lite.

Who should be involved

  • The company secretary or governance lead, as the usual day-to-day counterpart.
  • The chair of the risk or audit committee, who receives the scored result.
  • The executive who will own AI governance once the engagement ends.
  • Whoever holds IT, data protection and supplier management, because most AI exposure arrives through them.

What is included

  • A scoping call to confirm fit and agree scope and price before you commit.
  • Structured interviews and a review of your existing policies, registers and controls.
  • A readiness score across the five governance areas, scored consistently so you can re-score later.
  • A board-ready report and a prioritised action plan, presented at a readout by our team.

What is not included

  • ISO/IEC 42001 certification. Only an accredited certification body can issue it.
  • Legal advice. We tell you what a regulator or auditor will expect to see, not what the law means for you.
  • The remediation work itself, unless you take the diagnostic plus roadmap tier or a build engagement.
  • Software licences or ongoing monitoring. Prices exclude VAT.

What happens after delivery

  • You keep the scored baseline and can re-score it as your AI use grows.
  • The diagnostic fee is credited against a 90-day Governance Sprint if you decide to proceed.
  • Where a control has to be enforced in software rather than described in a policy, our build line writes it.
  • If nothing further is proportionate yet, we will say so.

Full deliverables, tiers and steps are on the GovernIQ Diagnostic page.

The people accountable for the work.

Two named leads, one on the governance and one on the engineering, and you meet both before you commit.

Portrait of Karl George MBE

Dr Karl George MBE

Founder & Chief Executive, Governance AI

Karl George MBE is an internationally recognised governance expert and the creator of the TGF Governance Code, a twelve-principle framework endorsed by the late Sir Adrian Cadbury. A Fellow of the Chartered Governance Institute and a qualified accountant, he founded the governance forum (tgf) and is Partner and Head of Governance at RSM UK.

Full profile
Portrait of Hamada Mahdi

Hamada Mahdi

Chief Technology Officer, Governance AI

Hamada Mahdi leads the design and delivery of Governance AI's systems, from the BoardServe platform to bespoke client builds. The governance controls are written into the code.

Full profile

Common mistakes when buying AI governance.

The failures we are most often called in to fix have the same few roots.

  • Buying a framework or a policy pack with no evidence behind it. A policy a regulator cannot test is a statement of intent, not a control.
  • Treating a diagnostic as a one-off certificate rather than a baseline to re-score as your AI use grows.
  • Hiring for brand over shipped evidence. Ask what the adviser has actually built and governed, not only what they have reviewed.
  • Assuming a consultancy's certification claim is the same as an accredited certification body's audit. A consultancy prepares you; only an accredited body can certify you against ISO/IEC 42001.

For a vendor-neutral way to test any adviser, see how to choose an AI governance partner and our responsible AI consultancy selection test.

Questions boards ask us first.

If yours is not here, a short conversation will answer it faster than another page would.

Start where it is proportionate.

The free Board AI Scorecard takes about two minutes and tells you your weakest area and the right next step. The GovernIQ™ Diagnostic goes deeper, from £3,950.