AI governance & assurance · UK regulated firms
Where your AI exposure needs attention first.
Your teams are already using AI inside your core work. We show you where that puts you at regulatory, contractual or business risk, what needs attention first, and what can wait.
Usually a reply within one working day.
Why it matters
AI has moved into how your business actually operates: drafting, claims, client communications, decisions. Most firms adopted it faster than they decided how to run it.
The questions are already arriving.
Clients and regulators are asking how you use AI and who checks it. A vague answer costs trust, and sometimes the work.
Bans don’t work.
Strict AI bans don’t stop AI use. They just stop you seeing it.
Risk sits where nobody’s looking.
Client data in free tools, one supplier carrying critical work, output nobody owns. These surface as incidents, complaints or regulatory action, usually before anyone has asked the question.
Who can hold you to it
Every control that applies to you is sorted by who can enforce it, so you know what to deal with now and what to plan for.
Enforceable now
UK GDPR, and your sector’s existing rules; in financial services, Consumer Duty and SM&CR already apply to AI. A regulator can act today, whether or not anything has gone wrong.
From a stated date
The EU AI Act. Some obligations already apply; most from December 2027, and only where your AI reaches EU users.
Through contract
ISO/IEC 42001 and your clients’ own requirements. No fine, but it shows up in due-diligence questionnaires and tenders.
What you can’t yet see
Nobody enforces it, and nobody will ask. Client data in free AI tools, one supplier carrying critical work, nobody left who can do the job by hand.
Often the most expensive category, and the reason to use a person rather than a product.
A readout of where your attention belongs
After every engagement, starting with the free first session, you receive a signed readout: where your AI work sits, what’s open at each of the four levels, and where attention belongs first, next and later. Early sessions cover less ground; the readout grows as the work does.
Behind it sits a dated record of the evidence for every point, ready when a client or regulator asks.
Example readout
Where Contoso’s attention belongs
Two critical claims workflows act without a person. The regulated exposure is current, not future: focus there first, then on ownership and supplier continuity.
- Focus now Regulatory position
- Focus now Permissions and oversight
- Focus next Ownership, suppliers, culture
Engagement readout · Contoso Insurance
Where Contoso’s attention belongs
Contoso Insurance is an invented company.
Contoso’s AI use is concentrated in Claims, where two critical workflows act on the claims system without a person. The regulated exposure is current, not future: focus there first, then on ownership and supplier continuity.
Where the AI work sits
Two workflows act without a person. Both are critical.
- Claims triage (critical)ClaimsA person checks the AI's work: none.
- Fraud flagging (critical)ClaimsA person checks the AI's work: none.
- Claim lettersClaimsA person checks the AI's work: lightly.
- Chat repliesCustomer serviceA person checks the AI's work: lightly.
- Campaign copyMarketingA person checks the AI's work: lightly.
- Settlement offers (critical)ClaimsA person checks the AI's work: every time.
- Risk summariesUnderwritingA person checks the AI's work: every time.
- Policy wording draftsUnderwritingA person checks the AI's work: every time.
- Complaint responsesCustomer serviceA person checks the AI's work: every time.
Critical, as recorded
Not yet recorded: 1 claims workflow. Finance: no AI workflows recorded.
- 1Regulatory positionOpen controls: enforceable now 11 · from a stated date 4 · through contract 7 · what you can’t yet see 3Focus nowConsumer Duty applies today to two claims workflows.
- 2Permissions and oversightActs without a person 2 · checked lightly 3 · reviewed every time 4 · permissions agreed 3Focus nowThe two that act alone are both critical.
- 3OwnershipWorkflows: owner named 5 · no owner 3 · not recorded 2Focus nextTools are owned; the work they do is not.
- 4Supplier dependenceVendors 4 · due diligence submitted 1 · continuity submitted 0Focus nextOne supplier carries all claims drafting.
- 5DataAI steps touch personal, special category and commercial data · class not recorded 2Keep watchingNo attention suggested where recorded; two steps not yet classified.
- 6Culture and trustNo recorded facts. Judgement only.Focus nextStaff use AI openly; leadership hasn’t said what’s allowed.
It is a record, not a certificate. Ignivara iQ does not certify, audit or confirm compliance.
We do not score.
Most AI governance tools hand down a rating: a percentage, a maturity level, a traffic light. A score tells you how you compare. It doesn’t tell you what to do on Monday.
We started with a scoring framework and replaced it. You get areas to examine rather than a rating, evidence rather than estimates, and a named person’s judgement, signed and dated.
Every point traces back to a fact you recognise, and you can challenge any of it.
Who it’s for
UK firms of 20–250 people where AI is in daily use and there’s no dedicated AI governance team: insurance brokers, law firms, financial services and specialist services firms. Usually it’s the managing partner, COO or compliance lead who has been asked about AI and needs a clear answer.
Financial services and brokers →Begin with a single workflow.
60–90 minutes on one piece of your own work, free. You leave knowing where to look first.
Usually a reply within one working day.