Skip to content

AI governance & compliance

Evidence of what your AI does, produced as it runs.

The documentation, logging and human oversight that regulators, customers and auditors now ask for — built into your systems as standard, rather than reconstructed after the fact.

Why this matters now

97%of organisations that reported an AI-related security incident lacked proper AI access controls.Source: IBM and Ponemon Institute, Cost of a Data Breach Report, 2025
63%of breached organisations had no AI governance policy to manage AI or prevent unsanctioned use.Source: IBM and Ponemon Institute, Cost of a Data Breach Report, 2025
34%— among organisations that do have an AI governance policy, the share that regularly audit for unsanctioned AI.Source: IBM and Ponemon Institute, Cost of a Data Breach Report, 2025

The EU AI Act's obligations for high-risk systems now apply from 2 December 2027 for stand-alone systems, and 2 August 2028 for AI built into regulated products. Transparency obligations already apply. The deadline moved; the requirements did not. And customers, procurement teams and auditors are not waiting for it — they are already asking for an inventory of the AI you run and evidence of how it was built.

What we build

Conformity-ready build & governance setup

We build new systems, or retrofit existing ones, so they produce the required technical documentation, logging, human-oversight controls and evaluation evidence as standard. We also set up the governance scaffolding — the AI inventory, risk classification, documentation pipeline and monitoring that keeps the evidence current. The same evidence supports ISO/IEC 42001 and the NIST AI Risk Management Framework.

Where it applies: an HR-tech or credit-scoring vendor whose product is high-risk under the Act · a company preparing for ISO/IEC 42001 certification · a board asking what AI the company runs and what its exposure is.

Article 50 transparency build

Disclosure at the first interaction that people are dealing with AI, labelling of generated content, and machine-readable marking. The disclosures themselves are accessible.

Where it applies: a chatbot or voice agent that must tell users they are talking to AI · a platform generating images, video or text that must be marked as AI-generated.

Decision records & human review

Where systems make or support decisions about people, we build the notices to affected people, the record-keeping, and the routing to human review that rules on automated decisions increasingly require.

Where it applies: a lender or insurer using AI in approvals · an HR platform screening candidates with AI.

What comes with it

  • An AI inventory — every system, what it does, and how it is classified
  • Technical documentation generated from the system itself, kept current as it changes
  • Logging of inputs, outputs and decisions, retained and protected
  • Human-oversight controls — the ability to review, override and stop
  • Evaluation evidence showing the system performs as claimed

Built secure and evidenced, as standard

Built so the evidence already exists when someone asks.

  • Security and compliance are not a separate service we sell. They are how the work is built, on every engagement — and in this area, they are the work itself.
  • That means three things in particular. Evidence is produced by the system as it runs, not written up afterwards, so it stays accurate as the system changes. Every AI system has its own identity and scoped access, which is the single control most breached organisations lacked. And oversight is engineered in — a person can see what a system did, override it, and stop it — rather than promised in a policy document.
  • Everything we build in this area is delivered against our published engineering standard, and ships with the evidence to prove it: the AI inventory, the technical documentation, and the logging and evaluation records.

How the work runs

  1. 01

    Scoping — which systems, what they decide, how they are classified.

  2. 02

    Design — the evidence model and oversight controls, written down.

  3. 03

    Build — against the published standard, every merge reviewed.

  4. 04

    Handover — documentation, logs and controls in systems you own.

Typical duration: 2 to 12 weeks. A transparency build for a single assistant sits at the short end; conformity-ready governance across several systems at the long end.

How we work

What we will tell you

Many systems turn out not to be high-risk at all, and when that is the case we will say so — the obligations are different, and so is the cost. Classification comes before anything is built.

What we do, and what we do not

We do

provide the engineering and the documentation that make a system conformity-ready and audit-ready — the inventory, the logging, the oversight controls, the technical documentation and the evaluation evidence.

We do not

issue certification, or give legal advice on whether a given system is compliant. That determination is yours, made with your legal and compliance advisers.

Tell us what you’re building.

Describe the problem in your own words. We will tell you honestly whether we are the right people for it.

modularitiEngineering  :  
Available