ConsultingAI governanceSheet 12

AI governance consulting.

Independent assessment, framework design, and model risk for institutions that must put AI into production and still answer for it. Banks, insurers, healthcare systems, and government, across North America and the GCC.

§ 01Definition

What AI governance actually is.

AI governance is the institutional capability to say who approved a model, against which obligation, on what evidence, and who has the authority to stop it. Everything else is documentation.

Most organisations do not have an AI problem. They have an accountability problem wearing an AI costume. The models work. The pilots demo well. What is missing is the record: the inventory that says which systems exist, the classification that says which of them are high risk, the validation that says someone independent checked, the gate that says this one may not ship, and the log that will still be readable when a regulator asks about a decision made eighteen months ago.

That record is not produced by a policy document. It is produced by machinery, and the machinery has to be engineered into the systems rather than written about them. The distinction matters commercially: a governance programme that produces policies will pass an internal review and fail a supervisory examination. A governance programme that produces evidence will do the opposite.

§ 02The obligations

The deadlines are dated, not theoretical.

AI governance stopped being a matter of principle at some point in the last two years and became a matter of calendar. The obligations below are in force or scheduled, in the jurisdictions this practice covers.

AI governance obligations by jurisdiction and date
InstrumentDateWho it reaches
EU AI Act, Article 50In force 2 Aug 2026Transparency duties for anyone providing EU-facing generative or conversational AI, synthetic media, emotion recognition or biometric categorisation. This one is live now.
EU AI Act, Annex III2 Dec 2027High-risk stand-alone systems including recruitment, credit scoring, education and law enforcement. Delayed from August 2026 by the Digital Omnibus, not cancelled.
EU AI Act, Annex I2 Aug 2028AI embedded in products already covered by EU product-safety regulation.
OSFI Guideline E-231 May 2027Canadian federally regulated banks and insurers, including branches. Model risk management, with scope expanded to cover AI and machine learning.
Texas TRAIGA (HB 149)In force 1 Jan 2026Anyone developing or deploying AI in Texas, or offering AI products to Texas residents. Attorney General enforcement, sixty-day cure period, no private right of action.
PIPEDA and the Treasury Board Directive on Automated Decision-MakingIn forceCanadian private-sector personal data, and federal institutions using automated decision systems.
GCC supervisory regimesVariesSAMA, CBUAE, SDAIA, DIFC, ADGM, QCB and AAOIFI, plus Sharia governance for Islamic finance. Jurisdictionally plural: a regional bank can sit under several at once.

Alongside these sit the voluntary standards a board will be asked whether you have adopted: ISO/IEC 42001 for AI management systems and the NIST AI Risk Management Framework. Neither is law. Both are what a supervisor, an auditor or an enterprise customer will use as the yardstick when they ask how your programme compares.

§ 03The method

Scored against a published framework.

Assessment work here runs on the MESA Framework, a four-layer model for institutional AI governance: the Regulatory Floor, the Strategic Compass, the Operational Machinery, and the Technical Substrate. Maturity is scored per layer, because institutions rarely climb the four in lockstep, and a weak substrate caps the machinery no matter what the policies claim.

The framework is not adopted from a vendor. It is original work, specified in the published Enterprise Playbook, which carries a foreword by the Executive Director for Science and Technology at the Kuwait Institute for Scientific Research. It extends ISO/IEC 42001, NIST AI RMF, TOGAF and DMBOK rather than competing with them. The examiner wrote the method the examination uses.

§ 04The work

Three ways this gets done.

Assess

The AI Governance Teardown

Two weeks, fixed scope, fixed fee. Fifty questions across the four MESA layers, up to eight stakeholder interviews, every finding traced to evidence. Ends in a board-ready gap report and a Now, Next, Later roadmap. Full scope →

Design

Regulated AI Architecture Sprint

Four to six weeks. Target architecture for LLMs, agents, retrieval, observability and the compliance controls that sit inside them, with an implementation backlog an engineering team can pick up. Engagement models →

Sustain

Governance Retainer

Monthly advisory for institutions executing a roadmap: architecture and governance review on live initiatives, a regulatory-change brief, and an annual re-score against the original baseline. A fractional Chief AI Officer rather than a full-time hire.

Fees are not posted. Each is fixed and shared on the free Fit Call once scope is clear, because a number that fits no one is worse than a conversation. No production data leaves your environment in an assessment. The examination reads governance artifacts, not customer or patient records.

