Skip to content

AI governance

Use AI safely, with rules people can follow.

We write the AI policies, set up the security controls and line everything up with your regulatory obligations, so AI is used responsibly and can be audited. That covers acceptable use and accountability, plus encryption, access controls and monitoring in your Microsoft tenant.

What we do

Governance from policy to technical controls.

A policy on its own does not stop sensitive data ending up in the wrong place. We cover the written rules and the settings in Microsoft 365 and Azure that back them up.

Microsoft Purview

Sensitivity labels, data loss prevention and retention policies that apply to AI as well as people.

Microsoft Purview

Data governance

Policies for classifying and handling data, with owners and review dates agreed.

Data governance

Data security

Access controls, encryption and monitoring set up and checked across your tenant.

Data security service

Copilot readiness

A review of permissions and content before Copilot starts answering from it.

Copilot readiness assessment

SharePoint governance

Ownership, permissions and lifecycle rules for SharePoint, where much of the content AI reads lives.

SharePoint governance

AI strategy

A plan for AI adoption with governance built in from the start rather than added later.

AI strategy

2 hours

for our Copilot readiness workshop, covering data and security first

20+ years

of SharePoint and Microsoft experience behind the team

1 working day

to hear back from us after you get in touch

How we work

How an AI governance project runs.

01

Discovery

Workshops to understand how AI is used today, the data involved, and the regulations and internal standards you need to meet.
02

Design

A governance framework covering acceptable use, data handling and accountability, alongside the security controls needed to support it.
03

Build

We configure encryption, access controls, labels and monitoring in your environment and write up the policies ready for approval.
04

Train

Training and documentation for the people who own the policies and the staff using AI day to day.
05

Go live

We test the controls with your team, refine anything that gets in the way and support the rollout.

Case studies

Case studies we have delivered.

Governed content on modern SharePoint

Shelter moved from a 2016 SharePoint intranet to modern SharePoint, mostly out of the box, with retention labels and policies keeping content governed.

Read the Shelter case study

Simpler permissions after a file server move

Praxis moved from a file server to Teams and SharePoint, with data cleansed and reorganised and simpler permissions for a hybrid workforce.

Read the Praxis case study

FAQ

Frequently asked questions.

What does an AI governance framework include?

Acceptable use, data handling and accountability measures, backed by technical safeguards such as encryption, access controls and monitoring.

Can you help us meet regulatory requirements?

Yes. We align your AI solutions with the regulations that apply to you and with your internal standards, so they are ethical, secure and auditable.

Do we need this before rolling out Copilot?

It helps a lot. Copilot answers from whatever a user can already reach, so getting permissions and labelling right first stops it surfacing content people should not see.

Do you just write policies?

No. We write the policies and configure the controls in your tenant that enforce them.

Talk to our AI governance team.

Tell us what you are working on and we will come back to you within one working day to arrange a call.