AI governance

Give your people an approved way to use AI on real work.

Tier 1 finds the AI already in use, approves suitable tools and tasks, sets information boundaries, reviews suppliers and keeps a qualified person accountable for consequential output. GRC and cybersecurity stay connected wherever the use requires them.

Most firms do not need certification to start. Begin with the tools, information and decisions already in scope.

Scroll to explore
02Tier 1

Section 02

See the use before writing the policy.

AI can enter a firm through public tools, approved subscriptions and features built into existing software. Client material may then be processed under terms the firm has not assessed, while output can be wrong and still sound convincing. Governance starts by making that use visible.

A glowing glass form contained within frosted screens in a dark room.
03Tier 1

Section 03

What an AI governance baseline gives your firm

The goal is safe, useful adoption with named accountability, not a large policy exercise. The baseline creates a working decision system the firm can keep using.

AI tool and use-case register

Record approved, trial and prohibited tools, their purpose, users, business owner and information.

Data-handling rules

Define what may and may not enter each tool, including client, personal, privileged and security information.

Risk and approval path

Classify uses by consequence and make the required review, authority and exception path clear.

Supplier assessment

Assess terms, locations, retention, training use, subcontractors, deletion, incidents and administration.

Human oversight

Define which output needs checking, who is qualified and what evidence should be retained.

Training and review

Teach the line with relevant examples, make mistakes reportable and revisit a use when material details change.

04AIUC-1 readiness

AIUC-1 readiness

Prepare agentic AI for independent assurance

When an AI system can access sensitive data, call tools or take actions, ordinary acceptable-use rules are not enough. AIUC-1 examines agent-specific safeguards across Data & Privacy, Security, Safety, Reliability, Accountability and Society.

Tier 1 helps prepare the scope, remediate gaps and organise evidence before formal assessment. Tier 1 does not issue the AIUC-1 certificate or replace the accredited auditor and independent technical-testing process.

Define the boundary

Identify the agents, capabilities, environments, data, tools, suppliers and owners that may need to enter formal scope.

Map readiness

Compare existing governance, security and operating evidence with the current requirements likely to apply.

Remediate the gaps

Coordinate policy, access, supplier, monitoring, testing and response improvements with technical and professional advisers.

Prepare the evidence

Build a traceable evidence set and resolve readiness gaps before engagement with AIUC and an accredited auditor.

05Tier 1

Section 05

Move from unknown use to governed use

The work can begin as a focused baseline and grow only where the firm's use and obligations require it. The immediate aim is to give staff a safe route to use useful tools and a clear way to ask before crossing the line.

Discover

Speak with the people doing the work and record existing tools, experiments, embedded features and intended use cases.

Decide

Classify uses, approve suitable tools and set the information, review and recordkeeping rules that apply to each category.

Enable

Train staff with relevant examples, publish a simple approval path and make reporting a mistake easier than hiding it.

Review

Recheck approved tools, exceptions and higher-risk uses when suppliers, terms, models or business processes change.

06Tier 1

Section 06

Built for firms where confidentiality is part of the service

AI governance must fit professional duties, client commitments and the way people actually deliver work. Tier 1 coordinates the security and control work while legal, privacy and other specialist advisers remain responsible for advice in their fields.

Law firms

Set boundaries around privileged matters, client instructions, legal research, drafting and qualified human review.

Boutique consultancies

Protect client intellectual property, investigation material, commercial advice and contract-specific restrictions.

Family offices

Keep private information and adviser workflows within approved tools, access paths and review arrangements.

07Tier 1

Section 07

Use ISO 42001 where the business case is clear

Most small firms do not need certification to begin. ISO 42001 becomes useful when clients, tenders, higher-risk systems or strategic goals require a formal AI management system and repeatable assurance.

Readiness

Compare current ownership, policy, risk, supplier and monitoring practices with the management-system requirements.

Implementation

Build the governance, objectives, risk treatment, operating controls and evidence into the way the firm works.

Assurance

Prepare internal review, leadership oversight and audit evidence without claiming that paperwork alone controls AI risk.

08Questions

Straight answers

Common questions

Do we need to ban public AI tools?

Not necessarily. A practical starting point is to identify real use, decide which information cannot enter a tool and approve suitable services for defined tasks. Some uses may need to remain prohibited when the confidentiality or reliability risk cannot be controlled.

Is a paid or enterprise AI account automatically safe?

No. Contract terms, data use, retention, location, access controls, deletion and administration still need review. The right answer depends on the tool, configuration, information and proposed use.

Do we need ISO 42001 certification?

Most small firms do not need certification to begin governing AI. An inventory, data rules, supplier checks, human review and named ownership usually come first. Formal alignment becomes more useful when clients, tenders, higher-risk systems or strategy justify it.

Can our legal, privacy and IT advisers be involved?

Yes. AI governance crosses contractual, privacy, security, technology and professional duties. Tier 1 can coordinate the control work while the appropriate adviser remains responsible for advice in their field.

Can Tier 1 certify us against AIUC-1?

No. Tier 1 provides AIUC-1 readiness and remediation support, including scope preparation, gap assessment, control implementation and evidence organisation. Only AIUC can issue the certificate through its accredited audit and technical-testing process.

A quiet first step

Bring the issue already on your desk

Tell Michael what changed, who is asking and when a decision is needed. The first conversation will identify whether Tier 1 fits and the smallest responsible next step.

Book a confidential first call