AI Governance Policy
Our practice is grounded in international standards: ISO/IEC 42001, the EU AI Act and the NIST AI RMF.
Principles
Meaningful human oversight, transparency about AI system usage, active bias mitigation, information security and traceability of AI-assisted decisions.
Inventory and risk classification
Every AI system involved in a project is registered in an inventory with its purpose, data used, internal owner and risk level, following EU AI Act classification.
Impact assessments
Before any material deployment we run an AI Impact Assessment documenting risks to individuals, data exposure, vendor dependency and mitigating controls.
Data and intellectual property
We apply data minimization, privacy by design and contractual clauses preventing third-party model training on confidential client information without explicit consent.
Monitoring and incident response
Production systems are monitored with performance and quality KPIs. Incidents are logged, escalated and remediated with a documented post-review.
Editable base document. Replace this content with the definitive legal version for your jurisdiction.