AI use and governance review
The first conversation is free. Scope and price are agreed in writing before work starts.
Employees already use AI, but the approved tools, permitted data and review responsibilities are unclear. We build an inventory from surveys, interviews and available records, then prepare a risk register, acceptable-use rules and an approval process. We state the coverage and what remains unknown.
For a question about employee use, read what to document for ChatGPT and customer data, including the decision sheet and a fictional redaction example.
For whom
Organisations where staff already use AI tools — approved or not — on business or personal data.
Typical trigger: A leak or a prevented incident, a customer question about AI use, a policy request from management, or preparation for the AI Act’s transparency and literacy duties.
What you receive
- Inventory of AI use (survey, interviews, records)
- Acceptable-use rules, approval process and risk register
- AI governance rules, responsibilities and disclosures appropriate to each use
| Task | Data involved | Owner | Review needed |
|---|---|---|---|
| Drafting client e-mails | Business contact data | Sales lead | Acceptable-use rule; no special-category data |
| Summarising supplier contracts | Confidential commercial terms | Legal | Approved tool only; check the contractual and technical conditions for data retention |
| Shortlisting job applicants | Personal data of candidates | HR | Legal assessment before use — check against the AI Act’s listed high-risk uses |
What the price includes
- 1 legal entity
- Up to 5 AI systems or tools inventoried
- Up to 100 staff in the shadow-AI survey
Timeline and your input
A management sponsor, access to staff for a short survey and interviews, and the records you hold (licences, tickets, logs). Coverage depends on these sources; we state what was checked. Typical timeline 3–4 weeks.
Starting price
from €5 900. Base-scope price. The exact price is fixed in writing before work starts. It changes only when the agreed number of entities, systems, domains, contracts, documents, interviews, languages or depth of review falls outside the base scope. No additional work is charged without prior agreement. Scope and prices.
Beyond that scope · detailed terms
- +€700 per additional AI system
- +€1 400 per system requiring high-risk classification work (instead of, not in addition to, the +€700)
A “system” is a tool together with a specific use of it; we agree what counts before quoting. A high-risk use among the base five is not re-charged automatically — the additional analysis is scoped and quoted separately. This is not the price of full high-risk compliance for a system.
Agreed separately
Legal classification of specific high-risk uses beyond the extras listed; technical controls; training programmes.
What you prepare after we agree scope: known AI tools and uses, and a contact for the interviews. A brief description is enough for the first conversation. Do not send passwords or health information through the form. Documents and technical information needed for the agreed work are exchanged through a secure channel arranged in advance.
We prepare the agreed materials and document the scope, findings and limitations. Decisions by regulators, auditors or clients remain theirs to make.
Specimens and preparation for commissioning
These specimens and worksheets show how outputs, your participation and acceptance are recorded. Specific terms are completed and agreed for the engagement.