Skip to content
AI Digital Hub

AI & Automation

AI Governance & Compliance

Ship AI your risk function will actually approve

  • DPDP Act 2023 and GDPR by design
  • Audit trails, not after-the-fact assertions
  • Model risk documentation your auditors accept
4-6 weeks
Governance package delivered

Alongside a build, not as a separate project

100%
AI decisions traceable to inputs

Request-level audit logging

Why this stops projects

The technical work finishes and then the system sits in staging for four months while risk, legal and security ask questions nobody prepared for. Where does the data go. What happens when it is wrong. Who approved this. Can we delete one customer's data from the vector index.

Those are all reasonable questions with cheap answers if you designed for them, and expensive answers if you did not.

The DPDP constraints that matter architecturally

Purpose limitation. Data collected to deliver a service generally cannot be repurposed to train a model without fresh consent. This shapes what your AI is allowed to learn from.

Erasure that reaches everywhere. A data principal can require deletion. If their information sits inside embeddings in a vector store with no lineage back to the source record, you cannot honour that. Chunk-level lineage is the fix, and it has to go in early.

Consent that is specific and revocable. Bundled, pre-ticked or vague consent is not consent. That changes form design, not just policy wording.

Significant Data Fiduciary duties. Above certain thresholds you owe additional obligations including a Data Protection Officer and independent audits. Worth knowing which side of the line you are on before you scale.

Human oversight, designed rather than declared

"A human reviews the output" is not a control unless you can say who, with what authority, seeing what context, within what time, and what happens when they disagree with the model. We specify that concretely and build the queue, the escalation path and the audit record that proves it happened.

How it runs

What the engagement looks like

Phases, not a proposal. Each one has an output you can see.

  1. 1

    Inventory and classify

    Week 1

    Every AI use case listed and risk-rated. Most organisations discover two or three they did not know about, usually in a spreadsheet.

  2. 2

    Map the data

    Weeks 1-2

    What personal data is involved, on what legal basis, where it goes, how long it stays and which sub-processors touch it. The unglamorous work that determines what you are allowed to build.

  3. 3

    Design the controls

    Weeks 2-4

    Human oversight where the risk requires it, refusal behaviour, PII handling, audit logging and retention. Designed into the system rather than described in a policy nobody reads.

  4. 4

    Document to audit standard

    Weeks 4-5

    Model risk documentation, DPIA and the use-case register, written so an auditor or a client's security team can follow it without a workshop.

  5. 5

    Rehearse the failure

    Week 6

    A tabletop exercise on an AI-specific incident — a wrong high-stakes output, a data leak through a prompt, a provider breach. Whether the runbook survives contact is better learned now.

FAQ

Questions we get asked

Talk to someone who does ai governance

Thirty minutes with an engineer who has delivered this, not an account manager. You will get a straight answer on feasibility, rough cost and where it would fail.

Or email [email protected] · we reply within 1 business day