EVIDENCE-BASED
AI GOVERNANCE

FOR THE ENTERPRISE.

Build structured, reviewable AI governance inside your existing Microsoft 365 environment. We configure the controls, evidence and operating routines your organisation needs to demonstrate
accountable oversight-subject to scope, Microsoft licensing and legal applicability.

Netherlands-based

Specialist · AI · Security · Privacy

Microsoft 365 Native

Evidence-based delivery

EU-wide · Remote-first

THE COMPLIANCE GAP 

Most organisations use AI.
Very few can evidence how it is governed.

The EU AI Act requires organisations to demonstrate how applicable governance obligations are
implemented not merely state intentions in policies or slide decks. Reviewers need structured,
traceable evidence that AI systems have been identified, classified, assessed and assigned
appropriate controls.

No AI Inventory exists

Documentation is fragmented

Purview and Copilot governance 

Auditors need evidence

INTEGRATED REGULATORY SHIELD

Protect your board against the dual risks of data privacy violations and AI liability through our converged governance architecture.

THE SOLUTION

The AI Compliance Control Room

SharePoint Evidence Vault


Structured site architecture with document libraries for FRIAs, DPIAs, governance policies, incident records, and audit artefacts. Controlled permissions, version history, and sensitivity labels applied.


AUDIT-READY STORAGE

SERVICES

Three ways to engage.

Choose the depth that fits your stage. Every engagement produces documented, auditable evidence not advisory reports.

FIXED-SCOPE · 4 WEEKS

A structured four-week engagement that produces your AI inventory, risk classification, gap analysis, and a prioritised compliance roadmap built on your existing Microsoft 365 environment.

  • AI system inventory and EU AI Act classification
  • Gap analysis against Annex III obligations
  • Risk register deployed in Microsoft Lists
  • FRIA/DPIA requirement identification
  • Prioritised compliance roadmap (30/90/180 days)
  • Executive briefing and board-ready summary

Fixed investment · Delivered remotely

IMPLEMENTATION · 6–10 WEEKS

End-to-end implementation of your AI governance infrastructure inside Microsoft 365 from the evidence vault and risk registers to Purview controls, Copilot Studio workflows, and your first completed FRIAs.

  • SharePoint Evidence Vault fully configured
  • AI register, FRIA log, DPIA log deployed
  • Copilot Studio intake agents activated
  • Purview labels, retention, and audit access set up
  • First FRIA and DPIA completed and archived
  • Auditor access protocol established

Scoped investment · Remote delivery

ONGOING · MONTHLY RETAINER

Continuous compliance monitoring, regulatory update integration, quarterly assessments, and ongoing audit support so your governance infrastructure stays current as the AI Act is enforced.

  • Monthly regulatory intelligence briefings
  • Continuous risk register maintenance
  • New AI system intake and classification
  • FRIA and DPIA support for new deployments
  • Quarterly compliance health check
  • Audit and supervisory authority support

Monthly retainer · Scales with usage

BUILT FOR MICROSOFT 365

Your compliance evidence lives inside your tenant.

SHAREPOINT

Evidence vault, registers, and version-controlled documentation

MICROSOFT LISTS

AI risk register, FRIA log, DPIA tracker, vendor register

COPILOT STUDIO

Intake workflows, FRIA triggers, DSAR automation

PURVIEW

Sensitivity labels, audit logging, retention, and DLP controls

AUDIT & TRUST

Demonstrably compliant. Not just claiming it.

Our approach is execution, not advisory. Every engagement produces structured evidence that auditors, investors, and supervisory authorities can inspect directly.

Evidence in your tenant


Governance artefacts are created and maintained within your Microsoft 365 environment where the agreed architecture allows. No separate ESP governance platform is required. Relevant data flows, Microsoft services and other processors are documented for each engagement.

Controlled auditor access


Auditors receive structured, read-only access to the evidence vault through Microsoft 365's permission model no email attachments, no ad-hoc document requests.

Purview logging & control


Microsoft Purview provides unified audit logging and DLP controls that make the governance posture visible, searchable, and exportable for regulatory submissions.

Human review in the loop


Every assessment and classification is reviewed by a qualified compliance professional before archiving. Automation speeds the process. Human judgement ensures defensibility.

Ready to become demonstrably compliant?

Start with a focused AI Act Readiness Call. We will review your current position and identify a practical path towards structured,            reviewable AI governance.

Book an AI Act Readiness Call

Solutions for Privacy, AI Governance, and AI Act Readiness

We offer a focused set of remote services to help organisations turn complex privacy, AI governance and EU AI Act obligations into clear, practical action. Each solution is designed for lean teams that need expert support, simple workflows and concrete outcomes rather than long reports.

Privacy Solutions

AI Governance Solutions

AI Act Solutions

The AI Act Readiness Sprint :

Four weeks to a documented AI governance readiness position.

Watch how we leverage your existing Microsoft 365 environment to inventory your AI, classify risk, and build a prioritized roadmap for the Board.

FAQ

Boardroom Intelligence: The Executive Shield Guide.

The Act imposes strict "Duty of Care" requirements. Our architecture ensures you have an automated audit trail to prove oversight and mitigate personal legal risk.

The AI Act introduces role-specific governance, oversight and documentation obligations. Our architecture supports board oversight and traceable accountability. The legal exposure of individual directors depends on the facts, their role and the applicable national law.

A Fundamental Rights Impact Assessment is required only for the deployers and high-risk use cases covered by Article 27 of the EU AI Act. We first assess applicability. Where a FRIA is required, we help structure and document it; where Article 27 does not apply, a voluntary
fundamental-rights assessment may still be appropriate.

No. Our "Shield" acts as a governance layer that sits around your AI, enabling innovation within safe, compliant boundaries without slowing down your teams.

Yes. If you collect or process personal data, you must provide a privacy policy (or notice) that is transparent, clear and easily accessible.
It should explain what data you collect, how/why you use it, who you share it with (including third parties), data subjects’ rights, retention periods, and security measures.

You must keep personal data no longer than is necessary for the purpose for which it was collected (“storage limitation” principle). This means you should define retention schedules, justify retained data, and periodically review and delete or anonymise when no longer needed.

When a personal-data breach occurs that is likely to result in a risk to the rights and freedoms of individuals, you must notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of it.  Affected data subjects must also be notified when the breach is likely to result in a high risk to their rights and freedoms.

Yes, but only if specific safeguards are in place. These may include: an adequacy decision on the recipient country, or appropriate safeguards (e.g., standard contractual clauses, binding corporate rules).  You must also ensure data subjects are informed and there is documentation of the transfer.

You must appoint a DPO if: your organisation is a public authority, or your core activities require large-scale regular and systematic monitoring of individuals, or large-scale processing of special categories of data. Even if not mandatory, appointing a DPO is often a good best-practice to oversee compliance.
Organisations must facilitate these rights, respond without undue delay, and inform data subjects of their rights.

Individuals (data subjects) have multiple rights, including: right of access, right to rectification, right to erasure (right to be forgotten), right to data portability, right to restrict processing, right to object, and rights related to automated decision-making and profiling. Organisations must facilitate these rights, respond without undue delay, and inform data subjects of their rights.