Your AI brought under control, with the controls actually switched on.
We make the AI tools you already pay for safe to run on real data: DLP and sensitivity labels set properly, shadow AI and unmanaged devices shut out, and a policy that says who can do what. Much of what passes for AI governance is documentation that is never enforced. We configure the technical controls and write policy to match them.
We govern AI against the regulations that apply to you, and demonstrate compliance with evidence rather than assertion.
UK DPA and GDPR, EU equivalents, FCA and PRA, HIPAA.
We hold every client to the standard a regulated one would demand, whether you answer to a regulator or just want it done properly. So we already work to the regimes that govern the most exacting clients: UK data protection and GDPR, the EU and other overseas equivalents, the financial rules under the FCA and PRA, and the health and HIPAA obligations where the data is clinical. The controls and the policy are built around the obligations that bind you, not a generic template that satisfies none of them.
The AI governance controls we configure, and the gap each one closes.
Shadow AI nobody signed off.
Staff are pasting client work into free, unapproved chatbots, and browser extensions can read their mailboxes. You cannot govern a tool you do not know is in use.
What we put in place
- The unsanctioned tools blocked, and a sanctioned one put in their place that is actually worth using.
- A clear record of which AI is approved, so the answer is on a page rather than in someone's head.
Sensitive data walking out the door.
Personal records, client files and regulated material fed into a model whose retention and training terms you never see. Once it has left, you cannot pull it back, and the regulator holds you responsible for not having prevented it.
What we put in place
- Sensitivity labels in Microsoft Purview, so the data carries its own classification wherever it goes.
- DLP rules that prevent a labelled file from reaching an unapproved model.
Company data on devices you do not control.
Someone signs into an AI tool from a home laptop or a personal phone, and your data is suddenly on a machine you cannot manage, patch or wipe. A control applied everywhere else, but routinely overlooked for AI.
What we put in place
- Conditional access that lets AI reach company data only from a managed, compliant device.
- Unmanaged and personal devices blocked by policy, not left to discretion.
The on-premises file server left out of scope.
Governance work tends to stop at the cloud, while years of sensitive material sit in shares on a Windows Server with permissions nobody has reviewed since it was built. AI will read any source it is given access to, including those shares.
What we put in place
- Information protection extended to your on-premises Windows Server shares, not just the tenant.
- Stale and over-broad permissions cleaned up before any AI is let near the data.
The policy we write to back the controls.
Controls without policy are easily circumvented, so we write the policy alongside them. There are four documents. Acceptable use tells your people which tool they can use, and on which data. Data classification draws the line between what can go to an AI and what cannot, mapped to the same sensitivity labels the controls enforce.
Vendor approval gives procurement a straight way to judge any product that has quietly grown an AI feature, before it is signed. Incident response covers the cases your current plan does not: a prompt that returned another party's data, or an output that disclosed information it should not have. Each one is written to leave a record you can show.
Where a regulator already governs you, the policy is written to read cleanly to them. It covers the FCA and PRA for financial firms, the health and HIPAA rules where the data is clinical, and your data-protection duties under UK and EU law throughout. One set of documents, ready for the auditors and regulators who can request them.
What ends up in your policy library
-
An acceptable-use policy people will actually followWhich tool, on which data, set out so the rule is clear at the point of use.
-
A data-classification scheme tied to your labelsThe same sensitivity labels the controls enforce, so the rule and the technology say the same thing.
-
A way to vet any vendor that adds AIA straight check procurement can run before signing a product that has grown an AI feature.
-
An incident plan for when AI goes wrongThe model-specific cases your existing playbook does not cover, with the reporting duties spelled out.
Where clients typically start, and what they receive.
A clear view of what AI is already doing in the business.
When you suspect people are using AI but cannot say how, we start by establishing visibility. You get a plain picture of which tools, which teams and which kinds of data are in play, then a sanctioned route worth using so staff no longer need the unapproved tool.
An approval a team can rely on, built around your regulator's expectations.
When a team wants to put AI into client-facing work, you want a way to approve it safely rather than refuse it outright. We check what your regulator actually expects, then set the review step and the records around it, so the tool is used with the controls already in place, before any incident occurs.
A clear answer on whether a vendor's AI is safe to procure.
When a supplier turns up with an AI feature, your procurement team faces a question outside its remit. We give them a clear way to weigh it, with the data-protection side handled in the same pass, so the contract review and the privacy review move together instead of one after the other.
Start with a review of where your AI stands.
A senior engineer reviews your current AI use in full.
We look at what AI is in use with and without sign-off, how ready your Microsoft tenant and your servers are to govern it, where your policy stands against the obligations you carry, and what you could show a regulator on request.
- Scope
- Agreed with you on the first call, against your environment and the regulators you report to.
- Deliverables
- A written report, draft policy where agreed, and a prioritised plan you can act on.
- Continuity
- The engineer who reads your setup can stay on it, whether you want a named engineer, the work fully managed, or a fixed-fee project to turn the controls on.
AI governance and security governance belong together. Factor1's vCISO covers policy, risk and audit.
AI governance is one piece. We look after the whole.
Under one agreement, the estate is watched, maintained and documented as a single thing, by the team behind this page.
…and everything between.
Tell us where AI sits in your business today.
Who regulates you, which AI tools are in use, sanctioned or not, and what the board, the auditor or the insurer has started to ask. We will tell you what we would address first and how we would approach the work.
