AI you can put in front of your board, your auditor and your regulator.Documentation produced during the build, not after the question.
Compliance documentation is produced as part of the build, not reconstructed afterwards when somebody asks. Every engagement ships with a data map, a DPIA and a named accountable owner — before the system processes anything real. This page is the whole governance position in one place: trust, data residency, public sector procurement, EU AI Act alignment and the work we decline.
Six things in every engagement.
Not optional extras, and not priced separately. If we cannot deliver these for a piece of work, we do not take the work.
Data mapping before build
We map personal data flows, processing locations, retention and access control before writing code. Minimisation is applied at the schema, not asserted in a policy — if a field is not needed for the task, it does not enter the index.
DPIA before deployment
Produced for any workflow touching personal data, and written to be read by your DPO and your auditor rather than filed. Residual risk is stated plainly, including where we think it sits too high to proceed.
The line we do not cross
No solely automated decision producing legal or similarly significant effects on a person. We build the evidence-gathering that gets a qualified human to the decision faster, and the audit trail that shows they made it.
NCSC and DSIT aligned
Built against the NCSC Guidelines for Secure AI System Development and the DSIT AI Cyber Security Code of Practice — model and dependency provenance, supply-chain controls, prompt-injection and data-poisoning threat modelling, and secrets handling that assumes the model is hostile.
A name and a monthly report
One named individual owns each workflow and answers governance questions directly. Monthly reporting covers data processed, exceptions flagged, model behaviour changes and advance notice of anything about to change.
SOC 2 aligned, not certified
Controls are designed against the SOC 2 Trust Services Criteria. We are not SOC 2 certified, and we will not imply that we are. If certification is a hard procurement requirement, tell us early and we will say plainly whether we can meet it.
Where your data lives.
Default recommendation: UK residency with UK sovereignty. For regulated sectors we analyse extraterritorial jurisdiction exposure, because where the processor is incorporated can matter as much as where the disk sits.
- UK data centres by default, for every workflow
- UK-incorporated processors, governed by English law
- Non-UK hosting named explicitly and consented in writing, never assumed
- On-premise, private tenancy or fully air-gapped — your choice, evidenced
- Model weights and corpus never leave the approved boundary
- Sub-processor list maintained and provided on request
- Extraterritorial jurisdiction analysis for regulated sectors
- Data residency stated in the DPIA, not just in a sales conversation
Procurement and tendering.
We work to the standards public bodies are required to evidence, and we will tell you before you spend time on a bid if we cannot meet a mandatory criterion.
- G-Cloud and public sector procurement standards
- UK cross-sector AI principles — safety, transparency, fairness, accountability, contestability
- ICO AI and data protection risk toolkit applied during design
- DPIA and data map supplied as tender evidence, not written afterwards
- Named accountable owner mapped to your governance structure
- Algorithmic transparency information available where the standard applies
- Written statement of what the system will not decide
- Honest early answer where a mandatory criterion cannot be met
Where the Act actually stands.
Dated, and verified as at September 2026. This area moves — the high-risk deadlines shifted in July 2026 and a good deal of published guidance is now out of date.
Scope turns on role, not sector. Provider and deployer carry materially different obligations, and a UK organisation is in scope wherever a system is placed on the EU market or its output is used in the Union. We classify the role first, in writing, because every other obligation follows from it.
The deadline moved. The design requirement did not. A system built in 2026 without logging, traceability, human oversight and technical documentation will not spontaneously acquire them in December 2027. We build to the high-risk standard now, because retrofitting an audit trail into a system that was never designed to keep one is the single most expensive thing we get asked to do.
What we won't build.
The shortest conversation we have, and the least negotiable. Each of these is a decision a regulator would expect a named human to have made, with reasoning they can inspect.
Anything a regulator expects a person to decide
Credit and affordability, benefits eligibility, clinical judgement, safeguarding, admissions. We build the evidence-gathering that gets a person to the decision faster. We don't build the decision.
Citable output that reaches a client unverified
Fabricated authorities have been put in front of judges by practitioners relying on AI. Anything citable is checked against source by a qualified person before it leaves the building — enforced in the workflow, not left to discipline.
Probabilistic checks that need to be exact
Conflict searches, sanctions screening, duplicate detection. A fuzzy match that quietly misses is worse than no system, because it manufactures confidence you haven't earned.
Anything we can't explain after the fact
If a system can't show which inputs drove an output and who signed it off, it will not survive an audit, a complaint or a tribunal. Every build we ship logs its reasoning — because the question always arrives eventually, and usually at the worst moment.
Special category data through third-party tools
Not without an explicit DPIA, a documented lawful basis and DPO approval. If those are not in place, the answer is no until they are.
Common questions.
Does the EU AI Act apply to us if we are a UK business?
+
Often, yes. The Act reaches any organisation placing an AI system on the EU market or whose system output is used in the Union, regardless of where the organisation is established. What matters most is your role — provider and deployer carry materially different obligations, and we classify that in writing before design begins.
Are you SOC 2 certified?
+
No. Our controls are designed against the SOC 2 Trust Services Criteria, but we hold no certification and we will not imply otherwise. If certification is a hard requirement in your procurement, say so at the first call and we will tell you honestly whether to proceed.
Can you complete our security questionnaire?
+
Yes, and we would rather do it early than late. The data map, DPIA and sub-processor list exist as build artefacts, so most questionnaires are a matter of transcription rather than a scramble.
What happens if a regulator asks how a decision was made?
+
Every build logs its reasoning — which inputs drove an output, which sources were retrieved, and who signed it off. That is why we build to the high-risk standard whether or not a system is classified as high-risk: retrofitting an audit trail is the most expensive thing we get asked to do.
We can help.
Tell us what's hard, expensive, or taking too long — and we will help you identify, optimise and deploy AI for innovation, efficiency and growth.