Governance

AI governance consulting: what an engagement actually contains

Digiton runs AI governance consulting for enterprises in Europe: an inventory of every model in production, a risk classification, the controls, and the evidence a regulator asks for.

What does AI governance consulting deliver? An inventory of every AI system already running, a risk classification against Regulation (EU) 2024/1689, the controls that follow from it (human oversight, logging, approval gates, an incident path), and an evidence pack a supervisor or an audit committee can read. Digiton builds those controls into the system rather than beside it, and average deployment is 45 days.

By Brandon Da Costa, Founder, Digiton Dynamics. Reviewed 8 September 2026.

What an AI governance engagement contains

Governance work goes wrong in one of two directions. Either it produces a policy document nobody in engineering has read, or it stops a deployment that was never risky in the first place. The engagement below is built to avoid both. Average deployment is 45 days, and governance work runs inside that window rather than beside it.

Week one, the inventory. Every AI system already running in the business, named, with an owner, a purpose, the data it reads and the decision it touches. Most enterprises find between two and five times more than the AI programme knows about, because the finance team bought a tool and the support team turned on a feature. You cannot classify a system you have not written down.

Week two, the classification. Each system is placed against the risk tiers in Regulation (EU) 2024/1689: prohibited under Article 5, high-risk under Article 6 and Annex III, subject to the transparency duties in Article 50, or none of those. Most of what you find lands in the last two buckets. The record of why a system was placed where it was placed is worth more than the placement.

Weeks three and four, the controls. Only now does anything get built. Human oversight on the systems that need it, logging that survives an audit, an approval gate on any action a person would want to reverse, and an incident path with a name on it. Article 26(6) sets the deployer log retention floor at six months for high-risk systems. Six months is a floor and not a target.

Weeks five and six, the evidence pack. The inventory, the classification record, the decision logs, the human oversight record and the incident path, assembled into something a supervisor, a customer's procurement team or an audit committee can read without a walkthrough. Then it is handed over, because a governance artefact your team cannot update alone is a dependency, not a control.

The four decisions a governance owner has to make

Everything else follows from these. Answer them badly and the controls will be rebuilt in a year.

  1. Who owns the register. One named person, with the authority to stop a deployment. Splitting this between legal, risk and engineering produces three partial inventories and no register.
  2. What counts as a new system. A model swap, a prompt change, a new data source. Draw the line too tight and the register becomes a change log. Draw it too loose and a system quietly changes purpose without anyone reclassifying it.
  3. Where the approval gate sits. Before an action reaches a customer, or after it, with a reversal path. The first is slower and cheaper. The second is faster and occasionally expensive.
  4. What gets logged and for how long. Article 26(6) gives you the high-risk floor. GDPR retention limits give you the ceiling. The interesting decisions live between the two, and they are business decisions rather than legal ones.

Three kinds of supplier, and what each one is for

Buyers put all three in the same procurement and then wonder why the proposals do not compare. They are selling different things.

Supplier typeWhat you getThe trade-off
An assurance firmAn opinion. A certification, an audit report or an attestation an external party will accept.Independence is the product, so the same firm will not build the controls it later signs off. You get a document and a gap list, not a running system.
A platform vendorA control plane. Somewhere to hold the register, the policies, the evidence and the alerts.The platform records controls it does not enforce. Filling it is your work, and a half-filled register reads worse in an audit than no register.
A delivery firmThe controls built into the system itself: the oversight step, the log, the gate, the kill switch.The firm that builds a control is not the right party to certify it. Plan the independent look separately, and early.

Digiton is the third kind. We build the controls into the systems we deploy and hand over the evidence pack. When a signature is the deliverable, an assurance firm is the correct spend and we will say so.

What the evidence actually looks like

Five artefacts. Each one is a file a person can open, not a claim in a slide.

A note on staff capability, because it has changed. Article 4 of the AI Act was replaced by Regulation (EU) 2026/1744. The duty is now to take measures supporting the development of AI literacy, and the amended text states that it does not require providers or deployers to guarantee any specific level for any individual. The training obligation got softer. The register did not.

When you do not need this yet

If you run no AI system that touches a person, makes or shapes a decision about a person, or produces content published as your own, you have a shadow-AI question rather than a governance programme. Write the inventory. Stop there. Come back when the first system reaches a customer.

The same holds if you are still choosing between two pilots. Governance applied to a system nobody has agreed to build is theatre, and it slows the decision that actually matters. What is worth doing early is naming the owner, because that person will make every subsequent decision faster.

Frequently asked questions

What is AI governance consulting?

It is the work of finding every AI system a business already runs, classifying each one by risk, building the controls that follow, and producing the evidence that the controls exist and are used. The output is an inventory, a classification record, decision logs, a human oversight record and an incident path.

How is it different from an AI audit?

An audit tells you where you stand on one date. A governance engagement leaves behind a register your team updates and controls that run inside the system. Digiton runs both, and an audit is the cheaper first step when nobody has written the inventory yet.

Do we need this if we are only a deployer and not a provider?

Yes, and the deployer duties are the ones most enterprises miss. Article 26 of Regulation (EU) 2024/1689 puts human oversight, input data control, monitoring and log retention on deployers of high-risk systems. Article 50 transparency reaches far wider than high-risk.

Did the December 2027 deferral remove the need for governance work?

It moved the application date for Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028. The Article 5 prohibitions, the general-purpose model obligations and the Article 50 transparency duties were not moved. The register and the classification are what let you prove which bucket you are in.

Who should own AI governance internally?

One named person with the authority to stop a deployment. In practice this sits with risk or with the CTO, and it fails when it is split across legal, risk and engineering, because each function writes a partial inventory and nobody owns the whole register.

How long does an AI governance engagement take?

Digiton's average deployment across engagements is 45 days from signed scope to a system running in production, and governance work runs inside that window. The inventory is the first week. The evidence pack is the last.

Can the firm that builds our controls also certify them?

No, and you should not want it to. A delivery firm builds the oversight step, the log and the gate. An assurance firm gives an independent opinion on them. Plan the independent look as a separate engagement and book it early.

Related

EU AI Act readiness for enterprisesProvider or deployer under the EU AI ActAI agent governanceAI vendor due diligenceGDPR-compliant RAGEnterprise AI consulting in EuropeBrandon Da Costa

Ready to put AI to work?

Book a discovery call and we will map the highest-value AI agents and automations for your business.

Book a discovery call