The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
AI governance
Start by finding out how much artificial intelligence your company already runs.
Almost every company has more artificial intelligence running than it realizes: the tool one department signed up for on its own, the feature that came embedded in a system already under contract, the assistant someone plugged into a process. We map all of it, classify each system by risk, and build the treatment plan, following market references for AI risk.
The inventory comes from conversation, not technical scanning. We cross-reference contracts, access records, and what each team tells us about its own day to day, because that is how unapproved use surfaces. Each system found is placed in the applicable risk tier based on what it actually decides.
For that, we need access to business teams, to whoever procures software, and to the list of systems in use. You receive the full inventory, the classification of each system, and, depending on the option you choose, the risk matrix with the impact on the people affected and the algorithmic impact assessment for the highest-risk systems.
The options change where the work ends up. The inventory alone is the starting snapshot, and it is often the most revealing part. The risk assessment turns the snapshot into a prioritized plan. The full program builds the structure that keeps the inventory from going stale: a usage policy, criteria for approving new systems, training, and a recurring committee.
The stages and deliverables below describe the Inventory and risk assessment modality. The other modalities appear when you request the proposal.
Interviews
We talk to IT, to security and to the business areas. Documents say what should happen; interviews say what does.
AI system inventory
We map what exists, including what arrived embedded in a system already under contract and what a department signed up for without telling anyone.
Risk classification
We place each system in the applicable tier from what it decides, rather than from what we would like it to be.
Risk assessment
For each system we ask what can go wrong, for whom and how badly, and we record the answer with the criteria in the open. This is where the risk matrix and the treatment order come from.
Gap assessment
We compare what exists today with what the reference requires, item by item, and classify each gap by risk and by effort to fix. The result comes out in order of attack: what to do first and why, instead of an inventory of everything that is wrong.
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.