AI Governance & Assurance

AI adoption your board can explain, govern and defend

Cyber and governance-led advisory for organisations whose people are already using AI, before the structure to govern it has caught up. We build the footing underneath.

Cyber and governance-led Board-grade, not hype Fixed-scope, fixed-fee review
The problem

AI is live in your organisation before anyone can say who owns it

AI is already entering your business through staff, suppliers, client expectations and everyday tools. Adoption rarely waits for a board decision. It is usually live across the organisation before anyone can say who owns it, what data it touches, or whether its use could be defended to a client, an insurer or a regulator. The value and the exposure grow together, unseen.

And the exposure runs both ways. Ungoverned use carries risk. Failing to harness AI carries competitive cost — sophisticated buyers increasingly ask for evidence of AI governance and responsible-use practice before they award, and bids are already being won and lost on the speed of AI-enabled response.

Our stance

Most AI advice starts with the tools. We start with the conditions

Cyberbase is led from cyber security and information governance, not from technology sales, so our instinct is to capture the advantage only on a footing you can stand behind. We are here to let you move without inheriting a liability you cannot later account for.

What we mean by defensible

Your organisation can explain what AI is being used for, what data it touches, what risks it creates, who owns it, and what controls are in place.

Our method

The defensible-advantage test

Every AI use, and every recommendation we make, is held to four questions a board can repeat without us in the room.

01

Advantage

What commercial or operational advantage does it create?

02

Risk

What client, IP, data-protection or professional-liability risk does it carry?

03

Control

What specific control makes its use defensible?

04

Owner

Who inside your organisation is ultimately accountable for it?

Why security-led is different

A policy without controls underneath it is a framework in name only

AI governance and cyber security are not adjacent disciplines. They are the same discipline viewed from two ends. An AI policy is only as strong as the identity controls, data classification, supplier assurance and incident response sitting beneath it.

Layer 03 · What most advisers sell AI policy & board governance

AI policy, acceptable use, risk appetite, the standing governance body and its decision rights.

Layer 02 · What makes it operate AI-specific controls

The use register, the vendor-AI vetting gate, DPIA templates, controller and processor mapping, data-residency decisions, centralised licensing.

Layer 01 · What makes it true Cyber security baseline

Identity and access, endpoint protection, monitoring, device management, data classification, supplier assurance, an exercised incident response plan.

Remove Layer 01 and everything above it is decoration. Where we find the baseline absent, we say so, and we sequence it first — even when that is not the answer you were hoping for.

What this changes in practice

Data flows are mapped, not assumed

Where AI processing runs through SaaS brokers and onward suppliers, the real exposure is often two or three hops beyond the tool the business believes it is using. We trace it.

Controller and processor roles are established explicitly

Which AI providers are processors, which written agreements exist under Article 28 of UK GDPR, what sub-suppliers each provider uses, where data actually resides. Most organisations hold no consolidated view of this.

AI by Design, from inception

Privacy, ethical and security considerations are embedded into the AI development lifecycle as a foundational component — not a post-deployment measure.

Where clients start

Two front doors, both fixed-scope

Neither requires a programme commitment. Both give your board something it can act on.

Our front-door engagement

The AI Defensibility Review

Rather than a twelve-week study that ends in a slide deck — a fixed-scope, fixed-fee review your board can commission on its own authority.

⏲ About two weeks 📝 Fixed scope, fixed fee ✅ Board-signable, no programme commitment

AI use register

Every AI use already live in the organisation, inventoried and risk-scored.

Red Amber Green

The four-question test

Each use held to advantage, risk, control and ownership, so the board can judge it without us in the room.

90-day action plan

Owner-led: what to stop, what to permit, what to pilot, and what needs a named owner before it scales.

You receive a short written report, an AI use register, a risk-rated action plan and a leadership briefing. Every recommendation carries an internal owner, because governance has to live in your organisation to last. We propose external help, including our own, only where specialist depth genuinely warrants it.

The deeper assessment

AI, Security & Digital Readiness Discovery

For organisations with a stated AI ambition and a gap between it and the current state. Where the Defensibility Review establishes the footing, this establishes the whole picture — and gives the board the evidence it needs to decide direction, pace and investment.

8–10 consulting days 3–4 elapsed weeks Fixed professional services fee Mobilised in 1–2 weeks
Workstream A AI readiness

How staff actually use AI, sanctioned and unsanctioned. What data goes into which tools. Literacy levels, and the near-term gains available with the right guardrails.

