Structured gap analysis against EU AI Act risk tiers, NIST AI RMF, and ISO 42001 — for teams actually building and deploying AI systems.
"Practical AI governance for teams shipping AI, not just committees writing policy about it."
The EU AI Act is not a future concern — it is live regulation. If you are building or deploying AI systems in the EU, or processing EU residents' data with AI, your systems are already in scope. Most organisations don't know which of their AI use cases qualify as "high-risk" under Annex III, or what specific obligations that classification triggers.
This creates compounding exposure:
Governance debt compounds. Every month a high-risk system operates without its obligations mapped is a month of undocumented liability.
An assessment now costs a fraction of a regulatory incident later.
The EU AI Act organises AI systems into four risk tiers. Tier classification determines which obligations apply — and what you are required to demonstrate.
Prohibited
AI applications explicitly banned by the Act — subliminal manipulation, social scoring by public authorities, real-time biometric surveillance in public spaces.
Strict Obligations
AI systems listed in Annex III — including employment screening, creditworthiness, critical infrastructure, education, and safety-critical components.
Transparency Duties
AI systems with specific transparency obligations — chatbots must disclose they are AI; deepfakes must be labelled. Lower burden but still in scope.
Voluntary Codes
The majority of AI applications fall here — AI in spam filters, AI-enabled video games. No mandatory obligations, but voluntary codes of conduct apply.
Three steps. Fixed scope. You walk away knowing exactly where you stand and what to do next.
Free AI Governance Quick-Scan
A short conversation to map out your AI systems and flag the biggest exposure areas. Is anything likely to hit "high-risk" under EU AI Act Annex III? Are there obvious policy gaps? You'll leave with a clear picture of whether a structured assessment makes sense.
AI Governance & Readiness Assessment
Structured assessment of your AI systems against the three major governance frameworks. Deliverables are concrete — not a generic advisory report.
Ongoing Support
Policy development support, governance retainer, and ongoing compliance monitoring as your AI systems evolve.
Available after completing the Assessment.
The assessment maps your systems against all three major AI governance frameworks simultaneously — so you get a joined-up view of obligations rather than three separate reports.
EU AI Act
The world's first comprehensive AI regulation. Mandatory for any organisation operating in the EU or processing EU residents' data using AI. Risk-tier based — obligations scale with the stakes of the application.
NIST AI RMF
The National Institute of Standards and Technology AI Risk Management Framework. Voluntary but increasingly referenced in procurement and regulatory guidance globally. Structured around four functions.
ISO 42001
The international standard for AI Management Systems (AIMS). Certifiable — organisations can achieve third-party accreditation. Complements ISO 27001 and provides a governance structure for AI across an organisation.
12+ years in IT — hands-on DevSecOps engineering, AWS cloud architecture, and delivery management — now applied to AI governance and readiness. I understand how AI systems are actually built and deployed, which means the governance advice is grounded in engineering reality rather than theoretical compliance frameworks.
I approach AI governance from an engineering background, not decades of GRC consulting. That means I ask different questions — what does this obligation actually require at the systems level? What does a compliant implementation look like in code and infrastructure? — and I translate regulatory language into things engineering teams can act on.
I work with product organisations and engineering teams navigating their first structured AI governance assessment — helping them understand their real exposure, not a vendor-inflated version of it.
View LinkedIn ProfileBackground & Focus Areas
A 15–30 minute conversation to flag your biggest governance exposure areas. Is anything you're building likely to be classified as high-risk under EU AI Act Annex III? Are there obvious policy gaps? No commitment — I'll tell you honestly what the picture looks like.
Connect on LinkedInFixed-scope engagements. Written deliverables you can act on. No open-ended retainers or vague advisory reports.