§ 05Fit

Who this is for, and who it is not.

It fits regulated institutions with AI in or near production and a real obligation to answer for it: banks and credit unions, insurers, healthcare providers and payers, government bodies, and sovereign-backed initiatives. Typical sponsors are chief risk officers, chief data and AI officers, CTOs and VPs of Engineering, heads of platform, and model-risk and compliance leaders.

It does not fit an organisation looking for a certificate. There is no certification issued here, and a governance report that tells a board everything is fine is worth nothing to the board. It also does not fit a team whose binding constraint is engineering capability rather than institutional discipline. Governance discipline will document that gap honestly; it will not close it. That limit is stated in the framework itself.

§ 05bBy jurisdiction

Where the regulatory floor differs.

Layer 1 of the framework is populated with whichever regime applies, so the assessment changes shape by market. Two GCC jurisdictions have dedicated pages: AI governance in Kuwait, where there is no AI statute and the binding instruments are CITRA's data-protection regulation and CBK supervision, and AI governance in Qatar, where the QCB AI Guideline of September 2024 sets out classification and human-oversight duties for licensed entities.

§ 06Questions

What buyers ask first.

What does an AI governance consultant actually do?

Three things, in this order. Establishes what the institution is obliged to do, across every regime it operates under. Assesses honestly what it currently does, with findings traced to evidence rather than to opinion. Then designs and helps stand up the machinery that closes the distance: the inventory, the risk classification, the validation protocol, the deployment gates, the incident protocol, and the technical monitoring that makes all of it enforceable. The deliverable is a defensible record, not a policy binder.

How is an AI governance assessment different from an audit?

An audit tests compliance against a standard you have already adopted and issues an opinion. An assessment of this kind establishes where you actually stand before you are examined, scores maturity per layer, and sequences the remediation. It is run the way an auditor or a regulator would run it, with evidence required for every finding, but its purpose is to find the gaps while you still have time to close them. It is not a substitute for statutory audit and does not issue a certification.

We already follow ISO 42001 and NIST AI RMF. What does this add?

Those describe what good governance contains. They do not tell you which layer of your institution is failing when the governance turns out to be untrue. MESA is built on both and maps to both; what it adds is diagnostic altitude, a per-layer maturity profile instead of a single grade, and the requirement that every finding trace to a source. If you have adopted ISO 42001 and cannot produce the evidence behind a specific model decision from eighteen months ago, the standard is not the thing that is missing.

Does OSFI Guideline E-23 apply to us, and how much time is there?

E-23 applies to Canadian federally regulated deposit-taking institutions and insurers, including branches, and not to federally regulated pension plans. OSFI finalised it on 11 September 2025 and it takes effect on 1 May 2027. The revised text gives explicit attention to artificial intelligence and machine learning, which is the part catching institutions out: model inventories and tiering built for a narrower definition of a model do not cover what E-23 now reaches. This is a specific regulatory question, so take it to counsel as well; what an assessment gives you is the gap list and the sequence.

How long does it take, and what does it cost?

The Teardown is two weeks from kickoff, with the readout on day ten. The architecture sprint is four to six weeks. The retainer is monthly with a three-month minimum. Each is a fixed fee, shared on the free 30-minute Fit Call once the scope is clear rather than posted publicly, because the same engagement is priced differently for a five-model credit union and a two-hundred-model bank.

Do you work with institutions outside the Middle East?

Yes. The practice covers North America and the GCC, from stations in Winnipeg, Toronto and Calgary, and serves Texas and the wider United States remotely and on site. The framework is jurisdiction-neutral apart from Layer 1, the regulatory floor, which is populated with whichever regime applies: OSFI and PIPEDA in Canada, TRAIGA and the sectoral regulators in the United States, the EU AI Act for EU-facing systems, and SAMA, CBUAE, SDAIA and the rest across the GCC.

Will our data or models leave our environment?

No. An assessment reads governance artifacts: policies, inventories, committee records, validation reports, vendor contracts, and the decisions behind them. It does not require production data, customer records or patient records, and it refuses protected health information categorically. Where a technical review of a system is in scope, it is conducted inside your environment.

§ 07Start

Find out where you actually stand.

The Fit Call is thirty minutes and free, and it qualifies the work in both directions. If a Teardown is not what you need, you will be told that on the call.

Fin · AI Governance
Book the 30-minute Fit Call →