Workstream B Cyber security posture

What the security posture looks like beneath the surface. Not as reported — as it is.

Workstream C Systems & data landscape

What exists, what is genuinely end-of-life versus extensible with targeted AI intervention, and the data quality, structure and ownership picture.

Workstream D Findings & direction

The most material gaps against stated ambition, the foundational actions that must come first, and realistic resourcing options — build, buy or partner.

The full practice

What we build once the picture is clear

Assessment tells you where you stand. These are the engagements that build what stands underneath — commissioned individually or as a sequenced programme.

AI governance framework & secure operating model

The structure that turns findings into a working system.

  • Custom AI risk framework categorising applications by risk level, defining unacceptable risk and prohibited practice against your own appetite, with heightened attention to sensitive technologies such as biometrics.
  • Governance architecture — the standing body that owns AI: composition, chair, reporting line, cadence and decision rights.
  • The filter group pattern — a small standing group reviewing tools before organisation-wide release, so new tooling enters a controlled environment.
  • Vendor-AI vetting — a repeatable checklist at the gate, with a lightweight DPIA template attached.
  • Controller/processor mapping and DPAs, with data-residency decisions made deliberately rather than by vendor default.
  • Protecting AI you have built — source-control mirrors, deployment-surface review, supply-chain hardening on pinned dependencies.

AI & information security policy suite

Most organisations we assess are missing the same five artefacts.

  • Information security policy
  • AI policy
  • Acceptable use policy, with AI-specific provisions
  • Mobile device policy
  • Information risk register

Together these are the policy bones of an information security management system — without the overhead of ISO/IEC 27001 certification where certification is not the right answer. Where you already run a business management system for ISO 9001 or 14001, we bolt the missing machinery onto it rather than building a parallel structure.

Fractional Information Security Officer

Named accountability, without a permanent hire.

  • The most common material gap we find is the simplest: nobody can confidently say who is responsible for information security.
  • A senior, credentialed practitioner placed into that named role on an agreed number of days per month, reporting into your board or AI governance body.
  • They own the policy estate, chair or attend the governance forum, run the AI vetting gate, and hold the risk register.
  • Monthly retainer against agreed days, with a formal review point at which the commitment can be adjusted. Available alongside our wider CISO as a Service offering.

AI literacy & effective-use training

Governance that people understand is governance that holds.

  • AI effective-use training — addresses uncoordinated and duplicated tool use, and builds the internal capability to run pilots properly. Cyberbase syllabus, tailored to your audience and format.
  • Cyber-awareness training — the current threat landscape, including AI-enabled threats. Almost every board asks for this once the AI conversation starts, because the two topics turn out to be the same topic.
  • The goal is to raise literacy across the organisation and empower stakeholders to understand their own responsibilities — which is what makes a framework survive its first year.
Beyond the review

The review is where we start, not where we stop

A secure, governed foundation matters only if it produces value, and value is realised in delivery, not in documents. We stay to help you put AI to work, placing experienced, ground-level AI delivery specialists alongside your teams on longer-term assignments, with governance and security discipline built in from the start rather than bolted on afterwards. For organisations already mature in their governance, this is where we add the most value of all.

1
AssessThe AI Defensibility Review establishes a governed, defensible foundation.
2
DeliverEmbedded specialists put AI to work alongside your teams.
3
ValueMeasurable business outcomes, on a footing you can defend.

Efficiency

Faster, leaner ways of working.

Customer experience

Stronger retention and added services.

New services & revenue

New propositions and growth.

Protected margin

Value delivered, profit defended.

Frameworks & standards

We work to the standards your regulators, clients and insurers already recognise

ISO/IEC 42001:2023
The international standard for AI management systems. A natural lineage for organisations already running ISO 9001 or 14001.
NIST AI RMF
Risk-management lens on AI, structured around Govern, Map, Measure and Manage.
EU AI Act
Risk categorisation, prohibited practice and compliance preparation for organisations in or trading with the EU.
ICO guidance on AI
The UK regulator's published expectations on AI and data protection, including where DPIAs are required.
UK GDPR / DPA
Controller and processor roles, Article 28 agreements, DPIAs and records of processing.
ISO/IEC 27001 & 27002
Full ISMS where certification is the right answer — and the control set where it is not.
ISO/IEC 27701Cyber Essentials & CE+NIST CSF 2.0NCSC CAFNIST SP 800-53ISO 22301
Evidence

Delivered, not theorised

Global aviation

Proactive AI governance and EU AI Act compliance

A custom framework categorising the client's AI applications by risk level, defining unacceptable risk and prohibited practice against their own risk appetite, with heightened attention to biometrics. We championed AI by Design, embedding privacy, ethics and security into the development lifecycle from inception.

