By industry

Governance for models and the identities they use

Governance for models and the identities they act through.

The models are already in production, acting through credentials nobody inventoried, on data nobody classified for that purpose. Governance is arriving after the fact — the work is catching it up without stopping the roadmap.


The regulatory picture

What this sector has to satisfy

A certifiable management system, the security work underneath it, and the data protection rules that apply the moment training data contains people.


Where you are

The constraints at this stage

What tends to be true when companies come to us at this size.

Nobody has the full list of AI in use

Models in the product, copilots adopted by teams, agents wired into internal systems. Discovery almost always finds more than the org chart predicted.

Agents act through identities with no lifecycle

Service accounts, API keys and tokens created to let something act on a user's behalf, then never rotated, scoped down or revoked.

Buyers have started asking, and you have no answer

Enterprise security reviews now include AI questions — training data, retention, human oversight — and there is no artefact to point at yet.


How the engagement works

What actually happens

The same four beats every time, scoped to what this stage needs.

Discover what is already running

Models, copilots, agents and the integrations behind them, including the ones adopted outside IT. The inventory is usually the finding.

Threat model the workflows

Prompt injection, data leakage, output handling and what an agent can reach if it misbehaves — assessed per workflow, not in the abstract.

Control the identities and the data

Least privilege for agents and workloads, credential lifecycles, and lawful basis and retention for whatever the models were trained on.

Certify if it helps

Where buyers or regulators want independent assurance, ISO 42001 turns the programme into something assessable.


Proof

Track record

Across every engagement we have run, at every size.

0+

Companies Secured

Zero

Failed Audits

4-8

Weeks to Compliance

0+

Team Certifications


What you walk away with

The artefacts

Everything below is a thing you own at the end, not a promise about the process.

  • An inventory of AI systems, models, copilots and agents in use
  • Threat models for each production AI workflow
  • Guardrails, monitoring and defined human-in-the-loop control points
  • A non-human identity register with least privilege and rotation
  • Training and inference data mapping with lawful basis and retention
  • AI policy and acceptable use, written to be followed rather than filed
  • ISO 42001 management system, certified where that is wanted

Related

Where to go next

The problems this stage usually arrives with, and the services behind them.


Questions

What people ask at this stage

It is worth it when someone is asking — enterprise buyers, a regulator, or a board that wants independent assurance. If nobody is asking, the underlying governance work still matters and the certificate can follow later.
Yes, and often more urgently. You inherit the model's behaviour without controlling it, so the controls sit in what you send, what you do with the output, and what the integration is allowed to reach. That is squarely your responsibility.
Agents act through credentials. Those identities need the same governance human ones get — an owner, least privilege, rotation, expiry and review — except there are usually far more of them and they are created programmatically.
If it contains personal data, all of it applies: lawful basis, purpose limitation, retention, and data subject rights. Rights are the hard part, because deletion requests against a trained model are considerably harder than against a database row.

Govern what is already in production.

Tell us what you have shipped and what your buyers have started asking. We will start with discovery, because that is where the surprises are.