Skip to content
4th Turning Strategy

AI Governance & Risk

Move fast on AI without betting the company.

Policies, controls and board oversight sized for your business — governance that enables speed instead of blocking it.

Your people are already using AI, with or without a policy. The question is not whether to allow it. It's whether that usage happens inside guardrails you designed, or in a shadow layer you can't see.

Good governance is an accelerant. When teams know what's allowed, what's logged and who decides the edge cases, they move faster — because every decision no longer has to escalate to you. We build governance sized for SMEs and smaller enterprises: a working policy, proportionate controls, and board oversight that fits in an hour a quarter rather than an enterprise bureaucracy transplanted into a 200-person company.

The rules around AI are being rewritten in real time — the EU AI Act is taking effect in stages, customers are asking harder questions, and insurers are updating their exclusions. Preparation is cheaper than reaction. It usually is.

Who this is for

  • Boards and CEOs who have approved AI spending and now need oversight that matches it.
  • Leaders in regulated or trust-sensitive sectors — finance, health, legal, government suppliers — where one incident costs more than years of efficiency gains.
  • CTOs and compliance leads who have been asked to write the AI policy and want more than a downloaded template.

What we do

What you get.

AI usage policy

A practical policy covering approved tools, data handling, disclosure and human review — short enough that people read it, specific enough to hold when tested.

Risk assessment and register

Your AI use cases — including the undeclared ones — mapped against operational, legal, security and reputational risk, with proportionate mitigations for each.

Controls and approval pathways

Lightweight processes for adopting new tools and use cases, with clear thresholds for what needs sign-off and what doesn't.

Board oversight pack

A reporting template and briefing that gives directors a defensible view of AI risk in an hour a quarter.

How it works

The engagement, step by step.

  1. 01

    Discovery call

    A short conversation about your current AI exposure, your regulatory context and what's prompting the question now — an incident, an audit, or a board that's started asking.

  2. 02

    Risk and usage audit

    We survey actual AI usage across your organization — sanctioned and not — and assess it against your legal, contractual and sector obligations.

  3. 03

    Framework delivery

    We draft the policy, controls and board pack, pressure-test them with your leadership team, and adjust until they fit how your business actually runs.

  4. 04

    Annual review (optional)

    A retained yearly cycle to keep the framework current as regulation, tooling and your own AI footprint change.

Outcomes

What changes for you.

  • A written, board-approved AI policy your staff have read and can follow.
  • A risk register that covers real usage, including the tools nobody declared.
  • Faster adoption decisions, because the approval path is defined in advance.
  • Evidence of governance you can show customers, insurers, auditors and regulators.

Questions

Asked often, answered honestly.

Who is this for?

Boards and leadership teams of SMEs and smaller enterprises who are adopting AI faster than their controls are maturing — especially in regulated or trust-sensitive sectors. If you have no AI usage at all yet, you probably don't need this. Few organizations are in that position.

Do you cover the EU AI Act?

Yes. We map your use cases against the Act's risk tiers and obligations, alongside whatever applies in your home jurisdictions. We're strategists, not lawyers — where formal legal opinions are needed, we work alongside your counsel rather than replacing them.

How long does it take?

Three to five weeks from the start of the audit to a board-ready framework. If you're working to a deadline — a customer audit, an insurance renewal, a tender — tell us and we'll sequence around it.

What do you need from us to start?

An honest picture of current AI usage, copies of the relevant contracts and policies, and an hour with the executive who owns risk. The audit takes care of the rest.

Related thinking

From the Insights desk.

Every turning rewards the prepared.

Tell us where you are. We will be candid about what comes next — whether or not we end up working together.