6 mth
Programme
EU AI Act
Prepared ahead of enforcement
FTSE 100 aviation CNI

Enterprise data governance and AI enablement

A group-wide data strategy across seven operating airline brands, aligned to a £2bn+ transformation portfolio, covering data ethics and AI enablement. A federated, GDPR-compliant governance framework and a cloud-first platform embedding privacy by design.

40%
Lower audit risk and breach exposure
60%
Faster analytics onboarding
Global design practice

AI readiness discovery, UK and China studios

A practice with AI already live across its studios, including two tools built in-house with a university partner. We benchmarked maturity against ISO/IEC 42001, NIST AI RMF, ICO guidance and Cyber Essentials, and mapped the data-protection and IP exposure including three-hop SaaS-broker risk.

7
Board decisions, each with a named owner
90 days
Stabilisation and acceleration plan
Why Cyberbase

We bridge board governance and technical reality

Cyberbase brings together senior cyber security, information governance and hands-on AI systems experience. Our consultants include practitioners with formal computer science backgrounds, recognised cyber security credentials, and practical experience configuring, testing and applying modern AI systems.

What the board needs

Board-level governance

Risk, ownership, controls and defensibility, in language the board owns and can repeat without us in the room.

What is actually happening

Technical reality

How AI is genuinely being configured, licensed, routed and exposed inside your organisation — traced, not assumed.

We bridge the two. That is what separates us from governance advisers who do not understand the technology, and AI shops that do not understand governance. You work directly with our senior practitioners — deep expertise without the overhead structures of larger firms.

Chartered Security Professional (CSyP) Chartered Cyber Security Professional MBCS ISO 27001 Lead Auditor BSI-qualified Lead Auditors NCSC engaged
The pattern we see

Across sectors, AI adoption follows a consistent shape. Capable people find real value before the organisation can explain the risks, the owners or the limits. People across functions each hold a piece of the diagnosis; what is missing is ownership and a defensible footing under activity already in flight.

Your organisation does not lack AI ideas. It lacks structure.

Common questions

What boards ask us first

We already have an AI policy. Is that enough?
Usually not on its own. A policy establishes intent. Defensibility requires a register of what is actually in use, named owners, controls that operate, and a gate that new tools pass through. We frequently find good policies sitting above ungoverned activity.
How is this different from a cyber security assessment?
A cyber assessment tells you whether your controls hold. An AI governance assessment tells you whether your use of AI can be explained and defended — to a client, an insurer or a regulator. The two are related, which is why we do both, and why we will tell you if your cyber baseline needs closing before AI governance can mean anything.
Do we need ISO/IEC 42001 or ISO 27001 certification?
Sometimes. Often not. Certification carries real overhead and is worth it when clients or regulators require it. Where they do not, the same policy machinery can be bolted onto an existing ISO 9001 or 14001 business management system for a fraction of the cost. We will tell you honestly which applies to you.
Will you recommend your own services?
Only where specialist depth genuinely warrants it. Every recommendation carries an internal owner wherever one exists, because governance has to live in your organisation to last. Our discovery reports routinely name the client's existing advisers — legal, insurance, managed-services partner — as the right route for work that is not ours.
How quickly can you start?
The one-hour briefing can usually be arranged within days. The AI Defensibility Review runs to about two weeks. The fuller Readiness Discovery mobilises within one to two weeks of sign-off and runs over three to four elapsed weeks.
Do you implement the AI tools as well?
Governance work and implementation work are kept deliberately separate, so that our advice on what to adopt is not advice about what to buy from us. Once the footing is in place, we place experienced AI delivery specialists alongside your teams through our Intelligent Automation and Cloud Security & Software Engineering practices.
Our other services

How this practice connects to the rest

AI governance is the discipline that lets our other capabilities be deployed without creating exposure. Most engagements draw on more than one.

The next step

One hour with your board or leadership team

We will map the AI activity already visible in your organisation against the four questions — advantage, risk, control and ownership — and show what a full AI Defensibility Review would uncover.

Arrange the briefing

No preparation required. No obligation to proceed.