Responsible AI Statement
Last updated: September 2026 · Sets out the principles that guide how we advise on AI, and how we use it ourselves
Responsible AI sits at the heart of what we do, not as a marketing line, but as the standard we hold our own advice and our own practice to. This statement sets out the principles behind that, and how we put them into practice.
1. Our approach to responsible AI
PRIVINOTCH is a privacy, AI governance and strategic advisory consultancy. We help organisations adopt AI responsibly, securely, ethically and effectively, through governance, risk management, compliance and practical implementation support.
We ask our clients to hold their AI to a clear set of principles, so we hold ourselves to the same ones, in the advice we give and in how we work day to day. This statement sets those principles out, together with the practical measures behind them.
2. Our Responsible AI & Innovation Principles
Seven commitments underpin our approach to AI, whether we're advising a client or making decisions in our own business:
01Ethical Innovation
We encourage innovation that delivers long-term social and environmental value.
02Responsibility
Responsibility for AI outcomes must be clear and measurable.
03Privacy & Data Stewardship
We protect individuals' data rights by embedding privacy by design. Responsible innovation depends on responsible data.
04Fairness & Non-Discrimination
AI should perform equitably across demographics and contexts. We actively identify and mitigate bias in data, design and decision-making to promote fairness and inclusion.
05Human-Centred Design
AI systems must be designed to serve people, enhancing human capability, inclusion and wellbeing.
06Safety & Reliability
AI systems must be robust, secure and thoroughly tested to prevent unintended harm.
07Transparency & Explainability
We promote clarity in how AI systems function, how decisions are made, and what their limitations are.
3. How we apply this in our advisory work
These principles shape the recommendations we make, not just the language we use. In practice, that means:
- Responsibility. We recommend governance structures where a named person, not just a policy document, is accountable for an AI system's outcomes.
- Human-Centred Design. Where an AI system materially affects someone's outcome, we advise on keeping a human meaningfully in the loop, rather than a fully automated decision.
- Fairness & Non-Discrimination. We build bias and equity testing into the risk and impact assessments we carry out for clients.
- Transparency & Explainability. We help clients document how their AI systems work, what they were tested against, and where their limitations lie, in a form that stands up to internal and external scrutiny.
- Privacy & Data Stewardship. Our assessments and frameworks embed privacy by design, aligned with our own data protection obligations under UK GDPR.
We scope every engagement to strengthen the governance, policies and safeguards you already have, rather than bolt on a parallel structure you'd have to maintain twice.
4. How we use AI in our own practice
Like most consultancies, we use AI tools ourselves: for research, drafting and administrative work. Where we do, we apply the same principles set out in this statement:
- A person reviews and takes responsibility for any AI-assisted output before it reaches a client.
- We don't put client-identifying or confidential information into general-purpose AI tools without an appropriate lawful basis and safeguards in place.
- We don't use AI to make autonomous decisions about our clients or their people, or to substitute for the professional judgement behind our advice. That judgement remains ours.
- We keep this practice under review as our tools, and the underlying models, change.
5. Data privacy & security
How we collect, use and protect personal data, including data processed in the course of an AI-related engagement, is set out in full in our Privacy Notice. In brief: we only collect the data we need, we don't use personal data for automated decision-making or profiling, and where we process personal data on a client's behalf we do so strictly as instructed and under contract, as their processor rather than as controller.
For the full detail on what we collect, why, and your rights, see our Privacy Notice.
6. Alignment with recognised standards
Our advisory work is grounded in recognised standards and frameworks, including ISO/IEC 42001, the NIST AI Risk Management Framework, the EU AI Act, and applicable UK guidance. Requirements vary by jurisdiction and sector, and part of our job is helping each client work out which of these actually apply to them, rather than assuming a one-size-fits-all answer.
We keep our own approach under review as this regulatory landscape develops across the regions we work in.
7. An ongoing commitment
Responsible AI isn't a one-off exercise or a fixed checklist. As AI systems, regulation and our own practice evolve, we'll keep reviewing and strengthening the principles and practices set out in this statement.
8. Contact us
If you'd like to know more about how we approach responsible AI, in our advisory work or in our own practice, contact us at info@privinotch.co.uk. Our offices are in London, UK and Dubai, UAE.