Where real AI risk lives

We start by establishing how much AI risk you’re actually willing to carry. That risk appetite, combined with your sector and how you use AI, determines how much governance you need. However, almost all organisations need the following as a foundation:

  • An AI use policy your people can follow – not just sign.
  • An inventory of the AI tools in use.
  • A decision-rights map and the oversight committee that operates it – who approves what, and who’s accountable for reviewing it.
  • Integrated AI risk into your existing risk framework – no parallel system to maintain.

Risk Literacy sits at the heart of truly reducing risk and being compliant. If your people, from boardroom to frontline, do not understand your policy or risk appetite, then your governance is ineffective. The EU AI Act recognises this (Article 4 AI Literacy), and is a necessary component of compliance for those operating within the EU.

Meeting regulatory requirements will not be reviewing if your team have had prompt engineering training – they will be focused on whether you have suitably upskilled your teams in the risks and ethics in AI.

  • Bespoke AI Risk & Ethics workshops – mapped to your policy and risk appetite, not generic content.
  • Role-specific delivery – what your frontline needs to know isn’t what your board needs to know.
  • Evidence of delivery that satisfies Article 4 – ready to show a regulator.
  • This includes workshops focused on empowering your security, risk and intelligence teams.

Whilst the content is risk & ethics, protecting the organisation and its people, is it designed to compliment operations and improve adoption.

Governance sets the rules, and literacy helps people understand them – but neither tells you if they are followed. Assurance is where we measure the gap: how AI is actually being used, where it diverges from policy, and why.

  • An honest picture of what your people are actually doing with AI – gathered in a way that surfaces the truth, not a survey people learn to answer safely.
  • A gap analysis against your policy and AI inventory – what’s actually happening versus what’s supposed to be.
  • Compliance evidence ready for your board or a regulator – assembled before an incident.

Governance, literacy and assurance work give you a strong baseline – but AI tools, regulation, and how your people use both keep moving. Advisory is how that baseline stays current: a named advisor who already knows your organisation, on hand for what comes up between full reviews.

  • A named advisor who knows your governance framework and risk appetite – not a fresh briefing every time something comes up.
  • Scheduled reviews of your AI policy, decision-rights map and risk register as regulation and your AI use evolve.
  • Fast, informed answers when something lands unexpectedly – a new tool under consideration, a vendor’s claims to check, a question before a board meeting.

There’s a natural sequence here for many organisations: review the governance, deliver the literacy training, then build the assurance that shows you’re not just compliant, but genuinely managing the risks AI brings.

But you decide what’s needed, and in what order. If your governance is already tight but your team can’t find the time to deliver training, Risk Literacy might be exactly where we start.