AI moved from pilot to production faster than the oversight around it. IrisInfosec gives you that oversight: an inventory of where AI is used, a clear risk classification under the EU AI Act, and an AI management system to ISO 42001 and the NIST AI RMF. The result is responsible AI you can evidence to a board and a regulator.
Most organisations are already using more AI than they have governed, often through vendor features and generative tools no one formally approved. The work is to find it, classify it, and put proportionate oversight around it before a regulator or an incident does the finding for you.
This is governance of the AI you build and the AI you buy. It is about overseeing AI responsibly, not badging a product with it, and it sits naturally beside your privacy and security programmes.
AI governance and responsible AI
is the inventory, risk classification, management system and oversight that let you develop and use AI lawfully and accountably, aligned to the EU AI Act, ISO 42001 and the NIST AI RMF.
What we build
The components of a governance programme that an auditor, a board and a regulator
can all follow.
A register of every AI system in use, built and bought, with owner, purpose and data, so nothing governs in the dark.
Classify each system into the right tier and define the obligations that follow, from transparency to conformity assessment.
A certifiable management system that governs how AI is developed, procured and operated across the organisation.
Controls over training data, model changes, evaluation and documentation, so decisions can be explained later.
Disclosure where the Act requires it, and human-in-the-loop controls proportionate to each system’s risk.
Map your programme to the NIST AI Risk Management Framework for a common language across EU and US stakeholders.
Where governance starts
Obligations follow risk. Knowing which tier each system sits in is the first decision, and
the one everything else depends on.
| Tier | What It Means | What It Requires |
|---|---|---|
| Unacceptable | A short list of prohibited uses | Not permitted on the EU market |
| High-risk | Sensitive uses such as employment or credit | Risk management, data governance, oversight, conformity assessment |
| Limited risk | Systems that interact with people | Transparency, so users know they are dealing with AI |
| Minimal risk | The majority of everyday AI | Voluntary codes of practice |
How we work
A measured approach that fits how your teams actually adopt AI.
Find every AI system in use, built and bought, and record purpose, owner and data.
Place each system in its EU AI Act tier and confirm the obligations that apply.
Stand up the management system, policies and controls proportionate to each tier.
Produce the technical documentation, assessments and disclosures the Act expects.
Ongoing oversight of models, vendors and new use cases as your adoption grows.
What you receive
The register, the management system and the documentation a board, an auditor and a
regulator can all follow.
A maintained register of AI systems with their tier, owner and the obligations attached to each.
The ISO 42001 policies, roles and processes to govern AI across its lifecycle, ready for certification.
Technical documentation, impact assessments and disclosures for your high-risk and customer-facing systems.
Know your AI before a regulator asks
Tell us where AI shows up in your products and operations. We will inventory it, classify
it under the EU AI Act, and send a prioritised plan.
Questions, answered
Related services