PRIVINOTCH  /  Focus areas  /  Baseline Responsible AI Programme

A responsible AI baseline in eight weeks

A structured programme that takes you from scattered AI use to a documented, board-ready governance framework, tested on a real use case and aligned to the standards and regulations that matter to you.

Defined timetable. Two jurisdictions of your choice as standard. Not sure where you stand? Start with our free AI governance health check.

The programme

Four phases, eight weeks

A fixed shape that keeps the work moving, with one review cycle on each deliverable.

Weeks 1 to 2

Assess

Stakeholder interviews, an AI use-case and tooling inventory, a review of the AI regulations that apply in your chosen jurisdictions, maturity scoring against ISO/IEC 42001 and NIST AI RMF, and a gap analysis.

Week 3

Design

AI risk register and risk methodology, third-party and vendor AI risk process, and a RACI for ownership and accountability.

Weeks 4 to 5

Align

Alignment to the AI regulations that apply in your selected jurisdictions, a cross-walk to NIST AI RMF and OECD AI Principles, and a suite of appropriate AI policies, with updates to related policies such as privacy and information security.

Weeks 6 to 8

Implement

A consolidated Responsible AI Framework tested on one live use case, a board summary and roadmap, and playback and handover.

What you receive

Deliverables you can put to use

01

AI inventory, maturity and jurisdiction review

A clear picture of the AI you use, how mature your governance is, and which AI regulations apply in your chosen jurisdictions.

02

Gap analysis and roadmap

Prioritised gaps with practical recommendations and a sequenced plan.

03

AI risk register and methodology

A proportionate way to identify, rate and treat AI risk, set up and populated with your priority systems.

04

Third-party AI risk process

A repeatable approach to assessing suppliers and foundation-model providers.

05

AI policy suite and regulatory alignment

A suite of appropriate AI policies, with consequential updates to related policies such as privacy and information security, aligned to the AI regulations in your selected jurisdictions and cross-walked to NIST AI RMF and OECD AI Principles.

06

Responsible AI Framework, tested

A consolidated framework piloted on one live use case, including explainability and human-oversight checks.

Optional extras

Build on the baseline

Tooling configuration

Configure the GRC or AI governance platform you already use to hold your register, workflows and evidence.

AI governance as a service

Keep the framework working without hiring a full-time team. On a retainer basis we act as your fractional AI governance function: maintaining your AI register and risk assessments, reviewing new use cases and suppliers, tracking regulatory change and reporting to leadership.

AI ambition and strategy session

A facilitated session to align leadership on where AI should create value, and the guardrails needed.

Who it is for

Who this is good for

Organisations that use or build AI and need a defensible, practical foundation.

  • You use or build AI but have no consistent governance
  • A customer, investor or regulator is starting to ask questions
  • You need a defensible baseline before scaling AI
  • Your board wants to understand AI risk and sign off a clear position
  • You operate, or plan to operate, in more than one jurisdiction
  • Staff are already using generative AI tools and you want sensible guardrails
  • Enterprise buyers are sending AI governance questionnaires
  • You are preparing for a funding round, an acquisition or investor due diligence
  • You want a foundation for ISO/IEC 42001 or EU AI Act readiness
  • You have a privacy or security lead who needs AI added to their remit
Questions

Frequently asked

Is it a fixed price?
We do not publish pricing. We scope the programme to your size, jurisdictions and the live use case, and provide a clear proposal once we understand your context.
Which jurisdictions can be covered?
We work globally. As standard the programme covers two jurisdictions of your choosing, for example the UK and the EU, or the UK and the UAE. Additional jurisdictions can be added for an additional cost.
Does it replace the free health check?
No. The free AI governance health check is the easiest way to start. It gives you an initial view of where you stand and helps us scope the programme properly if you want to go further.
Do you implement tooling?
The core programme is advisory. If you use a GRC or AI governance platform, we can scope configuration support as an optional add-on, and we work with the platforms you already have.
What happens after eight weeks?
You have a framework, a risk method, policy updates, a tested live use case and a board-ready roadmap. Many clients continue with implementation support or a retainer, but that is entirely optional.
Talk to us

Request a scoped proposal

Tell us about your organisation, your AI use and the jurisdictions involved, and we will propose a scope.

  • Scoped to your size and jurisdictions
  • Clear deliverables and timetable
  • Start with the free health check if you prefer

Prefer to talk it through? Book an intro call or email info@privinotch.co.uk.

We use your details to reply to you. See our Privacy Notice.