1import{j as e,L as o}from"./index-rkFokeON.js";import{t}from"./faqs-CsY7qeMb.js";import{S as s}from"./ServiceDetailPage-Chdomjga.js";import"./Seo-Dtc4E3wL.js";import"./FaqsArchive-BYb_57qY.js";import"./faqSchema-BDe6oodK.js";import"./zaptic-DmajjgD_.js";import"./Banner-CNPvf9k0.js";import"./FurtherReading-dW9R0Lfh.js";import"./customerLogos-CVY9hGrf.js";import"./pricing-BHeDRPbx.js";import"./check-Dzpfs9c_.js";import"./external-link-DbJ0Tc1n.js";const a={seoRoute:"/services/ai-governance",docsUrl:"https://docs.oxfordinfosec.com/ai-governance",hero:{eyebrow:"AI Governance & Security",headline:"Is our AI use",headlineAccent:"under control?",intro:["Your team is probably already using ChatGPT, Claude, or Copilot, whether or not anyone signed it off. Customers and investors have started asking for your AI policy, and the rules are taking shape: the EU AI Act if you sell into Europe, and regulator expectations here in the UK.","AI governance puts just enough structure around that: an inventory of what's in use, an AI policy people can actually follow, a risk assessment proportionate to your size, and a clear route to ISO 42001 when a customer or regulator asks for formal proof."],summary:["An AI governance framework sized for a small business: policy, risk assessment, and vendor review, without enterprise bureaucracy.","Answers ready for the AI compliance questions customers and investors now put in due diligence.","A straight route to ISO 42001 when you need to prove it formally, built on the same management-system structure as ISO 27001."]},problemIntro:"Most businesses adopt AI tools long before anyone governs them. Six things that prompt the call:",problems:[{situation:"Staff are already using AI tools",wrong:"ChatGPT, Claude, and Copilot arrive through the browser, company data gets pasted in, and nobody has agreed what's acceptable."},{situation:"A questionnaire asks for our AI policy",wrong:"Procurement and due-diligence questionnaires now ask how AI is used and governed, and having nothing to show reads badly."},{situation:"We sell into the EU",wrong:"The EU AI Act applies to AI placed on the EU market wherever the provider is based, and enterprise buyers are starting to check."},{situation:"Nobody has assessed the risks",wrong:"Without an AI risk assessment, nobody knows which uses are harmless and which touch personal data or real decisions about people."},{situation:"Our vendors keep adding AI features",wrong:"SaaS tools switch on AI processing by default, and your data flows to models nobody has reviewed or approved."},{situation:"Investors ask how AI is governed",wrong:"Funding rounds and exits now include AI questions, and answers assembled the week before rarely convince."}],howHeading:"How we put an AI governance framework in place",phases:[{n:"01",title:"AI governance foundations",duration:"Fixed scope",durationLabel:"Basis",summary:"We inventory the AI in use across the business, write an acceptable use policy your team will follow, run an AI risk assessment, review the vendors and tools involved, and brief your staff on the ground rules."},{n:"02",title:"ISO 42001 when you need it",duration:"Optional",durationLabel:"Step up",summary:"If a customer or regulator wants formal proof, we take you on to ISO 42001 readiness and certification. It uses the same management-system structure as ISO 27001, so much of the work carries over."},{n:"03",title:"Privacy integration",duration:"Optional",durationLabel:"With DPO",summary:"Where AI touches personal data we handle the privacy side: DPIAs for AI processing, the UK GDPR rules on automated decision-making, and what you have to tell people about how their data is used."}],howClose:"Most businesses stop at the foundations; ISO 42001 and the privacy work are there for when a customer or regulator asks.",assessHeading:"What we put in place",assessIntro:"Everything is proportionate to how you use AI. A ten-person company drafting emails with ChatGPT needs different controls from one shipping AI features to customers, and we scale the work accordingly.",assessAreas:["AI use inventory across teams and tools","AI acceptable use policy","AI risk assessment and register","Vendor and AI tool review","Staff guidance and briefing","Data handling rules for AI tools","DPIA screening for AI processing","Automated decision-making checks","AI incident reporting route","Transparency wording for customers","Regulatory watch (EU AI Act, ICO guidance)","ISO 42001 readiness roadmap"],fitFor:[{label:"2 to 250 users",text:"large enough that ungoverned AI use carries real risk, small enough that enterprise AI governance would be overkill"},{label:"Using AI tools or vendors",text:"ChatGPT, Claude, or Copilot in daily use, AI features switched on across your SaaS stack, or AI built into what you sell"},{label:"UK or EU exposure",text:"selling into the EU brings the EU AI Act into scope, and UK regulators expect AI use to be governed under existing law"},{label:"Facing due-diligence questions",text:"customers, investors, or acquirers asking for your AI policy or how AI use is controlled"},{label:"Not ready for certification",text:"you need working governance now, with ISO 42001 as a step up when a contract or market demands it"}],notIncluded:["ISO 42001 certification itself (a separate service we deliver)","Hands-on ML engineering or model development","Formal DPO duties (that's DPO as a Service)","Foundational security hardening (Security Foundations covers this)","Legal advice on contracts and liability"],deliveryParagraph:"You work with a named Lead Consultant whose AI governance and security credentials are recognised (ISO/IEC 42001 Lead Implementer or Auditor, CIPP/E, CISSP). They are your single point of contact, accountable for delivery, and the same person stays with you if you later step up to ISO 42001, so nothing has to be explained twice.",pricingHeading:"Term and pricing",pricingRows:[{phase:"AI governance foundations",term:"One-off",pricing:"Fixed fee, fixed scope"},{phase:"Ongoing upkeep",term:"Optional",pricing:"Recurring fee, keeps the policy and register current"},{phase:"Step up to ISO 42001",term:"Optional",pricing:"Scoped separately when you need it"}],pricingNote:"Exact figures depend on how widely AI is used across the business and what's already in place.",faqsTitle:"AI governance FAQs",faqs:t,furtherReading:["ai-governance-framework","ai-management-system","guide-to-iso-42001","cyber-security-risk-assessments","gdpr-for-small-businesses","tech-due-diligence-checklist"],banner:{title:"Work out how much governance your AI use needs.",text:e.jsxs("p",{children:["If staff are using AI tools without ground rules, or a questionnaire has asked for an AI policy you don't have, a short conversation will tell you how much governance is required. And if the security basics aren't in place yet,"," ",e.jsx(o,{href:"/services/cyber-security/security-foundations",className:"underline hover:no-underline",children:"Security Foundations"}
1)," ","is usually the better starting point."]})}};function f(){return e.jsx(s,{content:a})}export{f as default};
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.