Governance,
installed.
I deploy an advisory agent into your organisation, backed by a senior risk practice. It reads what the company has written about itself, asks your leadership what actually happens, and shows the executive team where those two answers stop matching — then turns the gaps into work with named owners.
The company the chief executive describes. Clear, decisive, and usually written down nowhere.
The company the policies describe. Comprehensive on paper, silent exactly where the new risks are.
The company your department heads describe when asked separately. This is the one that decides.
Every organisation runs all three at once. Governance is only real where they agree — and the widest gap is almost always the same one: who owns AI decisions when they go wrong.
Where to start.
One flagship deployment and five ways in. Each runs on published methods you keep afterwards.
Governance deployment
The full engagement. An executive intent session, a read of every document the company has written about itself, structured interviews with each department head, a divergence assessment for the board — and then the part everyone skips: gaps converted into tasks with named owners, and an agent that stays behind to keep score.
Executive intent session
Ninety minutes with the chief executive on what company this is meant to be: which decisions you keep, which you delegate, what risk the business will carry. Most of it has never been written down. That's the finding.
Governance assessment
Stated, documented and lived governance scored against one model, with the gaps ranked by what they cost you rather than by distance from a framework. Delivered as something a board can decide on.
Control framework & regulatory crosswalk
A control library mapped across the obligations that touch it — EU AI Act, NIS2, DORA, CRA — so one piece of evidence answers four questions instead of one, and your team stops rebuilding the same proof in four formats.
Executive tabletop
A crisis your leadership hasn't rehearsed: an AI system producing biased outcomes in production, with a journalist already asking. Run to find out who actually decides under pressure, not to be passed.
Board & executive advisory
A second opinion on call for chief executives, CISOs and audit committees. Regulatory interpretation, control design decisions, and the papers that have to survive a regulator reading them.
XXX
XXXXXXXXXX.
An agent is only as good as the practice it encodes. The methods it runs are mine, and I'm in the room for the decisions that matter.
Principal Risk Advisor in the enterprise risk function of a global energy company, advising at executive and senior-vice-president level across the whole portfolio rather than any single business unit. Currently half-seconded into cyber defence, deliberately: governance written by people who have never watched an incident unfold is governance nobody follows.
Before that, consulting at PwC and leadership of a 200-person cybersecurity risk advisory team. Current work sits where AI governance meets operational security — the EU AI Act, NIS2, DORA and the CRA arriving at the same organisations at once, usually asking for the same evidence in four different formats.
The agent exists because the same questions repeated in every engagement and I could never answer them the same way twice. It does the repetition. I do the part that was always judgement — including sitting with a chief executive who has just seen the divergence view and doesn't like it.
Tell me the decision you're stuck on.
If a deployment isn't the right answer, I'll say so in the first reply. That's cheaper for both of us than a proposal.