Governance is not a template. It is a set of specific answers to specific questions the board will eventually be asked. We help you have those answers ready.
The questions are not hypothetical. A regulator will send a data request about how a model that touches customers is validated. A large enterprise customer will demand a security review that includes model provenance and third-party model use. A board member will ask, at the wrong meeting, whether the company has an AI policy that anyone actually follows. A journalist will ask what the company does when the model gets it wrong.
Governance is having credible written answers before those questions arrive. It is not a compliance binder that sits on a shared drive. It is the paperwork that makes it possible to move faster than competitors who are still writing theirs.
What we produce
- AI use policy. A written policy your workforce can actually read — what is allowed, what is prohibited, where the escalation lines run, what the enforcement mechanism is, and what the exception process looks like. Not a legal document (your counsel writes those) but the operational spine your legal document sits on top of.
- Model governance framework. The written process for how models — internal or vendor — get approved for use, how their performance is monitored, how issues get raised, and who decides when a model is retired. Scoped to the actual risk of the use case, not to the maximum risk anyone can imagine.
- AI committee charter. Where the operator wants a standing AI committee, a written charter — membership, cadence, decision authority, escalation, minutes discipline. Committees without written charters become theater. Written charters make them useful.
- Regulatory posture note. A short read on your specific exposure — EU AI Act (which risk tier, which obligations, on what timeline), sector-specific rules (SR 11-7 if you're a bank, HIPAA-plus if you're a covered entity, etc.), major-customer contractual asks. Written to be handed to your general counsel as an input, not as a legal opinion.
What we don't do
We don't practice law. We are not writing your terms of service, your DPA, or your regulator response. We produce the operational documents your general counsel and your CISO build against. Anyone who tells you their consulting product is a substitute for actual legal review is selling you exposure.
We also don't over-produce. Governance material is only as useful as the person willing to enforce it. If the honest answer is that a two-page written policy signed by the CEO will do more for you than a forty-page framework nobody reads, we write the two pages.
Every operator we've worked with has felt the tension between moving fast on AI and taking the time to write down what it looks like when this goes wrong. The choice is false. Written governance, done well, accelerates the program — because your GC can approve the next initiative in a day instead of a month, and your enterprise customers stop asking the same questions twice. Governance is a speed feature.
Engagement
Governance work is typically project-shaped — a four-to-eight-week design phase producing the policy pack and (optionally) a light retainer for the committee's first two or three cycles. Fee structures are fixed-fee for the initial phase; retainers cover facilitation and drafting support during committee ramp-up.
Introductions happen by referral. If you were pointed here by someone we work with, mention their name when you write. If not, tell us plainly where the exposure sits — regulator, enterprise customer, board — and what forcing function has surfaced it. We reply within two business days.